Linux 软件免费装
Banner图

Proofwright

开发者 sirahama
更新时间 2026年8月6日 20:55
PHP版本: 8.1 及以上
WordPress版本: 7.0
版权: GPLv2 or later
版权网址: 版权信息

标签

security compliance cra sbom cyber-resilience-act

下载

0.23.8 0.23.9 0.23.10 0.23.11 0.23.12

详情介绍:

Proofwright is the on-site agent for the EU Cyber Resilience Act (CRA). It builds the provable evidence behind a CRA due-diligence posture — and the foundation is free: a rigorous Software Bill of Materials, a deterministic readiness score, and the CRA paperwork. Inventory & SBOM. Inventories every component — core, plugins, must-use plugins, drop-ins, themes (and parents), the PHP runtime, and Composer dependencies (direct vs transitive) — and emits a machine-readable Software Bill of Materials in both SPDX 2.3 and CycloneDX 1.5, with package URLs (PURLs). Immutable, hash-chained snapshots. Each SBOM is stored as a dated, tamper-evident snapshot with diff-over-time, so you can prove how your component graph changed. CRA readiness, in your dashboard. A deterministic posture score; an on-site readiness engine mapped to CRA Annex I (no external calls — no data leaves your server); a scope-classification wizard; a CRA document generator (Vulnerability Disclosure Policy, EU Declaration of Conformity, risk assessment, technical-documentation outline); a consolidated compliance calendar with iCal export; a cross-framework crosswalk (ISO/IEC 27001, SOC 2, NIS2); and a /.well-known/security.txt + Vulnerability Disclosure Policy publisher. Tamper-evident evidence log. An append-only, cryptographically verifiable log of the material actions taken on your site. Not legal advice. A "not legal advice" disclaimer appears on every generated document and report. Related plugin This plugin is complete and fully functional on its own. Some further capabilities — continuous vulnerability monitoring, the SRP incident workflow, the supplier-conformity register, exportable evidence packs, a cross-site fleet console and team review — are provided by a separate plugin, Proofwright Pro, available from proofwright.eu. They are not part of, and not required by, the plugin in this directory.

屏幕截图:

  • CRA conformity readiness — every Annex I requirement tracked as Met (auto-evidenced from scans) or Pending.
  • Your path to CRA readiness — the ordered roadmap, flagged by obligation level (Must / Recommended / Optional).
  • Posture drivers with the full factor-by-factor score breakdown, the hash-chained SBOM snapshot, and detected security controls.

常见问题:

Does this make my site CRA-compliant?

No. Proofwright provides the workflow and the provable evidence; compliance is your legal responsibility. The "not legal advice" disclaimer appears on every generated document and report.

What does this plugin include?

Everything it needs to be useful on its own: component inventory, the SPDX 2.3 / CycloneDX 1.5 SBOM, immutable hash-chained snapshots with diff, the posture score and on-site readiness engine, the scope wizard, the CRA document generator, the compliance calendar, the cross-framework crosswalk, the security.txt / VDP publisher, and the tamper-evident evidence log — all fully functional, with no restrictions. Continuous vulnerability monitoring, the SRP incident workflow, the supplier register, exportable evidence packs and a cross-site fleet console are provided by a separate plugin, Proofwright Pro (see "Related plugin").

Does the plugin send my data anywhere?

No. This plugin runs entirely on your server — the readiness engine and SBOM make no external calls, and there is no licence check or phone-home of any kind.

更新日志:

0.23.12 0.23.11 0.23.10 0.23.9 0.23.8 0.23.7 0.23.6 0.23.5 0.23.4 0.23.3 0.23.2 0.23.0 0.20.0 0.13.0 0.9.0 0.1.0