Requires the free Dragon Compliance.
Licence
Enter your licence key on the plugin's settings screen (keys are in your dragoncore.ltd dashboard). Keys are stored encrypted; one seat covers one site, and you can deactivate a site from the same screen to move the licence. Updates are delivered automatically to licensed sites. If the licence lapses, the plugin keeps working with every Pro feature on each activated site; what stops is new versions, support and the Dragon Core vulnerability feed (the free plugin's own source takes over), and renewing restores both on the same key. Renewal reminders arrive by email about two weeks before the period ends.
Features
- Zero-config vulnerability monitoring — licensed sites download the Wordfence Intelligence feed from Dragon Core (
api.dragoncore.ltd) instead of needing their own Wordfence account and token. The request carries only your licence key and hostname; the feed is served unmodified, copyright notices included, and refreshed on Dragon Core every few hours. If the licence lapses the free plugin's own token (if any) takes over automatically. Requires Dragon Compliance 1.0.6+. - White-label reports — client/auditor-ready compliance reports under your own branding.
- SBOM snapshots & diffs — point-in-time software inventories, compared over time, exportable as SPDX as well as CycloneDX.
- Hash-chained evidence — the evidence log becomes tamper-evident, each entry sealed against its predecessor.
- Time-to-patch metrics — how fast vulnerabilities get closed, the number auditors ask for.
- Alert routing — findings to email, HMAC-signed webhooks, or Slack.
- NIS2 view — the checklist grouped against NIS2 supply-chain expectations.
Uninstall
Deleting the plugin keeps all its data by default, so a reinstall picks up where you left off. To remove everything on uninstall, opt in first:
wp option update dragoncompliancepro_delete_data_on_uninstall 1