Although if you just want a degoogled phone with some features and don't want to hide a criminal enterprise, I doubt an out-of-support Graphene phone is any worse than an out-of-support Huawei or Xiaomi or Realme or Motorola phone.
I'm curious how many months/years before out-of-date GrapheneOS becomes the worse option security wise compared to various brands' stock Androids. Obviously it is nuanced and there's no clean answer but it would be interesting on average.
We could think of metrics in public patches, but GrapheneOS has exploit protections that prevent against 0-days which would be hard to factor in.