It seems the author is very focused on signing with x509. I'm wondering if they are aware of free alternatives like signify or pgp that would work just as well (minus the windows UAC thing). Right now there are only checksums but no way to verify they are from the author and are distributed on the same server as the binary, so the only security layer is https.
The blue UAC prompt and no warning message is the main point, though.
In theory users could manually verify a PGP-signed executable, but that's well outside of the average Windows user's knowledge.