As your link says, VirtualBox isn’t patching older releases for security problems. This doesn’t fit well with a long-term stable distro. The risk to you is that you unknowingly run software with known but unpatched issues.
Whonix works fine on Debian with KVM/Virtual Machine Manager.