
Accessibility Security & Risk Analysis
wordpress.org/plugins/accessibilityAn advanced plugin, that immediately applies key accessibility features on your WordPress website.
Is Accessibility Safe to Use in 2026?
Generally Safe
Score 99/100Accessibility has a strong security track record. Known vulnerabilities have been patched promptly.
The 'accessibility' plugin v1.0.9 presents a mixed security profile. On the positive side, the static analysis reveals excellent practices regarding SQL queries, with all using prepared statements, and a high percentage of output being properly escaped. The absence of file operations and the presence of nonce checks are also encouraging signs. However, the plugin's vulnerability history is a significant concern, with three medium-severity CVEs recorded, including Cross-Site Request Forgery and Cross-Site Scripting. Although none are currently unpatched, this pattern suggests a recurring susceptibility to common web vulnerabilities.
The taint analysis, while not revealing critical or high severity flows, did identify two flows with unsanitized paths. While the attack surface is reported as zero entry points, these unsanitized paths could potentially be exploited if a suitable entry point were to be discovered or introduced in future versions. The lack of capability checks on any entry points is also a notable weakness, although the current reported zero entry points mitigates this immediate risk. The external HTTP request is also a potential, albeit small, vector if the target service is compromised.
In conclusion, the plugin demonstrates strengths in secure coding practices for SQL and output handling. However, the historical pattern of medium-severity vulnerabilities and the presence of unsanitized paths in taint analysis warrant caution. The absence of capability checks, while currently benign due to a zero attack surface, is a potential area for future risk. Ongoing vigilance and prompt patching of any future vulnerabilities will be crucial.
Key Concerns
- Two flows with unsanitized paths found
- 3 medium severity CVEs in history
- 1 external HTTP request
- 0 capability checks on entry points
Accessibility Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Accessibility <= 1.0.6 - Cross-Site Request Forgery
Accessibility <= 1.0.2 - Authenticated (Administrator+) Stored Cross-Site Scritping
Accessibility <= 1.0.3 - Authenticated (Administrator+) Stored Cross-Site Scripting
Accessibility Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Accessibility Attack Surface
WordPress Hooks 5
Maintenance & Trust
Accessibility Maintenance & Trust
Maintenance Signals
Community Trust
Accessibility Alternatives
AccessibleWP – Accessibility Toolbar
accessible-poetry
Add a professional accessibility toolbar to your WordPress site and make it easier for users with disabilities.
WP Accessibility Helper (WAH)
wp-accessibility-helper
Short Description WP Accessibility Helper helps solve accessibility problems
Ally – Web Accessibility & Usability
pojo-accessibility
Ally: Make your site more inclusive by scanning for accessibility violations, fixing them easily, and adding a usability widget and accessibility stat …
Accessibility by UserWay
userway-accessibility-widget
UserWay’s Accessibility Widget creates a simpler and more accessible browsing experience for your users.
WP Accessibility
wp-accessibility
WP Accessibility fixes common accessibility issues in your WordPress site.
Accessibility Developer Profile
1 plugin · 2K total installs
How We Detect Accessibility
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/accessibility/assets/css/admin-style.css//acc.magixite.com/freeCode?oatk=w0rdpre55//acc.magixite.com/license/lw?litk=admin-styleaccessibilityHTML / DOM Fingerprints
oc-accessibility-adminoctLoader