| 开发者 | sirahama |
|---|---|
| 更新时间 | 2026年8月6日 20:55 |
| PHP版本: | 8.1 及以上 |
| WordPress版本: | 7.0 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
/.well-known/security.txt + Vulnerability Disclosure Policy publisher.
Tamper-evident evidence log. An append-only, cryptographically verifiable log of the material actions taken on your site.
Not legal advice. A "not legal advice" disclaimer appears on every generated document and report.
Related plugin
This plugin is complete and fully functional on its own. Some further capabilities — continuous vulnerability monitoring, the SRP incident workflow, the supplier-conformity register, exportable evidence packs, a cross-site fleet console and team review — are provided by a separate plugin, Proofwright Pro, available from proofwright.eu. They are not part of, and not required by, the plugin in this directory.
No. Proofwright provides the workflow and the provable evidence; compliance is your legal responsibility. The "not legal advice" disclaimer appears on every generated document and report.
Everything it needs to be useful on its own: component inventory, the SPDX 2.3 / CycloneDX 1.5 SBOM, immutable hash-chained snapshots with diff, the posture score and on-site readiness engine, the scope wizard, the CRA document generator, the compliance calendar, the cross-framework crosswalk, the security.txt / VDP publisher, and the tamper-evident evidence log — all fully functional, with no restrictions. Continuous vulnerability monitoring, the SRP incident workflow, the supplier register, exportable evidence packs and a cross-site fleet console are provided by a separate plugin, Proofwright Pro (see "Related plugin").
No. This plugin runs entirely on your server — the readiness engine and SBOM make no external calls, and there is no licence check or phone-home of any kind.