We should dynamically compute a hash of the source files client-side and compare it with a previous hash validated by a trusted third party and available online. If they don't match, the client displays a red warning :)
I don't understand this point. In any case, the point is that we may trust your site today, but it may be compromised in the future. In which case it also can't be trusted to show any sort of warning.
Good idea in theory but it doesn't really work.
If someone (like you) can change the code that the client gets then they can simply remove or fake the hash checking code.