Installed it. So far no threats from VaultPress.
 
This looks to be a bug in the easy-social-share-buttons3 plugin .
The file
/home/yourdomain/public_html/wp-content/plugins/easy-social-share-buttons3/assets/admin/themify-icons.css
is linking to fonts using:
fonts/themify.ttf?-fvbane
The ? character is a special character in URL schemes.  It allows you to pass parameters to scripts.  But the syntax for these parameters is "key=value"
The lack of an = character in this string causes the request to mimic malicious code, thus the server blocks these attempts.
 
Thanks for the share kopuy. Is this purchased or shared from another forum?
 
Thanks. I appreciate your share.
 
Is this a purchased theme?