Dragon Compliance Pro
The Licence screen now says until when updates continue for a lapsed licence inside its renewal grace.
What's new in 1.0.12
- The Licence screen shows "Updates continue until <date>" for a licence that has lapsed but is still inside the server's renewal grace, so "Lapsed" no longer reads as if updates had already stopped.
- An update check with nothing to offer keeps WordPress's own bookkeeping for the plugin, and a plugin-details request fired with an unexpected argument is left alone.
Fixes an update check that could fatal for up to 12 hours, and makes the licence module treat a server error page as an outage rather than a rejection.
What's new in 1.0.11
- Fixed: when the licence server offered an update this site holds no seat for, the cached answer was read back wrongly and every update check fataled for up to 12 hours. Nothing but valid answers is cached now, a stale offer disappears once the site runs the latest version, and update packages are trusted from dragoncore.ltd exactly, over https.
- Fixed: a licence server reply that names no verdict (an error page, a firewall, a proxy) is treated as an outage and leaves the stored licence alone, instead of switching Pro features off for up to 12 hours. The server's own entitlement answers, including its renewal grace for updates, are honoured.
Evidence is sealed on every host, and verification never reports an unsealed chain as verified.
What's new in 1.0.10
- Evidence is sealed on hosts where database locks are unavailable, and verification says how many entries are still unsealed.
- Multisite: the zero-config feed works for sites on the licensed host; sites on their own domain need their own licence.
- Client reports label every evidence event.
- Uninstall, when opted in, cleans every site and leaves nothing behind.
- Multisite: updates are offered across the network when any site holds the licence, and removing the licence from one subdirectory site keeps the shared activation for the others.
Fixed: critical alerts reach the site admin when no recipients are set.
What's new in 1.0.9
- Fixed: with no Pro recipients set, alerts now go to the site admin. On licensed sites where an older version switched admin alerts off, they are switched back on once, with a notice.
- Fixed: scheduled reports are scheduled on first save and after reactivation.
- SPDX export uses valid licence identifiers.
Translation-ready throughout, with readable findings exports.
What's new in 1.0.8
- Every screen, email and alert is now translatable, and translations bundled in the plugin's languages folder now load. Counts use proper plural forms, and numbers and dates follow your site's language.
- The findings CSV has readable column headings; the evidence CSV used for verification is unchanged.
Activating or deactivating a licence now tells you when the change could not be saved on your site, instead of reporting success.
- An update offer left over from before a licence lapsed or was removed is now cleared, and the update check no longer logs a PHP warning on such a site.
- The licence screen now shows the result of activating or deactivating, including the reason when it does not work.
- No settings or data change. Nothing to do after updating.
Your licence now keeps working after it lapses. Pro features stay on for every activated site; renewing restores updates and support on the same key.
- The licence screen shows Lapsed, and what that means, instead of a red Expired.
- The Dragon Core vulnerability feed follows the same rule as updates: it is served while the licence is current, and the free plugin's own feed source takes over if it lapses.
- New versions are fetched only while the licence is current. Nothing else changes.
Fixes an evidence-sealing bug that could report the chain as tampered after a failed write, and a scheduled report that stayed unsent for 28 days after a mail failure.
What's fixed in 1.0.5
- A failed seal write no longer breaks the evidence chain. If the database refused to store an entry's hash, the sealer carried on and chained the next entry to a hash that was never written, so Seal & verify reported the log as BROKEN from then on. Sealing now stops at the first entry whose hash does not land, resumes from that entry on the next run, and the Snapshots tab reports the write failure separately from a real tamper verdict.
- Scheduled reports are retried after a mail failure. The report marked itself as sent before the email went out, so one failed send silently skipped the monthly report for another 28 days. The sent timestamp is now recorded only after at least one recipient accepted the mail. A report that reached nobody is logged in the evidence log as
report_send_failedand sent again on the next run. - The snapshots table schema version is stamped only after the table exists, so a failed creation is retried (every 10 minutes, with an admin notice) rather than recorded as complete.
- New
dragoncompliancepro_seal_failedanddragoncompliancepro_report_failedactions fire on those failures, for anyone routing them elsewhere. - A sealing failure can no longer be reported as a verified chain. If both the seal and the record of its failure were refused, the chain was left unsealed and then verified as valid with nothing checked, which read as an all-clear. A sealing failure is now reported from the run itself, and "valid" is never shown for a chain with no sealed entries.
- A broken chain is no longer hidden by a sealing failure. When verification found a genuinely modified entry in the same run that failed to seal a newer one, only the sealing failure was shown. Both are now reported, and the broken entry is never replaced by the one that failed to seal.
- A scheduled report that cannot record its send time says so. The send time is what stops the report going out again, so losing it silently re-sent the report on the next run. The mail is still reported as sent, and the bookkeeping failure is reported separately.
- Sites already missing the snapshots table are repaired on upgrade. The recorded schema version is no longer trusted on its own; the table is confirmed to exist first.
No settings or data changes otherwise.
Zero-configuration vulnerability monitoring: licensed sites now get the vulnerability feed from Dragon Core — no Wordfence account or API token needed.
= 1.0.4 =
- New: with a valid licence the vulnerability feed is fetched from Dragon Core (api.dragoncore.ltd) using your licence key. Delete your Wordfence token or never create one — monitoring stays active.
- If the licence lapses the plugin falls back to the free plugin's own Wordfence token automatically.
- Requires Dragon Compliance 1.0.6.
Security update: alert webhook secrets are authenticated at rest and Slack alerts no longer follow redirects.
= 1.0.3 =
- Security: the alert signing secret is encrypted at rest with authenticated encryption; Slack alerts disable redirects for parity with the signed webhook.
- Hardening: a stored licence is re-checked for a usable key before trusting the cached result.
Tested and verified on WordPress 7.1.
- Compatibility: tested up to WordPress 7.1.
Evidence verification and CSV export now stream in batches, staying fast and memory-safe no matter how large your evidence log grows.
Dragon Compliance Pro: the evidence pack your auditor asks for.
White-label reports, SBOM snapshots and diffs with SPDX export, a hash-chained tamper-evident evidence log, time-to-patch metrics, alert routing to email, signed webhooks or Slack, and a dedicated NIS2 view.