The more universally executable code you have to run in a low-trust environment which is a WWW document, the more interesting vulnerabilities can creep in.
It's too late though: https://portswigger.net/research/ublock-i-exfiltrate-exploit...
Its not always appropriate but I feel CSS benefits more often than not for this
Which browsers that matter aren't evergreen at this point?
EDIT: got an answer downthread, apparently at least some sites have to deal with old versions of the mobile Safari engine because of old iPhones/iPads that can't be updated and can't run other browser engines. Another good reason to wish that iPhones/iPads permitted other browsers.
To what extent are those platforms unable to support a better browser? For instance, Firefox works all the way back to Android 5.0.
Browsers on devices (sometimes iPads, sometimes Android) that are inside touch-screen kiosks.
Some of the ones I work with are in places so remote, it would take me three or four days to reach them if a software update goes wrong. Then another three or four days to get back to the office.
This is the most important question nowadays. there are still organizations where this is tightly controlled, they use LTS releases that don't always get the updates as fast or the same etc.
Safari on iOS, which is still tied to the OS version and not evergreen yet.
If I look at https://iosref.com/ios-usage there's only half of the users on last year update and 15% of users lagging behind on a 2+ year old browser version.
So expect your average users to have a new Safari version ~1.5 year after it's been out. So the answer to that is no, it's not fast enough to be considered evergreen.