Blacklisted site - but has it still remote file inclusion malware?

See: http://www.urlvoid.com/scan/moneyfactoryspain.es/
and http://urlquery.net/report.php?id=1687836 earlier detection of iFrame malware: http://urlquery.net/report.php?id=1678136
Now given clean here: http://zulu.zscaler.com/submission/show/8ae8524f1338bca004ff0d00b46a20d9-1364647266
WP outdated: Wordpress internal path: /home/moneyfac/public_html/wp-content/themes/Alpha/index.php
Blacklisted on Yandek via Sophos: http://www.yandex.com/infected?url=moneyfactoryspain.es&l10n=en
http://yandex.ru/infected?l10n=en&url=http://www.moneyfactoryspain.es/
See: http://evuln.com/tools/malware-scanner/http%3A%2F%2Fwww.moneyfactoryspain.es%2Ftag%2Fgrosz%2F/
Senderbase report neutral: http://www.senderbase.org/senderbase_queries.detailip?search_string=109.203.124.251 (neutral RBN)
But unknown_html_RFI_shell malware flagged here: http://support.clean-mx.de/clean-mx/viruses.php?id=9917055
hacked via wordfence_logHuman&hid=

polonus