IHD I have a 5a and I wonder what the actual security risks are. What entry point(s) would there be for compromise of the security?
The obvious case is remote code execution (RCE) vulnerabilities in the firmware (baseband, Wi-Fi, Bluetooth, GPU).
Pixel firmware RCE bugs have been found, reported to Google, announced, and patched in the past (2023 example). If somebody finds an RCE bug in 5a firmware now, Google is unlikely to track and fix it, so the vulnerability may well be sold to a zero-day market. If that happens, affected users will not get timely notice they're vulnerable and will not get a patch.
Once firmware support is over it is prudent to assume that nasty people are secretly building up a portfolio of exploits for bugs that are present and will never be fixed. There is no way to predict exactly how vulnerable a device will be on any given day, but the risk level starts climbing the day firmware support expires.