That is probably based solely on the fact that is it HTTP: not HTTPS: Simply because HTTP traffic is not encrypted doesn't mean there is a problem, it just means that it is possible for a 3rd party to intercept it. There's no secure information/passwords/financial transactions etc. on the page so pffff.
... or are they claiming some other security risk?