We're almost into the third decade of the 21st century and we're still grading security bugs out of 10 like kids. Why?

That may be true, but it says nothing about whether their predictive model is a useful tool, much less whether the approach in general can be useful.

