>it sure is something that offers very little value for very many site owners.
Because it's not meant to offer value for a site owner, it's meant to offer value to the user.
When I type a password on your website, I'm the one that has the most to lose there. When I type my credit card or other personal information into a site, I'm the one that will need to spend time and money getting control of my information if it was stolen.
When I am browsing the web and ads are being injected into the HTTP request, or my ISP is dragnet datamining, or a compromised router is injecting malware into every page, I'm the one that loses, not you.
The argument that an insecure website is easier to maintain than a secure website is like saying "a car without airbags is easier to work on". The extreme vast majority don't care about how easy it is to maintain the site, they care about their privacy and security.
And your counterpoint is needing to download and run some open-source software once a month (or automate the process and never touch it again). A few years ago that would have been a much larger list, but developers were listening to the complaints, and realized that the only way to a fully secure web was to make this process easier, so they did!
It's easier than ever to enable HTTPS on every website, and in the vast majority of cases it's a net improvement for users.