Keeping your snaps including the browser > 90 days behind in security patches seems like a really bad idea. It's better you have to actively postpone it periodically, having weighed the vulnerabilities publicized & fixed vs whatever your motivation to holding the update, rather than have a fail-open type of configuration that you can forget in the "not updating" state. Firefox fixes and makes public a RCE vulnerability quite frequently, more than once a month on average.
Also, if you want to have a more leisurely pace of browser functionality changes, you can also choose Firefox ESR that still receives timely security fixes.