Compliance
CRA compliance for WordPress: a practical checklist for agencies and site owners
What the EU Cyber Resilience Act and NIS2 actually ask of a WordPress site, the dates that matter, and a checklist you can evidence rather than just tick.
LAUNCH30 at checkout, until 30 November. See the pluginsSee plugins
CRA and NIS2 compliance for WordPress: software inventory, SBOM export, vulnerability scanning, readiness checklist and a timestamped evidence log.
CRA & NIS2 compliance for WordPress — software inventory, CycloneDX SBOM export, known-vulnerability monitoring, readiness checklist and evidence log. All processing stays on your server.
Dragon Compliance Pro
Pro add-on for Dragon Compliance — white-label scheduled reports, SBOM snapshots and SPDX export, tamper-evident evidence, time-to-patch metrics, alert routing and a NIS2 view.
Guides
Step-by-step guides from the team that builds it. All guides
Compliance
What the EU Cyber Resilience Act and NIS2 actually ask of a WordPress site, the dates that matter, and a checklist you can evidence rather than just tick.
Compliance
What a Software Bill of Materials is, why clients now ask WordPress teams for one, what it should contain, and how to export one in CycloneDX or SPDX format.
Compliance
How an agency answers a client's security questionnaire in an afternoon: continuous monitoring without per-site accounts, SBOM history, tamper-evident evidence, time-to-patch and a branded report.
A quiet pointer to the Pro add-on: an Upgrade to Pro link on the Plugins screen, a one-line note at the foot of the plugin's screens, and a single dismissible notice once the plugin has done its job. Nothing in the free plugin is locked or changed, and all three disappear when Pro is active.