An average XP user who practices safe computing/email practices and doesn't have their PC connected directly to the Internet (i.e. is behind a firewall or NAT router) can be reasonably secure from infection for a long time. For these people, visiting an infected website may be their biggest risk, so trying to do as much web surfing without Java and Javascript could improve their security tremendously, although you lose a lot of functionality, but it's a price to pay for more peace of mind.
That's certainly true, but the vast majority of people who know what safe computing/email practices are and practice them are already off of WinXP.
Some people don't realize that this is something they should learn. Others refuse to learn. This is possibly why I have a job

.