The site links to a site that accepts payment data. So because the author's site is http, a MITM attacker could change the payment links from lulu.com to site-that-actually-steals-your-credit-card.com.
That's one huge thing https provides over http.. assurance of unadulterated content, including links to sites that actually deal in sensitive data.