Hi everyone, thank you for your patience.
to be clear, everything has been al sorted out and this was really a matter of misunderstanding between WordPress and Wordfence.
The short answer is that we were removed from the WordPress repo due to a copyright infringement as we had both FB and Twitter logos on our banner. Once these were removed, we were reinstated into the WordPress repo as you can see. Unfortunately, we need to wait for the WordPress team (who you can imagine is extremally busy) to audit and approve our updates to the banner and confirm that we are in fact not in copywrite violation.
Regarding the security risk, WP Remote is echoing what Wordfence is reporting. The Wordfence issue was a separate matter and technically not a real threat which is why they list it as a 5.4 out of 10 on their website.
First they made a typo by listing it as 4.4 and they have fixed that typo.
Secondly there was an issue that allowed one logged in user to temporarily disconnect another users FB token. To which we asked Wordfence, “Who would go through all that hassle to trick someone into disconnecting Facebook.” and they agreed it is very minor but it is technically an “issue” they need to report.
We have fixed this with one line of code and version 4.3.1 is getting approved as we speak.
Thank you all for your patience.