Carnster,
That's a real vague answer. Cross site scripting is a big deal, no doubt, but you'd need to understand a lot more about where the problem is coming from and where the susceptibility lies.
Do you have reason to believe the test is failing because of JFBConnect? Do you have any information about what their test has detected? That would help us to understand more, and possibly help fix the issue if it's is indeed related to our extension.
Thanks,
Alex