Am I misunderstanding this one? GET still sends information to another server, what is the "read only" aspect?
GET requests are also easier to be abused in Cross Site Request Forgery (CSRF) attacks. Modern countermeasures in browsers (like SameSite cookies) will protect cross-origin POST and other state-changing methods, but will largely allow GET requests to go through while carrying session cookies.
Of course, some websites may permit mutations through GET so it’s probably only sensible to use alongside known hosts.