Yes, I'm aware that I can turn on 'allow less secure app'. To me, that sounds like asking for invasive trouble.
This is not asking for trouble of any sort. There is no question of lowering your email security by allowing Windows Live Mail to access your Gmail account. Windows Live Mail just doesn't happen to support OAuth, which is what Google wants you to use.
OAuth is analogous to the system used at this site. When you sign in to answers.microsoft.com, you are redirected to a different site - login.live.com - to enter your credentials (username and password). Once they have been verified, you're sent back to answers.microsoft.com with a ticket saying that you've been authenticated. Microsoft Community never sees your credentials, so even if a hacker managed to get in to it, he wouldn't find any credentials to steal.
I don't think there's any need to be wary of "allowing less secure apps to access my account". Windows Live Mail isn't an 'app' like those for Twitter or Facebook or LinkedIn that have enormous online databases that need protecting. It's a simple mail client that sets up direct communication with a mail server. You have to be authorized to access your mailbox so only you can do it, and you do this by submitting your username and password. You can't access any other part of your Google account through Windows Live Mail. It's just the same as when you access any other mailbox - at your ISP, at Outlook.com or wherever. And, to cap it all, your credentials are passed to Gmail through a TLS-secured tunnel, which is exactly the same as OAuth uses.
Just make sure that your security protocols are enabled like this at Control Panel > Internet Options > Advanced: