30% off Pro plugins with LAUNCH30 See plugins
Dragon Checkout Guard Pro box
All plugins

Dragon Checkout Guard Pro

Tamper-evident evidence ledger, named-owner alerts, review queue and a printable evidence pack for PCI DSS 6.4.3 / 11.6.1.

Have a code? Enter it at checkout.

Documentation

A year of updates and support, renewed yearly. Cancel any time; the plugin keeps working.

Not ready to buy? Dragon Checkout Guard is free

Or get every plugin, unlimited sites — £349/year

Set a cadence that matches your risk and Pro saves the targeted risk analysis behind it - reviewer, rationale and review date, all in one record.

A changed script matched against your plugin and theme updates, so a reviewer sees a likely vendor explanation before deciding whether to approve.

Name the person accountable for a change, pick email and webhook channels, and every send lands in the evidence ledger with its outcome.

A hash-chained ledger, a printable evidence pack, and provider confirmations tracked in one place - evidence supporting your assessment.

The printable pack opens with scope, cadence and provider confirmations, ready to attach to your assessment or hand to a QSA.

Features

What Dragon Checkout Guard Pro does

Pro add-on for Dragon Checkout Guard. Adds a tamper-evident evidence ledger, scheduled checks with alerts, review reminders, a printable evidence pack, Site Health tests and WP-CLI.

Tamper-evident evidence ledger

a hash-chained log of every

Alerts with a named owner

email, signed webhook or Slack alerts

Review queue with update correlation

changed and new scripts in one

Monitoring cadence with a risk analysis

a schedule from weekly to

Provider confirmation tracker

tracks written confirmations you have

Branded evidence pack

a printable record under your own name and

Site Health

a test for whether the check cadence is being kept.

WP-CLI

verify the ledger, list it, or run a check, from the command

Requirements

  • · WordPress 6.5 or newer
  • · PHP 8.0 or newer
  • · The free Dragon Checkout Guard plugin
  • · WordPress 6.5+ · PHP 8.0+

Changelog

v1.0.0

Dragon Checkout Guard Pro 1.0.0 is here: a tamper-evident evidence ledger, alerts with a named owner, a review queue that links script changes to plugin updates, and a branded evidence pack for your assessor. Dragon Checkout Guard (free) detects what runs on your payment pages. Pro turns those detections into the operational record an assessor asks for under PCI DSS 4.0.1 requirements 6.4.3 and 11.6.1. It is evidence supporting your assessment; it does not certify anything. ## What is in 1.0.0 - **Evidence ledger** - every check, new script, change, authorisation, alert delivery and review decision is written to an append-only ledger. Each row is hashed onto the one before it, so an edited or deleted row is detectable. Verify the chain from the Evidence tab or WP-CLI, and export it to CSV with the stored payload so the chain can be recomputed outside WordPress. - **Alerts with an owner and a delivery log** - email, signed webhook and Slack. Name the person accountable for responding, choose immediate or daily digest delivery, and see every delivery and test alert recorded with its outcome. Webhooks are signed (HMAC over timestamp and body) so the receiver can verify them. - **Review queue** - new scripts, changed scripts and header changes in one place, with Approve, Acknowledge and a required reviewer note. When a change lands within 24 hours of an update to the plugin or theme that owns the script, the queue says so and offers "Approve as vendor update". - **Monitoring cadence and risk analysis** - run checks weekly, daily, twice daily or every six hours. A guided targeted risk analysis records why that cadence was chosen, who reviewed it and when it is due again. A 52-week coverage calendar shows every week with a completed check, and a missed check raises an alert. - **Provider confirmation tracker** - for PCI SSC FAQ 1588 route 2: record when each payment provider's written confirmation was requested and received, its reference, contact and review date. - **Evidence pack** - a printable record for 30, 90 or 365 days: scope, risk analysis, provider confirmations, coverage, the script inventory, the check record, review activity, alert deliveries, header baselines and the ledger integrity result. Add your own name and logo. Monthly or quarterly reminders, and an SAQ due date reminder. - **Site Health and WP-CLI** - a Site Health test for the check cadence, and `wp dragon-checkout-guard-pro verify`, `ledger` and `check`. ## Good to know - Requires Dragon Checkout Guard 1.0.0 or later, WordPress 6.5+, PHP 8.0+. - Everything stays on your server. The only outbound traffic is to the alert channels you configure and to dragoncore.ltd for licence and update checks. - If your licence lapses, every feature keeps working on your activated sites. New versions, downloads and support stop until you renew. - On hosts where PHP's `dns_get_record` is disabled, webhook destinations must be reachable over IPv4.

View full changelog →