XF1 is end of life. So no it isn't fine.
Generally not a good idea to run end of life webapps that don't get security updates, especially with all the butthurt individuals we have out for blood.
Despite the popular belief, a lack of maintenance does not mean that a piece of software will be less secure. The security bugs don't just pop up out of nowhere --
they were there all along.
Furthermore, a new major version does not mean that it will be more secure either. Major versions come with new features, new features tend to mean more code, more code means more potential security bugs.
Paradoxically, the most secure version of software often is an end-of-life version that has had its batch of security updates done already. (That said, manually backporting any relevant security updates is still a good idea.)