
One Accessibility – Making Your Site Accessible to Everyone Security & Risk Analysis
wordpress.org/plugins/website-accessibilityMake your site accessible to everyone with advanced tools, WCAG compliance, and customization for a truly inclusive experience.
Is One Accessibility – Making Your Site Accessible to Everyone Safe to Use in 2026?
Generally Safe
Score 100/100One Accessibility – Making Your Site Accessible to Everyone has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The website-accessibility plugin v1.2.7 demonstrates a generally strong security posture, with notable strengths in its handling of SQL queries and output escaping. The absence of dangerous functions, file operations, and critical/high severity taint flows is commendable. The plugin also adheres to good practices by using prepared statements for all SQL queries and properly escaping all identified output points.
However, concerns arise from the plugin's attack surface. A significant portion of its REST API routes, specifically 3 out of 5, lack permission callbacks. This means these routes are potentially accessible without proper authentication, creating an entry point for unauthorized access or manipulation if sensitive actions are performed or data is exposed.
Furthermore, the plugin has no recorded vulnerability history, suggesting a potentially low risk of exploitation due to past issues. This, combined with the use of nonces and capability checks on some entry points, paints a picture of a plugin that is actively trying to implement security measures. The main weakness lies in the unprotected REST API endpoints, which require immediate attention to mitigate potential risks.
Key Concerns
- REST API routes without permission callbacks
- AJAX handlers without authentication checks
One Accessibility – Making Your Site Accessible to Everyone Security Vulnerabilities
One Accessibility – Making Your Site Accessible to Everyone Code Analysis
Output Escaping
One Accessibility – Making Your Site Accessible to Everyone Attack Surface
AJAX Handlers 1
REST API Routes 5
WordPress Hooks 20
Maintenance & Trust
One Accessibility – Making Your Site Accessible to Everyone Maintenance & Trust
Maintenance Signals
Community Trust
One Accessibility – Making Your Site Accessible to Everyone Alternatives
Everyone Accessibility Suite
everyone-accessibility-suite
A lightweight WordPress accessibility plugin with an accessibility widget and accessibility panel to improve accessibility compliance and usability.
WCAG Admin Accessibility Tools
wcag-admin-accessibility-tools
Accessibility diagnostics and tools for alt text, contrast, vague links, and more.
Ally – Web Accessibility & Usability
pojo-accessibility
Ally: Make your site more inclusive by scanning for accessibility violations, fixing them easily, and adding a usability widget and accessibility stat …
WP Accessibility
wp-accessibility
WP Accessibility fixes common accessibility issues in your WordPress site.
AccessibleWP – Accessibility Toolbar
accessible-poetry
Add a professional accessibility toolbar to your WordPress site and make it easier for users with disabilities.
One Accessibility – Making Your Site Accessible to Everyone Developer Profile
24 plugins · 251K total installs
How We Detect One Accessibility – Making Your Site Accessible to Everyone
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/website-accessibility/build/css/frontend.css/wp-content/plugins/website-accessibility/build/css/frontend.min.css/wp-content/plugins/website-accessibility/build/js/frontend.js/wp-content/plugins/website-accessibility/build/js/frontend.min.js/wp-content/plugins/website-accessibility/build/js/frontend.js/wp-content/plugins/website-accessibility/build/js/frontend.min.jswebsite-accessibility/build/css/frontend.css?ver=website-accessibility/build/css/frontend.min.css?ver=website-accessibility/build/js/frontend.js?ver=website-accessibility/build/js/frontend.min.js?ver=HTML / DOM Fingerprints
wapwap-frontendwap-admindata-websac-settingswebsacFrontend/wp-json/websac/v1/settings/wp-json/websac/v1/preferences