Most eCommerce sites do not deploy SSL site-wide, but only on login and checkout actions. Look at Amazon, Wayfair, etc. Depending on how the site was coded, you can mitigate session hijacking over HTTP. I'd love to see examples of Amazon session hijacking because product browse pages are simply over HTTP, I think you'll find that it's not possible to hijack those sessions.