MuRu Compliance Auditor
A native Joomla auditor for the European Accessibility Act, the ADA and EU/US privacy law. It crawls your site, tracks conformance over time, and generates the dated report a lawyer or a procurement officer actually asks for — then shows your editors how to fix every issue inside Joomla.
Not an accessibility overlay. That is the point.
Free edition is fully functional and always free · no account required to scan.
Updates arrive natively through Joomla's own System > Update screen.
Already have an account? Sign in

WCAG 2.2 AA
+ EN 301 549
PDF + VPAT
Roadmap 1.2 – 1.3
Joomla 4·5·6
PHP 8.1 – 8.4
No Overlay
Fixes At The Source
Overview
MuRu Compliance Auditor installs like any Joomla extension and runs entirely inside the administrator, behind Joomla's own authentication and ACL. It discovers your pages from menus and same-site link following, fetches each one with a same-origin, SSRF-safe crawler, and evaluates it against a pluggable set of WCAG 2.2 checks.
Every finding names the exact element, the success criterion it fails (WCAG 2.2 and EN 301 549), and how to fix it in Joomla. Scan results are scored, tracked over time, and exported as a printable HTML report with JSON/CSV — with a tamper-evident Pro audit report following in 1.2 — plus a ready-to-publish Accessibility Statement.
Part of the MuRu family alongside MuRu Guard Security Scanner.
Why It Matters Now
Accessibility stopped being optional in 2025 — on both sides of the Atlantic, at the same time — and the tool most sites reached for has been discredited.
28 Jun 2025
The European Accessibility Act became enforceable EU-wide, reaching any business selling to EU consumers, including firms based outside the EU.
$1,000,000
FTC order (finalized April 2025) against the leading accessibility-overlay vendor over claims that automation makes a site compliant.
≈ 23%
of H1-2025 US web-accessibility lawsuits were filed against sites that already had an overlay widget installed.
MuRu Compliance Auditor takes the opposite approach: find the real issues, guide the fix at the source, and keep a verifiable record that you did.
Free Edition — Always Free
Everything you need to find and fix accessibility problems on a single site, run on demand.
Whole-site accessibility scan
- WCAG 2.2 A/AA static analysis
- Images, headings, forms, links, frames
- Language, page title, zoom
- Same-origin, SSRF-safe crawler
- Tables, landmarks, contrast, ARIA — Free · From 1.2
Author-time linter
Free · From 1.3- Editor button for an on-demand check
- Warnings on save for new violations
- Catches issues before content goes live
Findings dashboard
- Score, and breakdown by success criterion and page
- Score trend across recent scans
- "How to fix in Joomla" on every finding
Reports & statement
- Accessibility Statement generator (public-sector EU model; EAA template Free · From 1.2)
- Printable HTML report
- JSON / CSV export of every finding
Free vs Pro — Full Breakdown
Free is genuinely complete for a single site run on demand. Pro is for teams that must stay compliant across many sites and prove it on request.
| Capability | Free | Pro |
|---|---|---|
| Accessibility scanning | ||
| WCAG 2.2 A/AA static scan (whole site) | ||
| Rendered deep scan (computed contrast, focus order, JS content) | — | Pro · From 1.4 |
| WCAG 2.2 additions (target size, focus not obscured, dragging) | — | Pro · From 2.0 |
| Scan profiles (+ EN 301 549, 508, custom on Pro) | WCAG 2.2 | Pro · From 1.3 |
| Incremental scan (changed pages only) | — | Pro · From 2.0 |
| Author workflow | ||
| In-editor linter (button + on-save warnings) | Free · From 1.3 | Pro · From 1.3 |
| Block-on-save policy, per category / severity | — | Pro · From 1.3 |
| "Needs attention" content queue | Free · From 1.3 | Pro · From 1.3 |
| Reporting & proof | ||
| Findings dashboard + remediation guidance | ||
| Score trend | recent | Pro · From 1.3 |
| HTML report · JSON / CSV export | ||
| Dated PDF audit report | — | Pro · From 1.2 |
| Report integrity hash + public verification page | — | Pro · From 1.2 |
| EN 301 549 / VPAT + ADA Titles II & III export | — | Pro · From 1.3 |
| White-label / agency branding | — | Pro · From 1.3 |
| Accessibility Statement generator | 1 template | custom 1.3 · multi-site 2.0 |
| Monitoring & alerts | ||
| Manual scan (single page + whole site) | ||
| Scheduled scans (Joomla Scheduler) | — | Pro · From 1.2 |
| Regression alerts (new findings / score drop) | — | Pro · From 1.2 |
| Slack · Discord · Telegram · webhook | — | Pro · From 1.3 |
| Privacy & consent (reporting only) | ||
| Consent Mode v2 signal check | Free · From 1.2 | Pro · From 1.3 |
| Tracker inventory vs declared consent categories | — | Pro · From 1.4 |
| Pre-consent network-call detection | — | Pro · From 1.3 |
| Stale cookie-declaration diff | — | Pro · From 1.4 |
| GDPR opt-in vs CCPA "Do Not Sell" guidance | — | Pro · From 1.4 |
| Right-to-be-forgotten helper | — | Pro · From 2.0 |
| Agency & scale | ||
| Single-site operation | ||
| Fleet dashboard (all licensed sites, one view) | — | Pro · From 2.0 |
| Remote re-scan / push profile across the fleet | — | Pro · From 2.0 |
| Per-client report packs | — | Pro · From 2.0 |
| Automation | ||
| Console command (muruaudit:scan) | — | Pro · From 1.4 |
| REST endpoints for CI | — | Pro · From 1.4 |
| CI gate mode (non-zero exit on threshold) | — | Pro · From 1.4 |
| SARIF export | — | Pro · From 2.0 |
| Platform | ||
| Admin quick-icon with live score | Free · From 1.2 | Pro · From 1.2 |
| Control-panel dashboard module | — | Pro · From 2.0 |
| Per-action ACL | ||
| Action-log entries | Free · From 1.3 | Pro · From 1.3 |
| Priority support | — | |
Free and Pro are the same product, different builds — Pro code is simply absent from the Free package. Everything is GPL-2.0-or-later. A “Free · From 1.x” or “Pro · From 1.x” pill marks the release an item is planned for — listed so you know what's next, not to suggest it ships today. Follow the v1.2.0 phase on the public roadmap.
What It Checks
Each check is a small, single-purpose rule that maps to a WCAG 2.2 success criterion and its EN 301 549 clause, and carries Joomla-specific remediation copy.
Images
Missing, empty or misused alt text; decorative images inside links or figures.
Headings
Skipped levels, empty headings, missing or duplicated h1.
Links & buttons
No accessible name, icon-only controls, ambiguous "click here" text.
Forms
Controls with no associated label, aria-label or wrapping label.
Frames
iframes with no title attribute.
Language
Missing or malformed html[lang].
Page title
Missing, empty or non-descriptive <title>.
Zoom
Viewport meta that disables pinch-zoom or caps maximum-scale below 2.
Colour contrast
Static estimate, labeled as such; computed in the browser on Pro's rendered scan (1.4).
Tables, landmarks, ARIA
Next in the check roadmap, with media captions following in 1.3.
Author-Time Linter
Free + Pro · From 1.3Accessibility drifts every time an editor uploads a PDF, pastes a table, or adds an image without a description. The linter moves the check left: an editor button runs an on-demand review of the current article, and a save-time hook warns when a change introduces a new violation.
On Pro, a policy can escalate specific categories or severities to block-on-save, and rules can be tuned per author or per category.
Reporting & Proof
Pro · From 1.2"Show us what you've done, and when." That is the question from a regulator, an insurer, a procurement officer or a plaintiff's lawyer — and a screenshot does not answer it. Today both editions ship a printable HTML report with JSON/CSV export; the dated Pro proof formats land across 1.2–1.3.
Dated PDF audit report Pro · From 1.2
Scoped, standard-mapped, and stamped with the scan date.
Integrity hash Pro · From 1.2
A SHA-256 of the exact scan is embedded; a public page re-computes and confirms it.
EN 301 549 / VPAT Pro · From 1.3
Export the Accessibility Conformance Report format procurement asks for.
ADA Titles II & III checklists Pro · From 1.3
Mapped alongside the WCAG results, for public and private buyers.
White-label Pro · From 1.3
Agency branding on every client report.
Full history Pro · From 1.3
Score and findings tracked across every scan, with charts.
Accessibility Statement Generator
Generates a statement following the public-sector EU model structure — standard applied, conformance status, known non-accessible content and why, the feedback mechanism, the enforcement contact, and the preparation date and method — ready to publish as a Joomla menu item. An EAA-style template for private-sector conformity documentation follows in 1.2.
Free ships one template for the current site. Pro adds custom fields and an auto-refreshed conformance status tied to your latest scan (1.3), multi-site statements (2.0), and a hosted verification URL.
Privacy & Consent Audit
Pro · From 1.3Reporting only — it never blocks or rewrites anything. The Joomla cookie-consent space is already crowded; the unsolved part is knowing whether what actually fires matches what you declared. A free single-signal Consent Mode teaser lands in 1.2; the full Pro audit follows across 1.3–1.4.
- Pro · From 1.3Google Consent Mode v2 signal check (all four signals)
- Pro · From 1.3Detection of tags loading before a consent signal
- Pro · From 1.4Inventory of third-party trackers present on each page
- Pro · From 1.4Diff of new cookies since the last scan (stale declaration catch)
- Pro · From 1.4GDPR opt-in vs CCPA "Do Not Sell" guidance by visitor region
- Pro · From 2.0Right-to-be-forgotten helper: locate a person's data across core and registered third-party tables
Agency & Fleet
Pro · From 2.0One licence will cover every client site. The fleet dashboard will show each site's score and open findings in a single view, let you trigger a remote re-scan or push a scan profile across the fleet, and bundle per-client report packs. It is the basis for a productised "compliance monitoring" retainer.
CI & Automation
Pro · From 1.4A Joomla console command and read-only REST endpoints will let a pipeline run a scan and fail a build when the score drops below a threshold. Findings export as JSON and CSV today, with SARIF for code-scanning UIs following in 2.0.
php cli/joomla.php muruaudit:scan --profile=wcag22-aa --fail-under=90 --format=sarif
Installation
- 1
Install the package
Upload pkg_muruaudit from System > Install Extensions. One package installs the component and the system and quick-icon plugins; Pro-only plugins ship alongside their features across 1.2-1.4.
- 2
Set permissions
By default only Super Users get access. Grant Scan, Export, Statement or Fleet permissions to trusted groups through Joomla's own Access Levels.
- 3
Run a scan
Open Components > MuRu Compliance Auditor > Dashboard, pick a profile, and review findings grouped by success criterion and page.
- 4
Publish the statement
Generate an Accessibility Statement and link it from a menu item.
- 5
Schedule monitoring
On Pro from 1.2, enable a scheduled task in Joomla's Scheduler and bind an alert channel (email or webhook at first; Slack, Discord and Telegram follow in 1.3).
- 6
Activate your licence
Paste your key into Settings > Licence to unlock each Pro feature as it ships across 1.2-2.0, starting with scheduled monitoring and PDF reports.
- 7
Stay updated
The extension registers with Joomla's update system on both Free and Pro — new releases appear in System > Update.
Requirements
Privacy & Security Model
Nothing leaves your server
Page content, findings, file paths and URLs are analysed locally and never transmitted. The Free edition's only outbound call is Joomla's update check.
Pro outbound is opt-in
The licence check, alert webhooks and fleet sync are each off by default and configured by you; none of them send page content or findings unless you set up that channel.
SSRF-safe crawler
Same-origin only; refuses to fetch private, loopback, link-local or CGNAT addresses even when given an operator-supplied URL; caps pages, time and response size.
Offline install script
The install/update script makes no network calls and sets a restrictive ACL default — only Super Users until you widen it.
CSRF + ACL on every action
Scan, export, settings and statement actions all require Joomla's token and an explicit permission check.
Parameterised queries, escaped output
Every database access uses the query builder; every template value is escaped.
Not an overlay
No runtime script is injected into your public site. No DOM is rewritten for visitors. No "instant compliance" claim is made.
GPL-2.0-or-later
Both editions, as required for Joomla extensions.
