Earlier quoted context omitted.
If you install a more recent version of Android (such as 4.4) on the Defy (it shipped with Android 2.3 or so), it will be too slow for use (for my taste,anyway). I tried it with a faster Defy+. Even with Android 4.4 it will be a very insecure phone. With Android 2.3 it will be laughably insecure. Visit one wrong webpage and your phone is owned. No thanks.
In what way would this be "a very insecure phone"? It runs Android 4.4.4 just fine. I patched the one glaring bug ('Stagefright'), it runs the latest browsers (Firefox/Fennec, Lightning, PB) without problems. While there is lots of talk about 'Android being insecure' it is hard to find actual examples of Android devices which are used in a sensible way (i.e. which do not get fed whatever APK just downloaded from getf…
Just look at the monthly security fix notes. There are critical vulnerabilities getting fixed every month.
Here are more critical ones: CVE-2017-0764, CVE-2017-0756 from the September patchlevel that also affects Android 4.4.4. See https://source.android.com/security/bulletin/2017-09-01
In August 2017, three more. In July one. In May another two. Still not convinced?