Absolutely. The privacy of library searches has long been viewed as one of the archetypal examples of why privacy matters. A user's ISP shouldn't be able to learn what sort of books, movies, and music a library patron is interested in. And that's before we get into matters like injection of malicious content by local miscreants at your favorite cafe, or ads by mobile networks. Fundamentally, it's an issue of your users being the ones deciding what they do and do not care about being secure, and security being the default (could you imagine the emotional hurdle someone who has a real need for their privacy when using the library website would have to go through to explicitly ask for it?). The Library Freedom Project, who has been in the news a lot as of late, was in part started to push the use of SSL in all libraries, even if you "don't need it."
https://libraryfreedomproject.org/ourwork/digitalprivacypled...
https://github.com/EbookFoundation/library-privacy-pledge/wi...
You might be interested in this list of web hosts that support Let's Encrypt[1]. Generally speaking, your hoster should be able to provide a one-click interface for obtaining and installing a certificate for you, and odds are most hosts will eventually do so free of charge once HTTPS becomes mandatory.
[1]: https://github.com/letsencrypt/letsencrypt/wiki/Web-Hosting-...
You don't need logins/user accounts for your users to be identified. IP is sufficient in many cases, and browser fingerprint pretty much covers the other cases.
Also, if the website ever has need to become more complex, it will be easier and less error prone not to have to throw 'figure out how to implement TLS' on the pile of tasks.
Also, if permissions are the primary concern, might I recommend moving to a host that does SSL/TLS for you? Webhosts have come a long way in the last few years. Moving to a nicer one may actually save you effort in the long run.
- Increased resistance to surveillance. Instead of seeing the pages/information that a client downloads from your server, state actors, ISPs, local attackers, and anyone else listening only learn that the client downloaded some bytes from your server.
- Mitigation of man-in-the-middle and man-on-the-side attacks against your website. These can be as simple as someone attacking a local open Wi-Fi access point to sophisticated attacks like the Chinese DDoS against GitHub and the NSA's QUANTUM INSERT. Potential attacks range from replacing/rewriting information to attacking client machines with browser exploits.
- Better SEO rankings, Google weighs HTTPS sites higher than their equivalent insecure plaintext.
If you need a shared host that supports HTTPS, take a look at DreamHost, they have a free one-click Let's Encrypt integration.
It is probably more important that you do TLS/SSL than not do it because you are uncomfortable with Letsencrypt setup
here's the one I buy - https://www.ssls.com/ssl-certificates/geotrust-rapidssl
If we are not just being hypothetical, a simple solution for you could be to register with cloudflare and run your site behind that. They will give you a free ssl certificate. This isn't as secure as running your own, since the connection between cloudflare and your server is in plain http, but it's a lot better. As an added bonus, you get a free caching layer in front of your site, which might be a good thing if you're on a small shared host.