> 1. Security
Linux (and Unix before it) has always had security mechanisms built in. File permissions, setuid bits, namespaces. Any old program shouldn't be able to access /etc/passwd, and likewise the `<input type="password">` in my browser should be protected. Wayland's problem isn't that it tried to add security, but that the design and development process went horrifically wrong so that 17 years after the first release, people still have trouble with screen sharing.
> 2. Performance
The client-server model is obsolete and unsupported by modern applications (and nowadays there are easier ways to do remote GUI access) and keeping it was just a big pile of tech debt.
The problem wasn't that Wayland tried to fix things, it's that the process took 17 years and still isn't finished or particularly successful. My uneducated guess at why Wayland failed to succeed is that it went for extreme modularity and refused to say (back in like 2009) "Here's the security mechanism everyone has to use to take screenshots, etc. If this breaks your spacebar heater, sucks to be you." Rather than just define a single API where 99% of graphical applications and desktop utilities can do the sorts of things they already do on Windows and MacOS, and call it 1.0, instead they built a sprawling monument to bikeshedding and over-engineering.