Over the last two years, Safari has had half the vulnerabilities [1] as Chrome [2] or Firefox [3]. Security updates are frequent [4].
As to code being a mess... perhaps there's a particularly offensive part of the WebKit code style guidelines [5] that make them less secure than Blink code style guidelines[6]?
[1] http://www.cvedetails.com/product/2935/Apple-Safari.html?ven... [2] http://www.cvedetails.com/product/15031/Google-Chrome.html?v... [3] http://www.cvedetails.com/product/3264/Mozilla-Firefox.html?... [4] https://support.apple.com/en-us/HT201222 [5] http://www.webkit.org/coding/coding-style.html [6] https://www.chromium.org/blink/coding-style