I’ve seen several ISPs inject things as well. No excuse for http anymore. No rewards, only risks and punishments.
You're not paying him anything to read his website. He does not owe you a single thing.
I’ve used dozens of ISPs and never had this problem. Guess I’m lucky.
I don’t care if people inject stuff into my http content. If it becomes a significant problem, I’ll think about it.
Simplicity is a reward. A big reward.