There is no such thing as a static website
blog.wesleyac.com
blog.wesleyac.com
Static sites are very difficult to knock over, there's no pile of PHP or Java or whatever and no database to sneak SQL into and no serverside tools to maintain. Their "source" lives on and is backed up from the developer infrastructure, and is merely deployed out to the server; if it blew up you could deploy it somewhere else in seconds and point the DNS at that instead. That is the major reason people use them.
From a security perspective this distinction matters, because if there's no code runtime/interpreter on the webserver, then the runtime/interpreter can't get hacked by a malicious request (or a flood of requests), while shipping all your frontend source code to the user might have security implications too. This decision also impacts costs and latency.