Earlier quoted context omitted.
Explain to me like I'm five what features a website that hosts it's own javascript can't have versus one that loads those same javascripts from remote source?
It can't have the features that would have been built, in the time spent learning about and implementing security. I regard nearly all security for startup-class, low-user, and low-value companies to be premature optimization, which is deadly to a new project's potential.
I can't see anybody working on user-less websites anyway but I sincerely hope that you'll make it plain which start-ups you work for so I can avoid them. Security and abuse potential are very important for start-ups because you have only one reputation and if you lose that you're pretty much done for.
I can point you to several pretty harsh reminders of how start-ups that don't take end-user security serious can end up.