Take a look at certbot. You don't need to pay for ssl and ssl is actually pretty mandatory for anything served on the internet.
Make sure you don't forward too much ports. And make sure you have a working firewall that only allow those same ports. You should be good to go then.
Was going to say exactly the same thing.
Even if your router have one, better safe than sorry!