If the client will not update then they lose the functionality. Not hard to understand that.
The internet is not a nice place. Keeping support for insecure software just makes it worse for everyone. Look at the number of places that do not impliment best practice for email doing stupid things like ignoring SPF records making joejob attacks so functional. Reasons I have been given for that was because it blocked too many emails from their clients who were misconfigured. Putting ease of use ahead of security is how most of this mess has happened and just saying "Ok, keep using the old piece of crap because you dont want to upgrade" puts more people at risk of spam and phishing attacks etc.
Get rid of the old software. If peoples businesses have not budgeted for IT replacement and they cannot afford it then they do not have a real business.