Many read only sites don't have HTTPS. Firefox and other browsers are at fault for saying it's insecure.
https://www.troyhunt.com/heres-why-your-static-website-needs...
Not having your site as HTTPS puts all of your readers at risk. Even US ISPs like that of Comcast use this very same practice to inject warnings into insecure web traffic[0]. And like mentioned in the article, promises from ISPs not to use it for advertisements are just that, promises, and those can be broken in an instant.
[0]: https://gizmodo.com/comcast-to-customer-who-noticed-it-secre...