That also depends a lot. Often (e.g. on Fairphone) the stock ROM may lag behind way worse than e/OS.
So if a user has reasons to avoid a Pixel, or just wants to improve their privacy without replacing their device, e/OS may be a marked improvement even on security.
I didn't say they weren't. I simply think that the implications for the average user often get blown out of proportion, because I've heard from absolutely no one who uses eOS on the forums for example that they've had a problem with their phones derived from that delay.
Depends on your threat model. If youre an average joe, and your threat model just want to avoid big tech and prolong your device suppport. eOS is great. People just need to have some common sense which is not installing random apk and what not.