I kept the OP brief -- I seem to recall a size limit for them. And also, for the sake of the reader.
A bit more: The dashboard and domain list pages were under this ap.www.namecheap.com subdomain (new to me) with its cert from GeoTrust having the obsolete configuration -- www.namecheap.com uses one from COMODO that has more current settings. But the shopping cart and checkout pages are still under www.namecheap.com .
And, I've been having more and more problems with sites rejecting access while I'm using a PIA connection. First came the blockage from Netflix and Amazon streaming video. Then, archive.is and some others. Now Namecheap? Is Amazon next?
I'm not hiding anything in particular. But I don't want Comcast monitoring and selling my connectivity, nor feeling free to inject Javascript into it whenever it likes.
I guess it's time to set up my own VPN on some hopefully untainted IP address. But more generally, are we slowly being pushed to use our / our ISP's addressing? "True name" addressing, one site at a time?
Feels more and more like the Internet is falling under corporate and government control. Not just the snooping, but active control.
Call me paranoid.
P.S. Encountering the combination of these changes, all at once, caused me considerable pause. Credential swiping? Fraudulent sub-domain passing through the main site while harvesting data?
Ultimately, after chatting with support a couple of times and weighing what I know and have seen in the past from Namecheap, I decided to proceed. Finding the checkout pages on the main domain was also a bit reassuring, and I used a credit card that I can monitor and cancel and chargeback if necessary.
Hopefully, Namecheap will clean this up.
They've generally received favorable comments and recommendations here on HN, for years. The basis of my posting this here.