
Max Access – DEPRECATED (new plugin available) Security & Risk Analysis
wordpress.org/plugins/max-accessVersion 2.0.0 Requires PHP: ^5.6 License: GPLv2 or later License URI: http://www.gnu.org/licenses/gpl-2.0.html Add front-end WCAG compliant accessibi …
Is Max Access – DEPRECATED (new plugin available) Safe to Use in 2026?
Generally Safe
Score 92/100Max Access – DEPRECATED (new plugin available) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "max-access" v2.0.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, using prepared statements for all SQL queries, and having no recorded vulnerabilities. However, the plugin has a significant security concern due to its attack surface. It exposes one AJAX handler without any authentication or capability checks, making it a prime target for unauthorized actions. This lack of protection on a critical entry point is a major weakness.
The taint analysis revealed one flow with an unsanitized path, which is a serious concern even without a critical or high severity rating. This suggests that user-supplied data might be processed in an unsafe manner, potentially leading to vulnerabilities if exploited. The absence of nonce checks on the unprotected AJAX handler further exacerbates this risk, as it facilitates Cross-Site Request Forgery (CSRF) attacks.
While the plugin's vulnerability history is clean, indicating good development practices historically, the current static analysis results highlight immediate and actionable security risks. The combination of an unprotected AJAX endpoint, an unsanitized path flow, and a lack of nonce checks creates a substantial security gap that needs to be addressed to improve the plugin's overall security.
Key Concerns
- Unprotected AJAX handler
- Flow with unsanitized path
- Missing nonce checks on AJAX
- Output escaping (50% proper)
Max Access – DEPRECATED (new plugin available) Security Vulnerabilities
Max Access – DEPRECATED (new plugin available) Release Timeline
Max Access – DEPRECATED (new plugin available) Code Analysis
Output Escaping
Data Flow Analysis
Max Access – DEPRECATED (new plugin available) Attack Surface
AJAX Handlers 1
WordPress Hooks 4
Maintenance & Trust
Max Access – DEPRECATED (new plugin available) Maintenance & Trust
Maintenance Signals
Community Trust
Max Access – DEPRECATED (new plugin available) Alternatives
Web Accessibility by accessiBe
accessibe
Fix accessibility issues & make your site accessible with an AI-powered accessibility service.
Web Accessibility with Max Access
accessibility-toolbar
The ultimate web accessibility plugin. Leverages AI to scan your site, fix website code, and improve SEO. Includes the web accessibility toolbar.
Accessibility Enabler
accessibility-enabler
This plugin increases compliance with WCAG 2.0, ADA , Section 508 without changing your website’s existing code.
Ally – Web Accessibility & Usability
pojo-accessibility
Ally: Make your site more inclusive by scanning for accessibility violations, fixing them easily, and adding a usability widget and accessibility stat …
Accessibility Widget by OneTap – Easy One-Click Accessibility Toolbar
accessibility-onetap
OneTap is a multilingual WordPress plugin designed for seamless website accessibility.
Max Access – DEPRECATED (new plugin available) Developer Profile
3 plugins · 2K total installs
How We Detect Max Access – DEPRECATED (new plugin available)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/max-access/src/admin.js/wp-content/plugins/max-access/src/style.css/wp-content/plugins/max-access/src/admin.jsHTML / DOM Fingerprints
ajax_objectoada_ma_license_keyoada_ma_license_url<div id="oada_accessibility_toolbar_admin"></div>