I usually allow websites to run their first-party scripts on their own domain without much of a second thought (using NoScript on Firefox). But my threat model is likely more lax than yours.
I wish more people used Anubis instead of Cloudflare, I am a little concerned with how often I have to allow the latter to run their script to even access a website...