Accessibility widgets combine public front-end output with administrator-managed settings, on-page WCAG scanning, and guided fixes that change how content is presented to visitors. Web Accessibility (formally known as Ally) – WCAG Scanning, Guided Fixes, Usability Widget version 4.1.4 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65698. The review focused on REST API authorization, the public analytics endpoint, scan and remediation data handling, SVG icon uploads, and safe rendering of administrator-controlled widget settings.

Name ofWeb Accessibility (formally known as Ally) – WCAG Scanning, Guided Fixes, Usability Widget
Version4.1.4
Active installations500,000+
DescriptionAdds a customizable front-end accessibility widget (text sizing, contrast and grayscale modes, readable fonts, link highlighting, reading mask), scans pages for WCAG/ADA issues, offers guided and AI-assisted fixes and remediations, and generates an accessibility statement.
SecuritySuccessfully tested for:
SQL Injection (SQLi)
Cross-Site Scripting (XSS) – Stored and Reflected
Cross-Site Request Forgery (CSRF)
Authentication Vulnerabilities
Authentication Bypass Exploits
Privilege Escalation
Buffer Overflow
Denial-of-Service (DoS) vectors
Data Leakage Vulnerabilities
Insecure Dependency Usage
Remote Code Execution (RCE) Risks
Unauthorized File Access
Insufficient Injection Protection
Information Disclosure via Misconfigured Endpoints
CleanTalk CertificationProudly earned the “Plugin Security Certification” (PSC) from CleanTalk, indicating adherence to stringent security standards.
Additional InformationUse Web Accessibility (formally known as Ally) with confidence backed by the “Plugin Security Certification” (PSC). Re-run accessibility scans after major content or template changes, and keep widget settings and the generated accessibility statement aligned with the features actually in use.
Plugin Security Certification by CleanTalk
Logo of the plugin

Join the community of developers who prioritize security. Highlight your plugin in the WordPress catalog.

PSC by Cleantalk

Key Features

Web Accessibility (formally known as Ally) provides a customizable front-end accessibility widget with tools such as text resizing, contrast and grayscale modes, readable fonts, link highlighting, and a reading mask. Version 4.1.4 also includes on-page WCAG scanning, guided and AI-assisted fixes, page and global remediations, an accessibility statement generator, and usage analytics, with configuration managed from the WordPress dashboard.

Security Assurance

The CleanTalk Plugin Security Certification evaluation considered capability checks and request integrity across the plugin’s REST API (ea11y/v1), validation and parameterized storage of scan, remediation, and analytics data, and escaping of administrator-controlled settings before they reach public pages. The single public analytics endpoint, SVG icon upload sanitization, and the cloud connection flow were also reviewed.

The plugin has been successfully tested for:

✅ Information Leakage Vulnerabilities

✅ SQL Injection Vulnerabilities

✅ Cross-Site Scripting (XSS) Attacks

✅ Cross-Site Request Forgery (CSRF) Attacks

✅ Authentication and Authentication Bypass Vulnerabilities

✅ Privilege Escalation Vulnerabilities

✅ Buffer Overflow Vulnerabilities

✅ Denial-of-Service (DoS) Vulnerabilities

✅ Data Leakage Vulnerabilities

✅ Insecure Dependencies

✅ Code Execution Vulnerabilities

✅ File Unauthorized Access Vulnerabilities

✅ Insufficient Injection Protection

Conclusion

With PSC-2026-65698, Web Accessibility (formally known as Ally) version 4.1.4 demonstrates a strong security baseline for its accessibility widget, scanning, and remediation workflows. The certification covers privileged settings, the public analytics endpoint, scan and remediation records, file uploads, and front-end output. Site owners should re-run accessibility scans after significant content or theme changes and confirm that widget settings and the generated accessibility statement still reflect the site’s actual behavior.

Note: The date and certification information may change over time. It is advisable to verify the latest details on the plugin developer’s website.

Plugin Security Certification (PSC-2026-65698): “Web Accessibility (formally known as Ally) – WCAG Scanning, Guided Fixes, Usability Widget” – Version 4.1.4

Artyom Krugov

Cybersecurity Specialist with 4 years of hands-on experience in web application and WordPress security. Holder of the OSCP+ certification and author of 80+ publicly disclosed CVEs affecting WordPress plugins and themes. Specialized in vulnerability research, penetration testing, website incident response, malware removal, and security hardening of production environments. Experienced in identifying and validating high-impact vulnerabilities in WordPress plugins, themes, and custom web applications, as well as providing practical remediation guidance to improve overall security posture. Strong background in web application security, source code review, vulnerability assessment, exploit validation, and post-compromise recovery of infected websites.

Visit Author's Website

See all posts by krugov-artyom

Leave a Reply

Your email address will not be published. Required fields are marked *