Website with hidden iFrame detected?

See: http://killmalware.com/thesumlab.org/# Now hidden iFrame no longer detected, was there 3 days ago.
WP plug-ins have latests updates: WordPress Plugins
The following plugins were detected by reading the HTML source of the WordPress sites front page.

cookie-notice latest release (1.2.32)
http://www.dfactory.eu/plugins/cookie-notice/
easy-columns
http://www.patrickfriedl.com/
sitepress-multilingual-cms
easy-social-icons latest release (1.2.4.1)
http://www.cybernetikz.com
olevmedia-shortcodes latest release (1.1.9)
http://olevmedia.com/
LayerSlider
all-in-one-seo-pack latest release (2.2.7.2)
http://semperfiwebdesign.com
juiz-last-tweet-widget latest release (1.3.4)
http://www.creativejuiz.fr/blog/wordpress/wordpress-plugin-afficher-derniers-tweets-widget
contact-form-7 latest release (4.3)
http://contactform7.com/
revslider

Warning: Warning User Enumeration is possible
Warning Directory Indexing Enabled

jQuery vulnerable library detected:
Detected libraries:
jquery-migrate - 1.2.1 : -http://www.thesumlab.org/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1
Info: Severity: medium

jquery - 1.10.2 : (active1) -http://www.thesumlab.org/wp-includes/js/jquery/jquery.js?ver=1.11.3
jquery.prettyPhoto - 3.1.5 : (active1) -http://www.thesumlab.org/wp-content/themes/Avada/js/jquery.prettyPhoto-min.js?ver=3.7.1
Info: Severity: high forgotten_disclosure_dom_xss_prettyphoto!

(active) - the library was also found to be active by running code
See: http://www.domxssscanner.com/scan?url=http%3A%2F%2Fwww.thesumlab.org%2F

Quttera gives site as clean. Excessive headers warning, HTTP only cookies Warning, Clickjacking warning given.

polonus (volunteer website security analyst and website error-hunter)