All Plugins
EU Required by 2027

Erdo CRA Compliance

The first WordPress plugin purpose-built for EU Cyber Resilience Act compliance. Scan your site, generate required documentation (VDP, SBOM, security.txt, conformity declaration), produce audit-ready PDF reports, and track your compliance status from a central dashboard.

Download Free
New active installs
1 review

Everything you need

No paid extensions required. All features ship with the free plugin.

Plugin Risk Scanner

Evaluates every active plugin on your site against CRA readiness standards — flagging abandoned, unmaintained, or high-risk plugins before they become a compliance liability.

Visual Compliance Dashboard

A central hub showing your compliance score across CRA, GDPR, and NIS2, outstanding issues, and improvement history over time.

PDF Audit Report

Export a professionally formatted PDF report listing all scanned controls, their status, and remediation steps. Ready to share with clients or auditors.

VDP Generator

Automatically generate a Vulnerability Disclosure Policy — a CRA requirement. Published at a standard URL and formatted to RFC 9116.

SBOM Generator

Generate a Software Bill of Materials in CycloneDX 1.4 JSON format, listing all active plugins and their versions. Required under CRA for connected products sold in the EU.

security.txt (RFC 9116)

Create and host a security.txt file at /.well-known/security.txt — a CRA requirement that tells security researchers how to report vulnerabilities.

How it works

01

Run Your First Scan

Install the plugin and click "Run Compliance Scan". It checks your site against CRA, GDPR, and NIS2 requirements in under 60 seconds.

02

Fix the Issues

The dashboard lists every failing control with an explanation and step-by-step remediation guide. Fix issues one by one.

03

Generate Documentation

Once your score improves, generate your VDP, SBOM, security.txt and conformity declaration — all required documents in one place.

What's included — free

CRA / GDPR / NIS2 scanner
Visual compliance dashboard
PDF audit report export
VDP & SBOM generator
security.txt (RFC 9116)
Conformity declaration

Frequently asked questions

Can't find what you're looking for? Open a support thread on WordPress.org.

Changelog

v1.0.0
June 2026
  • + Initial release
  • + CRA / GDPR / NIS2 compliance scanner
  • + Visual compliance dashboard
  • + PDF audit report export
  • + VDP, SBOM, security.txt generators
  • + EU Conformity Declaration template

More free plugins

30+ active installs

Erdo Image Optimizer

WebP & AVIF conversion, auto alt text, lazy load and SEO audit — zero API key.

Learn more
10+ active installs

Erdo Draft Links

Share WordPress drafts with clients securely. No WordPress account required.

Learn more
New active installs

Erdo Client Preview

Magic links, live annotations and visitor feedback — client reviews without the email back-and-forth.

Learn more

Ready to install?

Free on WordPress.org. No account required. Works in under 2 minutes.

Download Erdo CRA Compliance