I use
GetSimple, and it may meet all your requirements:
Data is stored in multiple XML files
I don't know about security track record as I only found it recently (when I found it I did some quick searching and only came across one reference to a security problem, but I admit I didn't spend much time on this).
Not sure how old the project is
Officially requires Apache, but I use it with Lighttpd for lower resource usage with no problems. I have a half dozen sites on a 128MB VPS, but they're all low traffic so not really a good indication of how well it scales. (NOTE: They provide .htaccess files to ensure the XML data files (and some other stuff) aren't viewable via the web, so if you do use an alternative webserver you need to ensure you recreate those restrictions)