PGP tried "web of trust" and it never really got off the ground, except within very small groups. (I mean, PGP is used all the time; but actual traceable webs of trust among keys are rare.)

Also you don't have to pay anything for a signed cert. I use Let's Encrypt on my personal servers; at work we have access to InCommon certificates.

