Earlier quoted context omitted.
I think the irony is that newness is irrelevant once it's being used at a certain scale. You can battle test more in an hour than you could a small scale project in ten years.
How do you battle-test in an hour the ability of the upstream developer to provide security fixes? To provide updates at all as the ecosystem develops (e.g. the rise of systemd, taking advantage of advancements in worker models, SSL library API changes, new Lua versions)? Ability to keep backward compatibility with modules? Your approach might have led you to invest heavily in lighttpd at some point in time.
It takes years to to tell if serious vulnerabilities are being found often or not.