The EU Cyber Resilience Act (CRA) requires those who develop or manage software — including small agencies that run WordPress sites for clients — to notify known vulnerabilities in the components they use within tight deadlines, if those vulnerabilities are actively exploited.
CRA Vuln Notify automates the most time-consuming part of this obligation: knowing a vulnerability exists, understanding how urgent it is, and never missing a deadline.
How it works
- Scans all installed plugins and themes every day (or on demand, with one click from the dashboard), checking their versions against a known vulnerability database.
- Classifies each vulnerability found by severity — critical, high, medium, low — and checks whether it is actively exploited.
- Starts the CRA timeline for actively exploited vulnerabilities: preliminary notification within 24 hours of discovery, full notification within 72 hours, final notification upon closure — with countdowns always visible in the dashboard.
- Alerts you by email and with a banner in wp-admin as soon as a critical vulnerability appears, so you don't have to check the dashboard every day to notice it.
- Generates a draft notification document, ready to adapt for submission to the competent authority (national CSIRT / ENISA) or to end users, with a full log exportable to CSV for audit purposes.
Vulnerability providers, your choice
Works out of the box with
WPScan (free, only requires a free API key from the provider), or — if you need more daily requests — with
Patchstack (paid). The provider is chosen from Settings, nothing else needs to change.
Built for agencies managing multiple sites
The dashboard shows at a glance where action is needed and how much time is left to act, instead of discovering a critical vulnerability by chance during a routine check.
Important note: this plugin is an operational support tool, not a legal advisory service. The generated documents are drafts to review and adapt: always confirm the applicable regulatory obligations with a qualified legal/compliance advisor before considering yourself compliant.