The problem here is that the people who are actually aware and concerned about security updates (or lack thereof) are the technologically literate who upgrade to a new phone fairly frequently.
The target market that you want to secure is generally either unaware of or apathetic towards security concerns (until they get hit).
But the people who are knowledgeable also give recommendations to their friends and family who want something that just works.
If you can buy a 1-2 year old phone for $100-$200 (without contract) and pay an extra $10 per year to receive security updates, that's a pretty good deal.