That is a valid call to our extension. That URL is what Facebook will hit whenever a user tries to delete your application. I just, quickly, looked at the code and I don't see any method where a SQL injection or other vulnerability could be exposed in that call. JFBConnect has also never had a security vulnerability.
If there's any details you could provide about why you think it's a hack, any of the details of what information is in the POST request or the IP addresses that are hitting that URL, it will help us investigate further.
Thanks,
Alex