{"id":358504,"date":"2026-08-26T09:15:17","date_gmt":"2026-08-26T09:15:17","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/dragon-compliance\/"},"modified":"2026-10-10T17:02:44","modified_gmt":"2026-10-10T17:02:44","slug":"dragon-compliance","status":"publish","type":"plugin","link":"https:\/\/de-at.wordpress.org\/plugins\/dragon-compliance\/","author":23543042,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.1.0","stable_tag":"1.1.0","tested":"7.1.3","requires":"6.2","requires_php":"8.0","requires_plugins":null,"header_name":"Dragon Compliance","header_author":"Dragon Core","header_description":"CRA & NIS2 compliance for WordPress \u2014 software inventory, CycloneDX SBOM export, known-vulnerability monitoring, readiness checklist and evidence log. All processing stays on your server.","assets_banners_color":"211a1c","last_updated":"2026-10-10 17:02:44","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/dragoncore.ltd\/plugins\/dragon-compliance","header_author_uri":"https:\/\/dragoncore.ltd","rating":0,"author_block_rating":0,"active_installs":0,"downloads":453,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.10":{"tag":"1.0.10","author":"dragoncoreltd","date":"2026-09-24 17:50:58","revision":3711805},"1.0.11":{"tag":"1.0.11","author":"dragoncoreltd","date":"2026-09-25 05:08:58","revision":3712400},"1.0.12":{"tag":"1.0.12","author":"dragoncoreltd","date":"2026-09-25 10:54:15","revision":3712896},"1.0.13":{"tag":"1.0.13","author":"dragoncoreltd","date":"2026-10-02 17:13:34","revision":3725175},"1.0.5":{"tag":"1.0.5","author":"dragoncoreltd","date":"2026-08-26 09:15:03","revision":3666619},"1.0.6":{"tag":"1.0.6","author":"dragoncoreltd","date":"2026-08-26 12:01:07","revision":3666931},"1.0.7":{"tag":"1.0.7","author":"dragoncoreltd","date":"2026-09-06 15:52:43","revision":3683638},"1.0.8":{"tag":"1.0.8","author":"dragoncoreltd","date":"2026-09-12 01:53:45","revision":3692256},"1.0.9":{"tag":"1.0.9","author":"dragoncoreltd","date":"2026-09-24 17:27:08","revision":3711775},"1.1.0":{"tag":"1.1.0","author":"dragoncoreltd","date":"2026-10-10 17:02:44","revision":3738399}},"upgrade_notice":{"1.1.0":"<p>Vulnerability monitoring now works without an account, using WPVulnerability. Sites with a saved Wordfence token keep Wordfence. Alerts can go to several addresses.<\/p>","1.0.13":"<p>Stricter handling of checklist input. No change to how scans or exports work.<\/p>","1.0.12":"<p>Fixed: scheduled vulnerability scans now run. Please update.<\/p>","1.0.11":"<p>Vulnerabilities that come back are reported again.<\/p>","1.0.10":"<p>Translation-ready throughout.<\/p>","1.0.8":"<p>Fixes cases where a failed database write was reported as saved: attestations, finding status changes and scan resolutions are now only recorded in the evidence log once they are actually stored.<\/p>","1.0.7":"<p>Adds a one-time WordPress.org review prompt on the Compliance screen after your first scan or SBOM export. No other changes.<\/p>","1.0.6":"<p>Adds the feed-source hook Dragon Compliance Pro 1.0.4 uses for zero-configuration vulnerability monitoring. No change for free users.<\/p>","1.0.5":"<p>Security: your Wordfence token is now stored with authenticated encryption, and monitoring re-scans as soon as you add, update or remove a plugin or theme. Recommended update.<\/p>","1.0.4":"<p>Listing and documentation improvements only. Safe to update.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.gif":{"filename":"icon-128x128.gif","revision":3711775,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.gif":{"filename":"icon-256x256.gif","revision":3711775,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3666619,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3666619,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{"blueprint.json":{"filename":"blueprint.json","revision":3738400,"resolution":false,"location":"assets","locale":"","contents":"{\"landingPage\":\"\\\/wp-admin\\\/tools.php?page=dragon-compliance\",\"preferredVersions\":{\"php\":\"8.2\",\"wp\":\"latest\"},\"features\":{\"networking\":true},\"steps\":[{\"step\":\"login\",\"username\":\"admin\",\"password\":\"password\"},{\"step\":\"installPlugin\",\"pluginData\":{\"resource\":\"wordpress.org\\\/plugins\",\"slug\":\"dragon-compliance\"},\"options\":{\"activate\":true}}]}"}},"all_blocks":[],"tagged_versions":["1.0.10","1.0.11","1.0.12","1.0.13","1.0.5","1.0.6","1.0.7","1.0.8","1.0.9","1.1.0"],"block_files":[],"assets_screenshots":{"screenshot-1.jpg":{"filename":"screenshot-1.jpg","revision":3666619,"resolution":"1","location":"assets","locale":"","width":1456,"height":839},"screenshot-2.jpg":{"filename":"screenshot-2.jpg","revision":3666619,"resolution":"2","location":"assets","locale":"","width":1456,"height":839},"screenshot-3.jpg":{"filename":"screenshot-3.jpg","revision":3666619,"resolution":"3","location":"assets","locale":"","width":1456,"height":839},"screenshot-4.jpg":{"filename":"screenshot-4.jpg","revision":3666619,"resolution":"4","location":"assets","locale":"","width":1456,"height":839},"screenshot-5.jpg":{"filename":"screenshot-5.jpg","revision":3666619,"resolution":"5","location":"assets","locale":"","width":1456,"height":839}},"screenshots":{"1":"Dashboard - readiness score, open findings and vulnerability monitoring at a glance.","2":"Findings - known vulnerabilities in installed plugins, themes and core, with severity and CVE links.","3":"Inventory &amp; SBOM - every component on the site, exportable as a CycloneDX SBOM in one click.","4":"Checklist - automatic CRA readiness checks plus recorded process attestations.","5":"Evidence - a timestamped log of every scan, detection and attestation."}},"plugin_section":[],"plugin_tags":[14361,267090,269595,600,139069],"plugin_category":[54],"plugin_contributors":[276960],"plugin_business_model":[],"class_list":["post-358504","plugin","type-plugin","status-publish","hentry","plugin_tags-compliance","plugin_tags-nis2","plugin_tags-sbom","plugin_tags-security","plugin_tags-vulnerability-scanner","plugin_category-security-and-spam-protection","plugin_contributors-dragoncoreltd","plugin_committers-dragoncoreltd"],"banners":{"banner":"https:\/\/ps.w.org\/dragon-compliance\/assets\/banner-772x250.png?rev=3666619","banner_2x":"https:\/\/ps.w.org\/dragon-compliance\/assets\/banner-1544x500.png?rev=3666619","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/dragon-compliance\/assets\/icon-128x128.gif?rev=3711775","icon_2x":"https:\/\/ps.w.org\/dragon-compliance\/assets\/icon-256x256.gif?rev=3711775","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/dragon-compliance\/assets\/screenshot-1.jpg?rev=3666619","caption":"Dashboard - readiness score, open findings and vulnerability monitoring at a glance."},{"src":"https:\/\/ps.w.org\/dragon-compliance\/assets\/screenshot-2.jpg?rev=3666619","caption":"Findings - known vulnerabilities in installed plugins, themes and core, with severity and CVE links."},{"src":"https:\/\/ps.w.org\/dragon-compliance\/assets\/screenshot-3.jpg?rev=3666619","caption":"Inventory &amp; SBOM - every component on the site, exportable as a CycloneDX SBOM in one click."},{"src":"https:\/\/ps.w.org\/dragon-compliance\/assets\/screenshot-4.jpg?rev=3666619","caption":"Checklist - automatic CRA readiness checks plus recorded process attestations."},{"src":"https:\/\/ps.w.org\/dragon-compliance\/assets\/screenshot-5.jpg?rev=3666619","caption":"Evidence - a timestamped log of every scan, detection and attestation."}],"raw_content":"<!--section=description-->\n<p>The EU Cyber Resilience Act (CRA) and the NIS2 directive expect the businesses\nthey cover to know what software they run, monitor it for known\nvulnerabilities, patch without delay - and to be able to <em>prove<\/em> all of that.\nDragon Compliance turns your WordPress site into something you can hand to an\nauditor:<\/p>\n\n<ul>\n<li><strong>Software inventory<\/strong> - WordPress core, every plugin and theme with version,\nauthor and license, plus the PHP\/database\/server environment.<\/li>\n<li><strong>SBOM export<\/strong> - download a standards-compliant CycloneDX 1.6 JSON Software\nBill of Materials, the artifact auditors and enterprise customers ask for.<\/li>\n<li><strong>Vulnerability monitoring that works out of the box<\/strong> - a daily scan checks\nWordPress core and every installed plugin and theme against the free\nWPVulnerability database, with no account or API key, and lists affected\ncomponents by severity with CVE links. A component that could not be checked\nis shown as \"not checked\", never as clear. If you prefer, switch to the\nWordfence Intelligence feed with your own free token.<\/li>\n<li><strong>Vulnerability alerts<\/strong> - new critical findings, and new findings whose\nseverity has not been published yet, are emailed to the site admin or to a\nlist of addresses you choose.<\/li>\n<li><strong>CRA readiness checklist<\/strong> - automatic checks (HTTPS, auto-updates coverage,\ndebug mode, file editing, 2FA, default admin account, open criticals) plus\nmanual attestations for process facts like your update policy and backups,\nwith a completion score.<\/li>\n<li><strong>Evidence log<\/strong> - every scan, detection, resolution and attestation change\nis recorded with a timestamp, building the audit trail regulators expect.<\/li>\n<\/ul>\n\n<p>Matching, findings and the evidence log all stay in your WordPress database.\nTo check for known vulnerabilities, the plugin asks a public vulnerability\ndatabase about your installed components (see External services below): it\nsends component names and the WordPress version, never your site address,\nusers or content.<\/p>\n\n<p>Everything above is free, fully functional and unlimited.<\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin connects to one vulnerability database at a time, chosen under\nTools \u2192 Compliance \u2192 Settings. Both are used only for vulnerability\nmonitoring: once a day, after you add, update or remove a plugin or theme,\nwhen you press \"Scan now\", and once more shortly after a scan that ran out of\ntime before every component was looked up.<\/p>\n\n<h4>WPVulnerability (default)<\/h4>\n\n<p>WPVulnerability (https:\/\/www.wpvulnerability.com) is a free, public database\nof known WordPress vulnerabilities. By default the plugin asks\nwww.wpvulnerability.net about each installed component: the slug (folder\nname) of every plugin and theme, and the WordPress core version number. Plugin\nand theme versions are not sent; the plugin compares versions on your server.\nYour site address, users and content are not sent; like any web request, the\nservice sees your server's IP address. Answers are cached on your site for\n12 hours. No account or API key is needed.<\/p>\n\n<p>WPVulnerability data is published under CC0 1.0.<\/p>\n\n<p>WPVulnerability privacy policy: https:\/\/www.wpvulnerability.com\/privacy\/\nWPVulnerability licence: https:\/\/www.wpvulnerability.com\/license\/<\/p>\n\n<h4>Wordfence Intelligence (only when you choose it)<\/h4>\n\n<p>If you select Wordfence Intelligence and enter your own API token, the plugin\ninstead downloads the full Wordfence Intelligence vulnerability list from\nwww.wordfence.com (a service by Defiant Inc.) and matches it on your server.\nOnly your API token is sent with that request - no data about your site, its\ninventory or its users. Without a token nothing is sent to Wordfence. You need\na free wordfence.com account to generate a token.<\/p>\n\n<p>Wordfence terms of service: https:\/\/www.wordfence.com\/terms-of-use\/\nWordfence privacy policy: https:\/\/www.wordfence.com\/privacy-policy\/<\/p>\n\n<h3>Credits<\/h3>\n\n<p>The WordPress.org listing icon is drawn with glyphs from Lucide (https:\/\/lucide.dev), ISC License. Copyright (c) for portions of Lucide are held by Cole Bemis 2013-2022 as part of Feather (https:\/\/feathericons.com, MIT License). All other copyright (c) for Lucide are held by Lucide Contributors 2022. The plugin itself does not include these icons.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin files to <code>\/wp-content\/plugins\/dragon-compliance<\/code>, or\ninstall through the WordPress plugins screen.<\/li>\n<li>Activate the plugin through the 'Plugins' screen.<\/li>\n<li>Go to Tools \u2192 Compliance. Vulnerability monitoring is already on; press\n\"Scan now\" for a first result, or wait for the daily scan.<\/li>\n<li>(Optional) Under Settings, add more alert recipients, or switch the data\nsource to Wordfence Intelligence with your own free API token.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20the%20cra%20apply%20to%20my%20site%3F\"><h3>Does the CRA apply to my site?<\/h3><\/dt>\n<dd><p>Not necessarily. The CRA covers products with digital elements placed on the\nEU market, and NIS2 covers organisations in certain sectors above certain\nsizes; many websites fall under neither. Whether either applies to your\nbusiness is a legal question. This plugin gives you the technical evidence\nbase either way - it is not legal advice.<\/p><\/dd>\n<dt id=\"where%20does%20the%20vulnerability%20data%20come%20from%3F\"><h3>Where does the vulnerability data come from?<\/h3><\/dt>\n<dd><p>By default from WPVulnerability, a free public database, without an account.\nThe plugin sends it the slugs of your installed plugins and themes and your\nWordPress version, and compares the answers with your installed versions on\nyour server. You can switch to the Wordfence Intelligence Community Edition\nfeed with your own free token, in which case the whole feed is downloaded and\nnothing about your site is sent.<\/p><\/dd>\n<dt id=\"what%20happens%20if%20a%20lookup%20fails%3F\"><h3>What happens if a lookup fails?<\/h3><\/dt>\n<dd><p>That component is listed as \"not checked\" on the Dashboard, Findings and\nInventory tabs and in the evidence log, and its open findings stay open. It is\nnever reported as free of vulnerabilities. The next scan tries again.<\/p>\n\n<p>A plugin or theme whose folder name cannot be a WordPress.org slug (for\nexample one with a space, a plus sign or brackets in it), one WPVulnerability\ndoes not accept as a slug, and a custom single-file plugin (a lone .php file\nin the plugins folder) are not failures: they are shown as \"Checked - not in\nthe database\". A pre-release of WordPress (a beta or release candidate) is\nchecked against the release it leads up to.<\/p><\/dd>\n<dt id=\"which%20findings%20are%20emailed%3F\"><h3>Which findings are emailed?<\/h3><\/dt>\n<dd><p>New critical findings, and new findings whose severity the data source has not\npublished yet. The email lists the critical ones first, then the others, each\nmarked \"severity not published - review it\". Findings of high, medium or low\nseverity are shown on the Findings tab but not emailed.<\/p><\/dd>\n<dt id=\"what%20does%20the%20%22no%20open%20critical%20vulnerabilities%22%20check%20count%3F\"><h3>What does the \"No open critical vulnerabilities\" check count?<\/h3><\/dt>\n<dd><p>Only open findings with a published critical severity. A finding whose\nseverity has not been published does not make the check fail, so review those\non the Findings tab. The check also fails while any component could not be\nchecked.<\/p><\/dd>\n<dt id=\"what%20happens%20when%20i%20switch%20the%20data%20source%3F\"><h3>What happens when I switch the data source?<\/h3><\/dt>\n<dd><p>At the next scan, findings from the old source get the status \"Closed: data\nsource changed\", never \"Resolved\", and the new source's findings are recorded.\nAn issue both sources report (same component and CVE) is not alerted again,\nand stays ignored if you had ignored it. The switch is recorded in the\nevidence log. A site updated from an earlier version that had vulnerability\ndata but no saved Wordfence token moves to WPVulnerability, and that switch\nis recorded the same way.<\/p><\/dd>\n<dt id=\"who%20receives%20alerts%3F\"><h3>Who receives alerts?<\/h3><\/dt>\n<dd><p>The site admin email by default. Under Settings you can enter several\naddresses, one per line or separated by commas; each gets its own email.<\/p><\/dd>\n<dt id=\"what%20sbom%20formats%20are%20supported%3F\"><h3>What SBOM formats are supported?<\/h3><\/dt>\n<dd><p>CycloneDX 1.6 JSON.<\/p><\/dd>\n<dt id=\"what%20is%20an%20sbom%2C%20and%20why%20would%20i%20need%20one%3F\"><h3>What is an SBOM, and why would I need one?<\/h3><\/dt>\n<dd><p>A Software Bill of Materials lists every software component you run, with versions and licenses - like an ingredients label for your site. Auditors, enterprise customers and EU regulation increasingly ask for one. This plugin exports yours in the standard CycloneDX format in one click.<\/p><\/dd>\n<dt id=\"when%20do%20the%20cra%20obligations%20apply%3F\"><h3>When do the CRA obligations apply?<\/h3><\/dt>\n<dd><p>The Cyber Resilience Act's vulnerability and incident reporting obligations have applied since 11 September 2026, and the remaining requirements apply from 11 December 2027. If the CRA touches your business, the evidence trail is worth keeping from now on - findings and attestations only prove a history if they have one.<\/p><\/dd>\n<dt id=\"will%20it%20slow%20down%20my%20site%3F\"><h3>Will it slow down my site?<\/h3><\/dt>\n<dd><p>No. Scans run in the background once a day via WP-Cron, there is no front-end code at all, and vulnerability answers are cached for 12 hours.<\/p><\/dd>\n<dt id=\"is%20this%20a%20malware%20scanner%3F\"><h3>Is this a malware scanner?<\/h3><\/dt>\n<dd><p>No. It matches your installed software versions against a database of\npublicly known vulnerabilities. It does not scan files for infections.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>New: vulnerability monitoring works out of the box. WPVulnerability is the default data source, with no account or API key. Each installed plugin and theme is looked up by its slug, and WordPress core by its version; answers are cached for 12 hours.<\/li>\n<li>New: a component whose lookup fails is listed as \"not checked\" on the Dashboard, Findings and Inventory tabs and in the evidence log. Its open findings stay open, and the \"No open critical vulnerabilities\" check does not pass until it is checked.<\/li>\n<li>New: a plugin or theme whose name cannot be a WordPress.org slug, and a custom single-file plugin, is shown as \"Checked - not in the database\" instead of \"not checked\". A WordPress beta or release candidate is checked against the release it leads up to.<\/li>\n<li>New: findings whose severity has not been published are emailed too, after the critical ones and marked for review.<\/li>\n<li>New: switching the data source closes the old source's findings as \"data source changed\" instead of fixed. An issue both sources report is not alerted again and keeps its ignored status. A site updated with vulnerability data but no saved Wordfence token moves to WPVulnerability, and that switch is recorded in the evidence log too.<\/li>\n<li>Changed: a WordPress core issue listed several times under one CVE is shown once, and a copy without a CVE is dropped when its description matches a CVE entry. Copies worded differently can still appear as separate findings.<\/li>\n<li>New: choose the data source under Settings. Sites that already saved a Wordfence Intelligence token keep Wordfence.<\/li>\n<li>New: alerts can go to several email addresses (one per line or separated by commas). Leave the field empty to keep emailing the site admin. A list with an invalid address is refused whole, and an alert the mail system refuses is recorded in the evidence log.<\/li>\n<li>Changed: requests to WPVulnerability and Wordfence identify the plugin instead of carrying the site address in the user agent.<\/li>\n<li>Changed: the Wordfence feed can only be fetched from www.wordfence.com.<\/li>\n<li>Removed: the License tab and all add-on prompts.<\/li>\n<\/ul>\n\n<h4>1.0.13<\/h4>\n\n<ul>\n<li>Checklist notes and attestations are cleaned as they are read. A malformed submission saves an empty note instead of the word \"Array\".<\/li>\n<li>The plugin inventory reads each plugin's licence through WordPress's own plugin list.<\/li>\n<li>Another plugin that changes the list of plugin headers can no longer hide licences from the inventory or the SBOM.<\/li>\n<li>Fixed: uninstall deletes data only when the opt-in is clearly on (1, true, yes or on), not for a value set to \"false\" or \"no\".<\/li>\n<\/ul>\n\n<h4>1.0.12<\/h4>\n\n<ul>\n<li>Fixed: the daily scan and the scan after a plugin change stopped with an error when run by WP-Cron, so only Scan now worked. Scheduled scans now run.<\/li>\n<li>Fixed: a custom single-file plugin named like a WordPress.org plugin could be matched to that plugin's vulnerabilities. Only Hello Dolly is matched by file name.<\/li>\n<li>Multisite: each site schedules its own scan, reads the network's auto-update settings and sees network-activated two-factor plugins.<\/li>\n<li>Deactivating clears both scheduled scans, and uninstall runs per site.<\/li>\n<\/ul>\n\n<h4>1.0.11<\/h4>\n\n<ul>\n<li>Fixed: a vulnerability that returns after it was resolved (for example after a plugin downgrade) is reopened and alerted again.<\/li>\n<li>Single-file plugins such as Hello Dolly are matched against the vulnerability feed.<\/li>\n<li>Alert text shows vulnerability titles correctly.<\/li>\n<\/ul>\n\n<h4>1.0.10<\/h4>\n\n<ul>\n<li>Every screen, email and alert is now translatable, so community translations from translate.wordpress.org cover the whole plugin. Counts use proper plural forms, and numbers and dates follow your site's language.<\/li>\n<li>Severity, status and evidence entries show readable labels.<\/li>\n<\/ul>\n\n<h4>1.0.9<\/h4>\n\n<ul>\n<li>An \"Upgrade to Pro\" link on the Plugins screen, a one-line pointer at the foot of the plugin's own screens, and a single dismissible note once the plugin has done its job. All three disappear when the Pro add-on is active; nothing in the free plugin is locked or changed.<\/li>\n<\/ul>\n\n<h4>1.0.8<\/h4>\n\n<ul>\n<li>Fixed: an attestation whose database write failed was still logged as evidence and reported as saved. All four attestations are now stored in a single write that is read back before any evidence is recorded, evidence is recorded only for items that actually changed, and a refused write shows an error instead of \"Attestations saved\".<\/li>\n<li>Fixed: ignoring or reopening a finding recorded a status-change evidence entry even when the row did not change. Evidence is now recorded only when the status actually changed, and a no-op or failed update shows a notice instead of \"Finding updated\".<\/li>\n<li>Fixed: a scan whose \"mark resolved\" write failed still recorded resolution evidence and fired the resolved hook for every finding. Resolutions that were not stored are no longer reported, and the next scan retries them.<\/li>\n<li>Fixed: the database schema version was stamped even when a table could not be created, which stopped the plugin from retrying. Each table is now checked to exist before the version is recorded; a failure is retried every 10 minutes and shown to administrators as a notice naming the missing tables.<\/li>\n<\/ul>\n\n<h4>1.0.7<\/h4>\n\n<ul>\n<li>Asks for a WordPress.org review once, only on the Compliance screen and only after a vulnerability scan has completed or an SBOM has been exported. \"Maybe later\" snoozes it for a month and \"No thanks\" is permanent.<\/li>\n<li>New <code>dragoncompliance_sbom_exported<\/code> action fires when an SBOM download is generated.<\/li>\n<li>Listing title, description and tags now say what the plugin does, so it is easier to find in the plugin directory.<\/li>\n<\/ul>\n\n<h4>1.0.6<\/h4>\n\n<ul>\n<li>New: the vulnerability feed source can now be supplied by Dragon Compliance Pro, which downloads it from Dragon Core so licensed sites need no Wordfence account. The free plugin only accepts www.wordfence.com or api.dragoncore.ltd as a source - any other host is ignored.<\/li>\n<li>Improvement: the dashboard and Findings screens now say when monitoring is configured but no vulnerability data has been downloaded yet, and show why the last download failed, instead of looking healthy with nothing checked.<\/li>\n<li>Hardening: the feed request no longer follows redirects; the Wordfence token is attached to the request after the source is validated and is never exposed to other plugins; an oversized feed record aborts the refresh (keeping the last good data) rather than being read into memory; an empty local index is never revalidated with a conditional request.<\/li>\n<li>Free users: no change; your Wordfence token keeps working exactly as before.<\/li>\n<\/ul>\n\n<h4>1.0.5<\/h4>\n\n<ul>\n<li>Security: the stored Wordfence Intelligence API token now uses authenticated encryption (tamper-detecting), so a modified ciphertext is rejected rather than decrypted.<\/li>\n<li>New: vulnerability monitoring re-scans immediately when a plugin or theme is installed, updated or removed, instead of waiting for the next daily run - newly added software is checked straight away.<\/li>\n<\/ul>\n\n<h4>1.0.4<\/h4>\n\n<ul>\n<li>Expanded the plugin listing: clearer free vs Pro breakdown, fuller FAQ, and a live-preview blueprint.<\/li>\n<\/ul>\n\n<h4>1.0.3<\/h4>\n\n<ul>\n<li>Added screenshots of every screen to the plugin listing.<\/li>\n<\/ul>\n\n<h4>1.0.2<\/h4>\n\n<ul>\n<li>Compatibility: tested up to WordPress 7.1.<\/li>\n<li>Housekeeping: corrected the contributor name in the plugin readme.<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>Performance: new database index keeps evidence sealing fast as the log grows.<\/li>\n<li>New: \"Delete data on uninstall\" checkbox in settings.<\/li>\n<li>Polish: helpful empty states on the Inventory and Evidence screens; accessibility improvements.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release: inventory, CycloneDX 1.6 SBOM export, daily vulnerability\nmonitoring via Wordfence Intelligence, CRA readiness checklist with\nattestations, evidence log, critical-finding email alert.<\/li>\n<\/ul>","raw_excerpt":"CRA and NIS2 compliance for WordPress: software inventory, SBOM export, vulnerability scanning, readiness checklist and a timestamped evidence log.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/de-at.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/358504","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/de-at.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/de-at.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/de-at.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=358504"}],"author":[{"embeddable":true,"href":"https:\/\/de-at.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/dragoncoreltd"}],"wp:attachment":[{"href":"https:\/\/de-at.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=358504"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/de-at.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=358504"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/de-at.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=358504"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/de-at.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=358504"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/de-at.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=358504"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/de-at.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=358504"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}