This means that if you have multiple rails sites with limited or no timely dev support you may not be readily able to upgrade your site to resolve issues.
This is why I took down my personal blog I had built in rails since I didn't want to be exposed to these issues and didn't have the time or desire to uplift the site onto more recent versions of rails.
A framework or system with only 10 users will never have the depth of security and bug fixing coverage that a larger, well used system has.
When examining web server access logs, it's quite common to see hundreds of requests coming in from a single host during a short period of time, looking to see if certain exploitable framework- or app-specific pages exist.
Such scanners do appear to target certain frameworks or web apps, contrary to your suggestion that this does not happen.
I'd go with something with a definitive support life and paid support if you need it.
Either that or something simple enough you can run your own fork.
And this article is about paid support if you need it. ;)
Paid support by the vendor?
As a guy who dislikes it (and doesn't know all that much about it), I still find Rails' security policy to be efficient and reasonable.