Why does http://ubuntu-mate.org/ not redirect to https://ubuntu-mate.org/?

This is the answer:

We are planning to switch to HTTPS only in future.

However, if you are to download the desktop ISOs of any flavour of Ubuntu, which are hosted by Canonical, their server only supports HTTP: Index of /ubuntu-mate/releases. This is out of our control.

It would be wise to securely get the SHA256SUM (checksum) of the file and compare it when downloading over HTTP.