Security Headers Are the Cheapest Insurance a Static Site Can Buy
Date Published

No server-side code doesn't mean no risk — a static site still serves HTML that can be targeted by cross-site scripting if it ever renders anything user-supplied, still loads third-party scripts that could be compromised upstream, still benefits from the same baseline headers that protect any other site.
A Content Security Policy, strict transport security, and the handful of other headers that go with them cost essentially nothing to configure at the hosting layer and close off entire categories of attack that have nothing to do with how the page was rendered.
The reason this gets skipped isn't difficulty, it's that a static site's actual risk feels low enough that the headers seem optional — right up until a compromised third-party script or a misconfigured redirect proves otherwise, at which point the fix that would have taken twenty minutes becomes an incident response.