The login request is always sent via https, even when you are using the site over plain http. So your password should always be encrypted.
The site does work over https (try it - https://readlang.com), and at one point I redirected all http traffic to https, but there was a big problem. I use external dictionaries in an iframe to provide additional definitions and these are almost always only available over http: https://readlang.uservoice.com/knowledgebase/articles/279539...
It worked OK for a short while, but then Chrome and Firefox both refused to display http content within a https page. Chrome displays a very subtle shield icon that the user must click on to reload the page allowing mixed content. This is far too unfriendly to expect my users to do, so I had to resort to using http again :-(
Of course, the ideal solution would be for me to have access to dictionary definitions so I could integrate them properly instead of using an ugly iframe, but with 50+ languages supported, that's a tall order!