Earlier quoted context omitted.
>utter lack of any sign of trying to mitigate these problems (e.g., fuzzing, or even merely attempting to identify security fixes in Firefox that may warrant backporting), And here's where you show you're making it up and haven't even looked at a Pale Moon release notes, http://www.palemoon.org/releasenotes.shtml
I don't read release notes, I read the commits and the patches themselves. Actually, I did check after posting, and they appear to do the bare minimum--port the posted CVEs, which won't even account for all the security bugs. There are definitely several commits I've seen them do where they specifically revert changes that rewrite functionality to be safer, but don't actually fix any specific known security flaw. If…
1. You don't seem to think the Pale Moon has value, nor that it should be used.
2. You say you don't read their release notes--which makes sense if you don't think it's worthy.
However:
3. You say you do spend time reading their patches--which doesn't make sense if you don't think it's worthy.
4. Their release notes frequently mention "defense-in-depth" patches which are their own work, not, as you put it, to "randomly backport patches purely to try to keep somewhat up-to-date"--which conflicts with your claims about their work.
So you say you read their patches, yet you don't appear to read all of them. And you say you don't read their release notes, yet you speak as if you have comprehensive knowledge of their work.
Then you say something that's supposed to be scary, but then you say that it might not actually be scary, and you won't tell us whether it actually is.
So, regardless of whether Pale Moon is valuable or useful or secure to any degree, isn't your comment a textbook example of FUD? What's your purpose here?