It doesn't make a difference. Just because a site is SSL-encrypted doesn't make it a site you should trust with your paypal credentials.
The only site you should trust with your paypal credentials is paypal. And the only way to be sure you're talking to paypal is to see paypal in the address bar with an SSL-encrypted session. (At least, that's what the whole web, browsers and CA's alike, have been striving to ensure is the case since the web has had encryption.)
You're not getting the core issue - the way real gateway works cannot be distinguished from phishing. "seamless" user experience confuses users and is going to create a whole new wave of phishing
The problem is that Github could open a popup with a form that looks the same, and you wouldn't be able to tell that you're not sending your credentials to Paypal only