Linux 软件免费装
Banner图

Dragon Compliance - CRA & NIS2 Compliance, SBOM Export & Vulnerability Scanner

开发者 dragoncoreltd
更新时间 2026年9月13日 09:03
PHP版本: 8.0 及以上
WordPress版本: 7.1
版权: GPLv2 or later
版权网址: 版权信息

标签

security compliance vulnerability scanner nis2 sbom

下载

1.0.8 1.0.9 1.0.5 1.0.6 1.0.7

详情介绍:

The EU Cyber Resilience Act (CRA) and NIS2 directive expect businesses to know what software they run, monitor it for known vulnerabilities, patch without delay - and to be able to prove all of that. Dragon Compliance is the WordPress compliance plugin that turns your site into something you can hand to an auditor: Everything is processed locally on your server. Your inventory is never uploaded anywhere - the only outbound request is downloading the public vulnerability database. Everything above is free, fully functional and unlimited. Dragon Compliance Pro For agencies and businesses that answer to clients or auditors: See Dragon Compliance Pro for details.

安装:

  1. Upload the plugin files to /wp-content/plugins/dragon-compliance, or install through the WordPress plugins screen.
  2. Activate the plugin through the 'Plugins' screen.
  3. Go to Tools → Compliance.
  4. (Optional, for vulnerability monitoring) Create a free wordfence.com account, generate an API token under Dashboard → Integrations, and paste it under Tools → Compliance → Settings.

屏幕截图:

  • Findings - known vulnerabilities in installed plugins, themes and core, matched against the Wordfence Intelligence feed with CVE links.
  • Inventory & SBOM - every component on the site, exportable as a CycloneDX SBOM in one click.
  • Checklist - automatic CRA readiness checks plus recorded process attestations.
  • Evidence - a timestamped log of every scan, detection and attestation.

升级注意事项:

1.0.8 Fixes cases where a failed database write was reported as saved: attestations, finding status changes and scan resolutions are now only recorded in the evidence log once they are actually stored. 1.0.7 Adds a one-time WordPress.org review prompt on the Compliance screen after your first scan or SBOM export. No other changes. 1.0.6 Adds the feed-source hook Dragon Compliance Pro 1.0.4 uses for zero-configuration vulnerability monitoring. No change for free users. 1.0.5 Security: your Wordfence token is now stored with authenticated encryption, and monitoring re-scans as soon as you add, update or remove a plugin or theme. Recommended update. 1.0.4 Listing and documentation improvements only. Safe to update.

常见问题:

Does the CRA apply to my site?

If your WordPress site is part of a commercial digital product or service offered in the EU, parts of the CRA and NIS2 likely apply to your business. This plugin gives you the technical evidence base - it is not legal advice.

Where does the vulnerability data come from?

From the Wordfence Intelligence Community Edition database, matched locally against your installed versions. Your inventory never leaves your server.

What SBOM formats are supported?

CycloneDX 1.6 JSON in the free plugin. Dragon Compliance Pro adds SPDX 2.3 and automatic SBOM snapshots with diffs.

What is an SBOM, and why would I need one?

A Software Bill of Materials lists every software component you run, with versions and licenses - like an ingredients label for your site. Auditors, enterprise customers and EU regulation increasingly ask for one. This plugin exports yours in the standard CycloneDX format in one click.

When do the CRA obligations start?

The Cyber Resilience Act's vulnerability and incident reporting obligations begin in September 2026, with the remaining requirements following in 2027. If the CRA touches your business, the evidence trail is worth starting now - findings and attestations only prove a history if they have one.

Will it slow down my site?

No. Scans run in the background once a day via WP-Cron, there is no front-end code at all, and the vulnerability match happens locally against a cached copy of the database.

Is this a malware scanner?

No. It matches your installed software versions against a database of publicly known vulnerabilities. It does not scan files for infections.

更新日志:

1.0.9 1.0.8 1.0.7 1.0.6 1.0.5 1.0.4 1.0.3 1.0.2 1.0.1 1.0.0