I like to think that after 15 years, most of the vulnerabilities have been exposed and patched, plus that with a decreasing user base, it gets less and less attractive to target.
I like the mode of operation. **I** boss it around. XP does what I tell it to do. Mostly.. Part of the appeal is I can update it and applications manually on my schedule and terms. No nagging. And rarely is an update (to anything) so important you have to stop all work and conduct said update.