There is a relatively recent audit[1] of EncFS with some damning results. I really wouldn't use it.
They didn't seem that severe to me, they seemed pretty minor actually. Especially if your attack vector is solely a read attack rather than a read-write attack.
Which one got you worried?
Which, seeing as my current major use case is to lock down Dropbox, kind of renders it useless for me.
However you should not use XTS with Dropbox http://sockpuppet.org/blog/2014/04/30/you-dont-want-xts/