Hacked and defaced website, exploitcode PHP detected by my CDAC scan extension!

See: http://killmalware.com/brontosaur.us/#
WordPress Version
4.3
Version does not appear to be latest 4.3.1 - update now.
The malware entry is cached and may not reflect the current status of the domain".
Infested:
https://sitecheck.sucuri.net/results/brontosaur.us
malscript, see: http://www.domxssscanner.com/scan?url=http%3A%2F%2Fbrontosaur.us%2F404testpage4525d2fdc
exploitcode php: https://github.com/cudeso/security-tools/blob/master/exploitcode/php/loic.php

polonus

We have examined the website in our virus lab.

It seems to have been hacked indeed; However, that is not the right reason for URL anti-malware blocking. There is no malicious code on the domain, it is safe as such.