I was biting my tongue about this, but I must agree, it grinds my gears that at least the login page does not use https. (And if you have it for the login page you might as well have it for the entire site.) Passing login credentials in the clear is IMHO simply not acceptable, especially given the ease of procuring even free SSL certificates (https://letsencrypt.org/) these days. I mean, even little me runs my own mail server that has (LetsEncrypt) SSL both for the mail server and the web interface. It's not that hard.