For the Chrome extension, you probably don't need to request permissions on tosdr.org. If you send CORS headers from that site, you will be able to make requests to it without the permissions.
With any CA's (or better, the right one's) private key, they could still use it to stage a MITM attack on the website, assuming they have the right access.
Even having an email address to send reports to would be good for a lot of websites. I sometimes don't bother reporting these issues for fear of being threatened with legal action.
> Also, on other note: username is Not an email address. Do not ask me for my username when you really mean email address.
Are you saying that sites should allow users to use email addresses to log in, rather than usernames? As I understand it, the former is a more recent thing.