For a US business, the website risks that cost real money are rarely dramatic hacks. They are an accessibility demand letter, a privacy complaint, or a checkout that no longer meets card-payment rules. Each one traces back to the same cause: a WordPress site that changed over time while nobody checked the basics.
This checklist covers the three areas US site owners ask us about most: the ADA, state privacy laws such as California’s CCPA, and PCI DSS for online stores.
Why Accessibility Matters Legally in the US
Title III of the Americans with Disabilities Act covers businesses open to the public, and the Department of Justice’s web accessibility guidance makes clear that applies to their websites too. Website accessibility claims have become routine, and many start with a demand letter rather than a lawsuit.
The law doesn’t name a technical standard for private businesses, but WCAG 2.1 Level AA is the benchmark courts and settlements usually point to. For state and local governments, a 2024 DOJ rule now requires WCAG 2.1 AA outright.
The Accessibility Fixes That Matter Most
On WordPress sites, the same problems come up again and again: form fields without labels, buttons that rely on color alone, image sliders that trap keyboard users, and PDFs that screen readers can’t read. Our practical WCAG guide shows how to fix each one.
The step most businesses miss is re-testing. A theme update, a new page builder module or a redesigned contact form can quietly break work you already paid for. Check key pages with only a keyboard after every major update.
State Privacy Laws: CCPA and Beyond
The California Consumer Privacy Act applies to for-profit businesses that do business in California and meet one of its thresholds: annual revenue above roughly $25 million (adjusted for inflation), buying, selling or sharing the personal information of 100,000 or more California consumers or households, or earning half their revenue from selling or sharing it. A growing number of states have passed similar laws with their own thresholds.
If any of these apply to you, your site needs a clear privacy policy, a working “Do Not Sell or Share My Personal Information” link where required, and support for the Global Privacy Control signal that some browsers send. WordPress helps with the first part under Settings > Privacy; your consent tool needs to handle the rest.
PCI DSS 4.0 and Your Checkout
If you take card payments, the PCI Data Security Standard applies. Version 4.0 replaced 3.2.1 in 2024, and its remaining requirements became mandatory on March 31, 2025. Two of them focus on payment pages: keeping an inventory of every script that runs there, and detecting unauthorized changes to those pages.
On WooCommerce, the simplest way to reduce your scope is a payment gateway that collects card details in its own hosted fields, so card numbers never touch your server. Then remove tracking and chat scripts from checkout pages, keep payment plugins current and watch for unexpected file changes. Our WooCommerce security guide and WooCommerce maintenance cover the details.
Security Basics Behind Every Rule
Every one of these rules assumes you protect the data you hold. That means applying tested updates quickly, using two-factor authentication for every admin, keeping off-site backups you have actually restored, and putting a web application firewall in front of the site.
Frequently Asked Questions
Can a plugin make my site ADA compliant?
No. Overlay widgets don’t fix the underlying code, and some sites using them have still received demand letters. Real fixes happen in the theme, content and forms.
Does the CCPA apply to small businesses?
Usually not, unless you meet one of its thresholds. Other state laws have different thresholds, so check each state where you have many customers.
Do I need to worry about PCI if I use Stripe or PayPal?
Yes, but much less. Hosted payment fields shrink your obligations considerably, yet you are still responsible for the security of the page that loads them.
How often should I re-check my site?
After every major theme, plugin or design change, and at least once a quarter.
What to Do This Week
- Tab through your homepage, contact form and checkout using only your keyboard.
- Confirm your privacy policy is linked from every page and up to date.
- List every script that loads on your checkout and remove what isn’t needed.
- Make sure every admin account uses two-factor authentication.
If you’d rather have the updates, backups and monitoring handled for you, our managed WordPress maintenance takes care of it, or start with a free site audit.
This article explains the technical side for website owners. It isn’t legal advice; for decisions about your own obligations, talk to a qualified adviser.
Get a free audit covering security, updates, backups, and performance gaps. Takes 60 seconds to request and costs nothing.
