That's just dogma. There's nothing about "new" and updated that makes it more secure. Look at old djbdns or similar for software that hasn't been found vulnerable after many years.

Without javascript, plugins, and all those features, there's much less to have vulnerabilities in a browser. With such a tiny code base, it's easier to be secure and fewer places for vulnerabilities to hide.

2015 is just the last "stable release". Development is ongoing (slowly). Some projects just don't care about "releases" that much, and their userbase is sophisticated enough to grab svn/git snapshots directly. Some projects have good development practices so that the dev snapshots are only rarely broken.

Don't like it? Do it yourself.

