Insecure site? Unknown_html_RFI_shell

See error fail and warnings on the asafaweb scan: https://asafaweb.com/Scan?Url=www.neyzenyachting.com
Trace.error for http://www.neyzenyachting.com/trace.axd & 404 - File or directory not found.

IP badness: https://www.virustotal.com/nl/ip-address/184.168.224.176/information/
http://sameip.net/ip184.168.224.176 - http://www.ip-finder.me/184.168.224.176/#collapseOne blacklisted

All green http://toolbar.netcraft.com/site_report?url=http%3A%2F%2Fwww.neyzenyachting.com%2F

Errors and warnings: http://www.dnsinspect.com/neyzenyachting.com/1415293030

Javascript analysis: http://jsunpack.jeek.org/?report=985f4dea9f966f56635f1afa47a75527c52888c2
Code-hickup: www.neyzenyachting.com/kb-plugin/js/jquery.themepunch.kenburn.js benign
[nothing detected] (script) wXw.neyzenyachting.com/kb-plugin/js/jquery.themepunch.kenburn.js
status: (referer=wXw.neyzenyachting.com/)saved 70095 bytes 4e924d6d6b6bda09f45bf222dda171723b3804e2
info: [img] wXw.neyzenyachting.com/kb-plugin/js/
info: [decodingLevel=0] found JavaScript
suspicious:

Quttera gives potentiallly suspicious: /js/jquery.hashchange.min.js
Severity: Potentially Suspicious
Reason: Suspicious JavaScript code injection.
Details: Procedure: + has been called with a string containing hidden JavaScript code .
Threat dump: http://jsunpack.jeek.org/?report=12d295fdf1d9162e7770288980013289b556a24a
Threat dump MD5: E0D0AF8E6A71A5B9CC9026F3F82F4871
File size[byte]: 1526
File type: ASCII
Page/File MD5: 757898A5793D29189E52CA6EE8FCE808
Scan duration[sec]: 0.173000

XSS vuln. Results from scanning URL: http://jsunpack.jeek.org/?report=55515a62858e0b09569168d094efbb2ec5796f6d
Number of sources found: 43
Number of sinks found: 20

Results from scanning URL: http://jsunpack.jeek.org/?report=d6b47a4c46d3c04f24d07116ce8c1f0eca04a1f8
Number of sources found: 30
Number of sinks found: 5
Exploitable
error: undefined variable jQuery
error: undefined function $.widget
error: undefined variable $

pol