I do not know much about it but WordPress (Requires 7.0 since very recently) used as part of their explanations (excuses) for their extreme backwards compatibility that some of the major webhosts used some special PHP versions to account for security risks while still serving with old versions.
Lack of security updates / process doesn't definitely imply an insecure environment, but it puts the onus for security more clearly on the host. You've got to at least watch all the security updates in newer revisions and consider if they apply, but there's also things that may have gotten fixed or at least changed without realizing the old version was insecure.