Do you have any 'slack' lead-in time? You could see how you get on with a regular DO/Linode VPS and forge I guess - if it feels ok then run with it :-) I've been doing sysadmin stuff for so long I kind of forget how much I know about all the weirdnesses and 'oh yeah, that'll break if you do that' stuff ;-)
I seem to remember that forge will auto-enable security updates etc so you'd only have to keep half an eye on that. I usually disable auto-updating as it's bitten me in the past though (some library updates, which then breaks something else that should have restarted to pick up the change, which then.... etc etc ;-)
I've got a few low-traffic sites on DO and never had an issue with them. They're pretty good at emailing you if there's going to be a network upgrade or whatever that might give you some downtime - but I think I've had like 5 minutes downtime in 3+ years with them.
They don't really offer 'real' private networking, dynamic scaling or the like - but sounds like you don't really need that just now (phew!) :-)
I guess backups would be your main worry for a 'oh, it's crashed and burned'. You can easily do full image backups with DO etc, but might be wise to have a small low-end box running that keeps a current-ish copy of the site & db if it's a for-money 'hello angry customer! hi!' kinda thing ;-)