There is already a GitHub ticket for this which is being worked on:
https://github.com/ZeroK-RTS/Zero-K-Infrastructure/issues/1795cathartes: I'm assuming most people don't have that enabled, and browse the site unsecured by default. Also, Firefox tells me the site is only partially secured because external images, etc.
Some of the minor stuff is already done (but not updated in the ticket yet), but the biggest change is to
force people to use https. Is it needed? This isn't a bank, or a social networking site. There is no personal, financial or medical information to protect. So, ehh. I don't have a strong feeling either way -- would be nice, but probably not a huge priority especially considering the state of MatchMaker & balance.