“I switched my nameservers to Cloudflare in order to enable R2 bucket serving through my own subdomain, and I found out that it silently had injected a JS analytics snippet in my HTML-only JS-free site.”

A JS-free site got JavaScript added to it without the owner asking. Turning it off means finding the Analytics dashboard, adding the site, and then disabling the snippet. That is three steps to undo something nobody opted into. Cloudflare sits in front of a huge share of the web and treats modifying your HTML as a default-on convenience.