> Until someone uses ROP-widgets turning stack return addresses into executing what the attacker wants.
That's like saying there's no point in locking your doors because thieves can go in through the window. Instead, you're better off applying separate defenses against separate attacks: read-only code against code injection and other defenses (like CFI or randomization) against ROP.
> Besides, any secure JIT will only keep a page either writable or executable, but not both in the same time.
Sure, but it's amazing how few actual JITs do that. V8, for example, actually maps its entire code cache as RWX.