Speziii One way to think about it is that EOL devices get roughly half of the grievous security bugs fixed. There is no way to put a precise figure on the exact fraction, but it is prudent by this point to assume that some grievous 4a bugs have been assembled by state actors and criminal gangs and are in use, but not being tracked with much energy by anybody because the device is EOL.
Luckily the 9 series is out, so 6, 7, and 8 devices should be cheaper than they were. A used 6a in good condition might be a good way to balance cost versus remaining support lifetime.