PuTTY is MIT licensed.
The primary author of PuTTY is unserious about traceable code, which is a shame, because as your essay implies, PuTTY is one of the motivating cases for traceable code. It's an actual lucrative real-world target for surreptitious replacement.
Clearly, the world cannot rely on PuTTY's author to provide a traceable download. Someone else needs to step in and do that.
That person can set up an HTTPS site, arrange to have their certificates pinned, get PGP-signed endorsements from people like you, the EFF, whatever, and --- given how awful PuTTY's SEO mojo is, easily take the top of the Google SERP for PuTTY with a reliable, traceable alternative.
What any of this has to do with WebCrypto is beyond me.