Accessibility by AudioEye Security & Risk Analysis

wordpress.org/plugins/accessibility-by-audioeye

AudioEye automatically finds and fixes common accessibility issues on your site. This plugin provides an easy way to install AudioEye’s accessibility …

1K active installs v1.1.0 PHP + WP 5.1+ Updated Dec 16, 2025
accessibilityadacompliancemonitoringwcag
99
A · Safe
CVEs total1
Unpatched0
Last CVEDec 14, 2025
Download
Safety Verdict

Is Accessibility by AudioEye Safe to Use in 2026?

Generally Safe

Score 99/100

Accessibility by AudioEye has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Dec 14, 2025Updated 3mo ago
Risk Assessment

The accessibility-by-audioeye plugin version 1.1.0 exhibits a mixed security posture. While it demonstrates strong adherence to good coding practices such as 100% output escaping and 100% prepared statements for SQL queries, significant concerns arise from its attack surface. The plugin exposes one AJAX handler without any authentication checks, creating a potential entry point for attackers. Taint analysis shows no critical or high severity issues, which is a positive indicator. However, the vulnerability history, although currently clear of unpatched CVEs, reveals a past medium severity vulnerability attributed to "Missing Authorization." This suggests a recurring pattern of authorization weaknesses that, if not addressed, could lead to future exploitable issues. The lack of authentication on an AJAX endpoint combined with past authorization vulnerabilities presents the most immediate risk.

Key Concerns

  • AJAX handler without authentication
  • Previous medium severity vulnerability (Missing Authorization)
Vulnerabilities
1

Accessibility by AudioEye Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-64246medium · 4.3Missing Authorization

Accessibility by AudioEye <= 1.0.49 - Missing Authorization

Dec 14, 2025 Patched in 1.1.0 (6d)
Code Analysis
Analyzed Mar 16, 2026

Accessibility by AudioEye Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
20 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped20 total outputs
Attack Surface
1 unprotected

Accessibility by AudioEye Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_post_firstincludes\class-audioeye.php:158
WordPress Hooks 5
actionplugins_loadedincludes\class-audioeye.php:142
actionadmin_menuincludes\class-audioeye.php:157
actionadmin_enqueue_scriptsincludes\class-audioeye.php:161
actionadmin_enqueue_scriptsincludes\class-audioeye.php:162
actionwp_enqueue_scriptsincludes\class-audioeye.php:177
Maintenance & Trust

Accessibility by AudioEye Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedDec 16, 2025
PHP min version
Downloads19K

Community Trust

Rating66/100
Number of ratings7
Active installs1K
Developer Profile

Accessibility by AudioEye Developer Profile

netopsae

1 plugin · 1K total installs

99
trust score
Avg Security Score
99/100
Avg Patch Time
6 days
View full developer profile
Detection Fingerprints

How We Detect Accessibility by AudioEye

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/accessibility-by-audioeye/js/audioeye-admin.js/wp-content/plugins/accessibility-by-audioeye/css/audioeye-admin.css
Script Paths
/wp-content/plugins/accessibility-by-audioeye/js/audioeye-admin.js
Version Parameters
accessibility-by-audioeye/js/audioeye-admin.js?ver=accessibility-by-audioeye/css/audioeye-admin.css?ver=

HTML / DOM Fingerprints

Data Attributes
data-ae-ignore
JS Globals
params.ajaxurlparams.nonce
FAQ

Frequently Asked Questions about Accessibility by AudioEye