Conversation

Replying to and
I was the one that created and maintained it, almost entirely on my own. It offered substantially more privacy and security than the stock OS. It couldn't offer a longer support period since it relied on the same security updates. It's no longer the same thing that it was before.
2
2
Only Nexus and Pixel phones support locking the bootloader with an alternate OS. I'm obviously aware of that since I worked on an alternate OS preserving the security model used by the stock OS and AOSP. There's no point in locking it if the OS being used breaks that security.
2
It has a huge number of vulnerabilities with whatever ROM you are using. The issue is using a Nexus 5 at all when it isn't receiving security support for the kernel, drivers and firmware. Your choice of ROM doesn't solve these issues. It's still incredibly insecure regardless.
1
It doesn't matter if your ROM pulls in all the latest AOSP security fixes and then lies about the security patch level by pretending that those are the only fixes in the Android security updates. It's missing half of the fixes for vulnerabilities. Sorry but it's totally insecure.
1
Even if they rewrote all of the closed source drivers that aren't receiving security updates and maintained them, moved to a kernel branch receiving security updates and maintained the other device-specific code, it wouldn't fully solve the problem. They're not doing that anyway.
1
It would be possible for people to rewrite and maintain all those drivers and move to a modern kernel receiving security updates. It would be an enormous amount of work. It's certainly not something that the ROM development community is doing, and it couldn't fix the firmware.
1