If they bought from a poison vendor and then sold it to me as food, then definitely they are to blame and "safety standards" have nothing to do with it - they knew what they are buying and selling, it's not some kind of mistake or accident. Facebook buttons and tracking scripts didn't just seep into sites by accident because of poorly maintained seals or rusty firewalls and weren't fraudulently sneaked in by spies sent by Facebook - they were deliberately installed by site admins, because they wanted to install this precise code, with full knowledge of what it is for. Site admins bear responsibility for them.