Perhaps 'security by obscurity' has its parallel in 'vulnerability in popularity'.
While not a good security tactic in general, there is something to the fact that an obscure library will be less exploited.
The more time you spend updating dependencies, the less time you spend actually coding things. Well, unless the updates actually give you new features, which is generally not what people are looking for when running an update for some reason.