It's good that it looks to be still maintained, but I imagine their resources are limited with so little market share and it doesn't look like they have the resources to switch to Wayland (which I assume is more secure).
I'm not sure my noob questions are worthy of asking the devs directly.
What kind of threats could affect Xorg? I can't imagine anything really exploiting the display manager without arbitrary code execution elsewhere (not that I know anything at all about software security).
I guess the biggest risk is whichever browser I use becoming a Wayland exclusive and not getting updates.