Of course it affects the average user, if nothing else then by showing that the browser can’t be trusted.
If the people making the browser is willing to alter the Web pages people visit to steal money once, what makes you think they aren’t willing to do so again for any number of reasons?
Because caddy has built in, and default enabled, SSL of all sites using letsencrypt, something nginx doesn’t have from what I can see.