How do you know a timestamped vouch is no more valid? Isn't that the point of revocation?
If you want to distrust a security vendor for greenlighting something that was found to be vulnerable the following week, you'd probably be in the clear.
If it was 6 years ago? Maybe don't count that against them; especially if it's a novel vulnerability that was discovered.
But also, if you're running 6 year old software, maybe update to a newer version of it.