An extremely brief glance at your source shows that you're loading 3rd party javascript from two different hosts, one being Google.
Are you sure you know what you're doing?
When you connect to the domain with torbrowser, the server detects your IP, then redirects to the appropriate .onion site if coming from an exit node. In order to be MITM'd, you'd have to either be using a Tor exit node that was compromised, or my server would have to be completely compromised beforehand.
neither of these seem like likely scenarios, so I'm curious as to what you see that I don't.
However, that's not too much an issue. we don't offer binaries (outside of two pdf files that may have a jpg embedded), and nothing on our Onion site requires a download. The most they could really do is make someone give bitcoins to the wrong wallet. That's a pretty easy customer service issue to solve ("We are not responsible for bitcoins sent to wrong wallets").
I guess I'm not seeing the vulnerability here.
If you'll notice, our website does not use broken encryption (because SSL delivered by OpenSSL is a joke anyway). And we currently require you to install Tor Browser in order to have dependable encryption before purchasing.
Either way, thanks for looking at our website!