Earlier quoted context omitted.
How do you know your users are seeing "a static site with no login and mostly PDFs"? Security is a state of mind, indeed.
I know because I make the site and use it too
* Inject a cryptocurrency miner JavaScript into your page during the transmission of your static HTML page to your clients, without you or your users knowing it [1]
* Injecting explicit, illegal image material that would get your clients immediately in legal trouble for possession of such material, without you knowing
* Injecting a JS snippet that, instead of your site's contents, shows a fake antivirus page, telling the clients that your site is malicious and that a threat was eliminated by Fake Antivirus 10.0 and that they should immediately call Microsoft Support (Phone number in Bangladesh) for further "assistance". There they're told they need to get a full cleaning of the hard drive for only 99$ and are asked for their CC number
The point is: If you don't have end-to-end-encryption, you can never be sure what your users see. They might see your site - or some slightly modified version of your site, with a login box, phishing passwords from your users, abusing their trust in your brand.
A MITM has nothing to do with someone gaining access to your server. It's someone gaining access to infrastructure - a vulnerable public wifi, for instance.
[1] https://www.hacking.reviews/2018/01/coffeeminer-collaborativ...