I don't think this has anything to do with "attack surface". This is simply to avoid google collecting ip addresses.
Running nginx might be marginally faster than PHP, but I believe the latency to your server will be far greater than the time it takes the server "to spin up the php interpreter" (doesn't even happen anymore when using FastCGI).
Still, neat :)