[My home computer] --> SSH --> [my hardcore IndieWeb local cloud]
That's about it. Safe enough.
In 25 years of hosting a dozen domain names on a server on my home connection, this problem has not surfaced for me.
For someone who knows what they are doing, it's more like mosquito noise, a mere nuisance, but even then, using a rock solid system with all updates installed carries the risk of having a zero-day.
If your server is networked to the rest of the house, and if somebody manages to get in, then it's all fun(!).
Especially if you host something like wordpress with plugins you really have to be on the ball with updates.
That said, the practice of running a modern corporate web browser that auto-executes all programs sent to it from arbitrary unknown third parties is a way, way, way bigger and more common and likely attack surface than a simple static webserver serving files in directories.
They have poor reputations and are blocked from streaming sites and so on. But when you're the server, that doesn't affect you.
Note that you need a static v4 and DMZ because the tunnel protocol is a very simple one - presumably because they run it on giant routers. It just puts a v4 header in front of the v6 header. No TCP or UDP.
I don't think ipv6 only is feasible yet unless your audience is exclusively in Asia where ipv6 uptake is much higher due to them running out of ipv4 years ago