
Accessibility Widget by OneTap – Easy One-Click Accessibility Toolbar Security & Risk Analysis
wordpress.org/plugins/accessibility-onetapOneTap is a multilingual WordPress plugin designed for seamless website accessibility.
Is Accessibility Widget by OneTap – Easy One-Click Accessibility Toolbar Safe to Use in 2026?
Generally Safe
Score 100/100Accessibility Widget by OneTap – Easy One-Click Accessibility Toolbar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'accessibility-onetap' plugin v2.10.0 demonstrates a mixed security posture. On the positive side, it uses prepared statements for all SQL queries, and 99% of its outputs are properly escaped, significantly reducing the risk of SQL injection and cross-site scripting vulnerabilities. The absence of any known vulnerabilities or CVEs in its history is also a strong indicator of a well-maintained and secure codebase. However, the plugin presents a notable concern regarding its attack surface. A significant portion of its entry points, specifically 5 out of 6 total, lack proper authentication checks. This includes all 5 AJAX handlers, which are common targets for malicious actors. While no critical taint flows or dangerous functions were identified in the static analysis, the large number of unprotected entry points means that if any subtle vulnerability exists, it could be easily exploited. The plugin also implements nonce checks on all its AJAX handlers, which is a good practice, but this is undermined by the lack of capability checks on these same handlers.
Key Concerns
- Unprotected AJAX handlers
- Limited capability checks on entry points
Accessibility Widget by OneTap – Easy One-Click Accessibility Toolbar Security Vulnerabilities
Accessibility Widget by OneTap – Easy One-Click Accessibility Toolbar Code Analysis
Output Escaping
Accessibility Widget by OneTap – Easy One-Click Accessibility Toolbar Attack Surface
AJAX Handlers 5
Shortcodes 1
WordPress Hooks 20
Maintenance & Trust
Accessibility Widget by OneTap – Easy One-Click Accessibility Toolbar Maintenance & Trust
Maintenance Signals
Community Trust
Accessibility Widget by OneTap – Easy One-Click Accessibility Toolbar Alternatives
AccessYes Accessibility Widget for ADA, EAA & WCAG Readiness
accessibility-widget
Free accessibility widget to support WCAG, ADA & EAA. Includes text resize, high contrast, dyslexia-friendly font, spacing, and more tools.
WebAbility Accessibility Widget
webability-accessibility-widget
Easy-to-use accessibility widget that makes your website compliant with WCAG and ADA standards. Simple setup with customizable positioning.
Web Accessibility by accessiBe
accessibe
Fix accessibility issues & make your site accessible with an AI-powered accessibility service.
Equalize Digital Accessibility Checker – Audit Your Website for WCAG, ADA, and Section 508 Accessibility Errors
accessibility-checker
Find and fix accessibility issues on your website. Detailed reports, autogenerated accessibility statement and one-click fixes to improve compliance.
Accessibly – WordPress Website Accessibility
otm-accessibly
Accessibly app is a WordPress accessibility plugin that will help your website become accessible to even more of your site visitors.
Accessibility Widget by OneTap – Easy One-Click Accessibility Toolbar Developer Profile
1 plugin · 40K total installs
How We Detect Accessibility Widget by OneTap – Easy One-Click Accessibility Toolbar
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/accessibility-onetap/admin/css/accessibility-onetap-admin.css/wp-content/plugins/accessibility-onetap/assets/js/admin-menu.min.js/wp-content/plugins/accessibility-onetap/assets/js/sweetalert.min.js/wp-content/plugins/accessibility-onetap/assets/js/admin-global.min.jsaccessibility-onetap/admin/css/accessibility-onetap-admin.css?ver=accessibility-onetap/assets/js/admin-menu.min.js?ver=accessibility-onetap/assets/js/sweetalert.min.js?ver=accessibility-onetap/assets/js/admin-global.min.js?ver=HTML / DOM Fingerprints
onetap_accessibility_wrapperdata-accessibility-langadminLocalizeapop_localized_labelsOneTap