Earlier quoted context omitted.
If you use apps that require security (like payment apps) you might run into problems here. My company might need to exclude phones like this one soon because more and more CVEs are coming up. Alternative ROMs are often not the solution here because Play Integrity and Key Attestation no longer work. For general messaging and browsing this hardware likely work quite well. Btw I had the Motorola Defy and flashed it eve…
I wouldn't use the phrase "require security" to describe such apps, since to fulfill what they actually require, you often end up being less secure. For example, most such apps will be fine with you running them on a phone with 20 critical CVEs from a year ago, but not on a phone that you unlocked the bootloader of to install a version of Android that fixes said CVEs.
The same applies to most open source efforts, but I think it's understandable for institutions with consequences to what their apps do (like handling money and bank accounts) to opt out of potentially being undermined by the OS when they have the means. There's also elements of phones being general purpose computers now vs locked down appliances, GPL3 vs tivoization, and so on.