Not true. First of all, I wouldn't use Windows at all on a machine I depended on for security. The fact is my XP box has never had a bug on it. It's fully patched, services off, behind a nat, with firefox and noscript. Acl's can be improved but I've never bothered. I admit it takes a lot of upfront prep to get XP safe to use, but it can be done if one has the knowledge.
Who said I know anything about web development? Greybeard here that learned on the Vic-20.
Yes. A number of security augmentations in Windows 7 required significant modifications to the operating system kernel and user space environment (almost to the point of a rewrite in some cases). These modifications cannot happen in Windows XP without turning Windows XP into Windows 7.
ASLR is mostly enabled, especially in 64-bit binaries. W^X protection is always enabled on 64-bit binaries. Service hardening and privilege separation are enabled by default always.