Actually, Apple sometimes patches actively exploited vulnerabilities in "unsupported" older versions of both macOS and iOS. The vulnerabilities that don't get quickly patched are the ones that aren't actively exploited.
In any case, security researchers talk about known vulnerabilities that have or haven't been patched, but as the author says, "New versions of macOS are full of bugs". This includes security vulnerabilities! Every new major OS version has brand new, unknown (to Apple) vulnerabilities that did not exist in the previous version. So just because the latest version is "fully patched", that doesn't mean it's "safer". I've seen it happen many times in the past where a new security vulnerabilities in a new OS isn't discovered by the public until many months later.
As far as stability and safety is concerned, I personally consider macOS N-1 to have the best tradeoffs.
Moreover, the most dangerous software on your computer is not the operating system per se, it's the web browser. The browser is where you're mostly likely to encounter "malicious crafted code" (i.e., JavaScript). Apple supports Safari for macOS N-2, and Safari on macOS N-2 is more similar to Safari on macOS N than macOS N-2 itself is to macOS N. In other words, Safari is likely to be fully patched even if macOS isn't.
You can also use another browser such as Firefox or Google Chrome, which ironically support older macOS versions than Apple supports, and the latest versions of those apps are identical and fully patched on every macOS version they support.