21% supported HTTPS. 'Only' somewhere between 16.6% and 25.1%, depending on the amount of overlap between the 'Modified JS' and 'Modified HTML' categories, did the shady thing of modifying returned content.
I thought the point of the article was that even if they didn't do anything to your content, they could still be collecting quite a bit of your information if everything you did was over HTTP and not HTTPS.