30% off Pro plugins with LAUNCH30 See plugins
Dragon Compliance box
All plugins

Dragon Compliance

CRA and NIS2 compliance for WordPress: software inventory, SBOM export, vulnerability scanning, readiness checklist and a timestamped evidence log.

A CRA/NIS2 readiness dashboard at a glance: your compliance score, open vulnerability findings and continuous monitoring status.

Live vulnerability findings for your plugins, themes and core — matched to CVEs from the Wordfence intelligence feed, with severity and status.

A complete software inventory with one-click CycloneDX SBOM export — the machine-readable bill of materials regulators increasingly expect.

An automated CRA checklist covering HTTPS, updates, file-editing, 2FA and more, plus attestations you can record against each control.

A tamper-evident, hash-chained evidence log that timestamps every finding, scan and attestation for your audit trail.

CRA & NIS2 compliance for WordPress — software inventory, CycloneDX SBOM export, known-vulnerability monitoring, readiness checklist and evidence log. All processing stays on your server.

Dragon Compliance Pro

Pro add-on for Dragon Compliance — white-label scheduled reports, SBOM snapshots and SPDX export, tamper-evident evidence, time-to-patch metrics, alert routing and a NIS2 view.

from £79/year →

Guides

Put Dragon Compliance to work

Step-by-step guides from the team that builds it. All guides

Requirements

  • · WordPress 6.2 or newer
  • · PHP 8.0 or newer
  • · WordPress 6.2+ · PHP 8.0+

Changelog

v1.0.9

A quiet pointer to the Pro add-on: an Upgrade to Pro link on the Plugins screen, a one-line note at the foot of the plugin's screens, and a single dismissible notice once the plugin has done its job. Nothing in the free plugin is locked or changed, and all three disappear when Pro is active.

View full changelog →