Just check it out, if any server stays more than a few hours online, you close and have them wait in line again
Imagine waiting an hour in the queue to finally be able to play on your server and then it just suddenly stops.
Exactly how can a bot / virus infect your network?
Allowing plugin uploads would enable users to keep their servers online forever. They also could run unwanted software (e.g. crypto currency miners) or even run DDOS attacks from our servers.
But why do other hosts allow it?
On other hosts, you pay money so your server is online 24/7. You also can't really use their servers to do something illegal since they usually have your payment information and therefore your name and address.
Since I'm currently in the mood, here are some other remarks about your post:
but how likely is it that someone will be able to do that?
Creating a security vulnerability in the hopes that no one will use it is a really bad idea.
Allow "Only" upload of JAR files!
Jar files are the problem. They are computer programs that get automatically executed when the server starts.
Allow FTP only for plugin servers, not for mod servers!
What's the difference? (rhetorical question)
Place ads on FTP to help you!
FTP stands for File Transfer Protocol. It's a protocol. It has nothing to do with the software you are using.