It is really hard to have vulerabilities with static html. Similarly, hosting these costs nothing. Usually in the ballpark of $3/year, the DNS alone is the dominate cost. And if they do get a sudden inrush of traffic, static hosts need to see a thousand times more load than stock wordpress before they fall down.
Come to think of it, I've never had a client that was the correct size for Wordpress. They were either way too small or way too large.