It's a bit hard to compare phpBB2 to phpBB3. 3.0 has a much larger ammount of code. 2.0 is also over 5 years old, so 22 releases in 5 years doesn't sound all too bad if you ask me. Although, considering almost every one of those releases fixed a security issue. phpBB 3.0 should be safer regarding this, it's code base is so much securer. You can never know however.
And yes, it's possible that there are a few RCs. I personally think the RCs are a great idea, they make sure that the release really works. In phpBB2 it was possible for the devs to test it out themselves, now there is a QA (quality assurance) team that tests these releases. But everybody is free to do so.
