Equalweb Accessibility Security & Risk Analysis

wordpress.org/plugins/equalweb

Make your website accessible and compliant with EqualWeb AI-powered accessibility widget & monitoring scans. EqualWeb offers real-time accessibili …

4K active installs v1.0 PHP 5.6+ WP 4.7+ Updated Apr 3, 2025
accessibilitydigital-accessibilitywcagweb-accessibilitywebsite-accessibility
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Equalweb Accessibility Safe to Use in 2026?

Generally Safe

Score 92/100

Equalweb Accessibility has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "equalweb" v1.0 plugin exhibits a generally positive security posture based on the provided static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, which significantly limits the potential attack surface. Furthermore, the code signals indicate a complete absence of dangerous functions and file operations. Crucially, all SQL queries are stated to use prepared statements, and there are no external HTTP requests or bundled libraries that could introduce known vulnerabilities. The taint analysis also reports no identified flows with unsanitized paths, suggesting that data manipulation might be handled safely.

However, a significant concern arises from the output escaping metric, which shows that 100% of the 17 identified outputs are not properly escaped. This is a critical weakness that could lead to Cross-Site Scripting (XSS) vulnerabilities if any user-provided or dynamic data is reflected directly in the output without sanitization. The lack of nonce checks and capability checks on any potential entry points (though none were found) is also a point of caution, as these are fundamental WordPress security mechanisms. The plugin's vulnerability history being entirely clear is a strength, but it doesn't negate the immediate risks identified in the code analysis.

In conclusion, while the "equalweb" v1.0 plugin has a commendably small attack surface and avoids common pitfalls like raw SQL queries and dangerous functions, the pervasive lack of output escaping presents a serious risk of XSS vulnerabilities. This needs to be addressed urgently to improve the plugin's security. The absence of historical vulnerabilities is positive, but proactive security measures for existing code are paramount.

Key Concerns

  • All outputs are unescaped
Vulnerabilities
None known

Equalweb Accessibility Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Equalweb Accessibility Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
17
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped17 total outputs
Attack Surface

Equalweb Accessibility Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_initequalweb.php:57
actionadmin_initequalweb.php:58
actionadmin_menuequalweb.php:59
actionadmin_enqueue_scriptsequalweb.php:60
actionwp_footerequalweb.php:63
Maintenance & Trust

Equalweb Accessibility Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 3, 2025
PHP min version5.6
Downloads12K

Community Trust

Rating100/100
Number of ratings2
Active installs4K
Developer Profile

Equalweb Accessibility Developer Profile

EqualWeb Accessibility

1 plugin · 4K total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Equalweb Accessibility

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/equalweb/assets/img/wp-plugin-logo.png/wp-content/plugins/equalweb/assets/img/wp-plugin-logo-small.png/wp-content/plugins/equalweb/assets/img/wp-plugin-step-1.png/wp-content/plugins/equalweb/assets/img/wp-plugin-step-2.png/wp-content/plugins/equalweb/assets/img/wp-plugin-step-3.png/wp-content/plugins/equalweb/assets/img/wp-plugin-arrow-down_anim.gif/wp-content/plugins/equalweb/assets/img/wp-plugin-js-code.png/wp-content/plugins/equalweb/assets/img/wp-plugin-banner.jpg+3 more

HTML / DOM Fingerprints

CSS Classes
equalweb-settingsequalweb-settings-innerleft-sidetop-logobigsmallmain-text-wraptext-2+8 more
Data Attributes
equalweb_activation_redirectequalweb_enableequalweb_codeequalweb_group
FAQ

Frequently Asked Questions about Equalweb Accessibility