When it comes to discussing the website, I would like to (annoyingly) point out, that HTTPS should be the first priority

Why?
If I remember rightly it uses a client side Java environment which populates / fuels the pages so the likelyhood of HTTPS representing any additional value to security are................................
Well, some man-in-the-middle can still be done. The attacker cannot get your password, but they can change the site ever so slightly, e.g. the deposit address, and then it is already unpleasant. Disclamer: I am not using coinlender services, so it could be that some sort of MIM protection is already in place.