In this context, orphaned doesn't always mean you should remove it. It just means that nobody in AUR is taking responsibility to keep it updated. You still might have other packages from the AUR that depend on this one.
Since it is unmaintained, basically anyone can now claim ownership of that package in the AUR and push updates for it. Theoretically, someone could try to distribute malware in this way.
This is why it's important to check the diffs of your AUR updates.