| 开发者 | dragoncoreltd |
|---|---|
| 更新时间 | 2026年9月13日 09:03 |
| PHP版本: | 8.0 及以上 |
| WordPress版本: | 7.1 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
/wp-content/plugins/dragon-compliance, or
install through the WordPress plugins screen.If your WordPress site is part of a commercial digital product or service offered in the EU, parts of the CRA and NIS2 likely apply to your business. This plugin gives you the technical evidence base - it is not legal advice.
From the Wordfence Intelligence Community Edition database, matched locally against your installed versions. Your inventory never leaves your server.
CycloneDX 1.6 JSON in the free plugin. Dragon Compliance Pro adds SPDX 2.3 and automatic SBOM snapshots with diffs.
A Software Bill of Materials lists every software component you run, with versions and licenses - like an ingredients label for your site. Auditors, enterprise customers and EU regulation increasingly ask for one. This plugin exports yours in the standard CycloneDX format in one click.
The Cyber Resilience Act's vulnerability and incident reporting obligations begin in September 2026, with the remaining requirements following in 2027. If the CRA touches your business, the evidence trail is worth starting now - findings and attestations only prove a history if they have one.
No. Scans run in the background once a day via WP-Cron, there is no front-end code at all, and the vulnerability match happens locally against a cached copy of the database.
No. It matches your installed software versions against a database of publicly known vulnerabilities. It does not scan files for infections.
dragoncompliance_sbom_exported action fires when an SBOM download is generated.