something worth investigating if you don't want to buy an ssl certificate
Worldpay has the ability to upload files to a custom page for completed sales.This facility used to be hosted on their secure servers. (look for resultX in their knowledglebad). In theory what you could do is use obama_scott's theory of rewriting the template by taking the current template, hard linking in a custom header file where the base href is set to worldpay's servers, then upload your stylesheets and images to their machine even though the callback would be pointing to your shop, the images and stylesheets would be pullled from their server so the SSL errors would go away.
This just theoretical, it couldn't be built into the module for the same reasons as to why that base href could never have been altered because everyone would need different templates. Javascript menus will still not work, but the old worldpay would have been able to do this. You'd need some pretty strong coding skills, but the files that would be needed to be altered are pinpointed in Obama_scotts's posting. SIde boxes would have to be turned off too, because else you'd be needing to upload every image to their servers. So the theory would go. Point base href to rbsworldpay's user customisable zone, upload the css files and the shop logo to their server, make sure the link to get to your shop are hard coded with http in front to make sure that the customer doesn't end up going off to rbsworldpay because of the new base href tag.
The work involves by a professional would be more expensive than buying a certificate alone, but may be worth doing if you fancy a little playing around with the code. ANd if you are buying a certificate make sure to check with your host first because otherwise you may spend the money to find that they then don't install it (plus you'll need a unique ip address anyway).
Ta Ta, toodle pip.
Philip.