There is only so far that support with UBB.C can go; it is EOL, thus is destined to never be updated again; the spam measures IN classic also only go so far...
In my posts I'm providing valid alternatives for items other than saying "well, classic is EOL, you're screwed"; we try to give every method available in classic, then also provide the information in threads that is much more customizable.
BTW, PHP is secure, it's the scripting which can be insecure; if the author doens't know what they're doing, you can lead into many issues; and the sad thing is, most of these issues aren't really that hard of things to patch, however they're found when they're found. Any scripting can have errors or security issues, regardless of the language it was coded in.
Also, threads is faster because of its database; the flatfile ways of UBB.C is what made it slow on larger forums. All of those lookups on flat files led to speed issues and for some it was completely unbearable... With regards to "having to setup a database", most webhosting servers come with some version of MySQL, so it's not generally an issue.
And don't get me wrong, I was with Classic from the beginning; I hated threads, it was an ugly product that wasn't worth my time, and I didn't want to change; however, being in the alpha/beta program a lot of my input (as the other UBB.C users in the beta program) led to more of a comfortable look/feel in threads.
But it seems no matter what I say there will always be someone that will sit and whine about me trying to convert people up to a faster and more reliable product which they already have licensed access to.