It’s very likely that project is a security nightmare. Just an OS old enough to support 2.7 would be problematic.
https://www.cvedetails.com/version-list/10210/18230/10/Pytho...
IIRC some commercial distros maintain patches for 2.7 but then you're paying for being 15 years behind the future.
Looking at the list, I'm actually kind of surprised there aren't more CVEs for python 2.7, but if you're only running it locally or on an intranet I could see letting it ride.
2to3 gets you pretty far and theres not much in the rest.