How does Envato justify selling outdated templates, themes, etc. with known vulnerabilities?

Both jquery and bootstrap are client-side frameworks and this null any real security issue…
I think you’re worried without a valid reason.

Jquery 2.1.3 and bootstrap 3.3.4 are safe to use, including Jquery 1.0 and Bootstrap 1.0 :wink: