setup SSL

self-signed is perfect, just post the hashes here and optionally GPG sign it

Or you could buy a 5$ SSL cert on namecheap with bitcoins

Or are you referring to a downloadable version?
i trust a self-signed more than a bought one, as self-signed only someone that hacks him can make fake certs, if you buy it, tonfs of organizations + ppls can create fake certs...
Doesn't that mean users will get a warning untrusted certificate when they visit the site?
Are cheap SSL's really risky?
yes they will get a warning. no matter how much you pay for your SSL cert, its still vulnerable.
the SSL system is pretty broken @ the trust part. currently SSL is mostly a scam to make tons of $$$ while serving a broken system.
in case your interested, check this out:
https://www.youtube.com/watch?v=Z7Wl2FW2TcA