Everything you need
No paid extensions required. All features ship with the free plugin.
Plugin Risk Scanner
Evaluates every active plugin on your site against CRA readiness standards — flagging abandoned, unmaintained, or high-risk plugins before they become a compliance liability.
Visual Compliance Dashboard
A central hub showing your compliance score across CRA, GDPR, and NIS2, outstanding issues, and improvement history over time.
PDF Audit Report
Export a professionally formatted PDF report listing all scanned controls, their status, and remediation steps. Ready to share with clients or auditors.
VDP Generator
Automatically generate a Vulnerability Disclosure Policy — a CRA requirement. Published at a standard URL and formatted to RFC 9116.
SBOM Generator
Generate a Software Bill of Materials in CycloneDX 1.4 JSON format, listing all active plugins and their versions. Required under CRA for connected products sold in the EU.
security.txt (RFC 9116)
Create and host a security.txt file at /.well-known/security.txt — a CRA requirement that tells security researchers how to report vulnerabilities.
How it works
Run Your First Scan
Install the plugin and click "Run Compliance Scan". It checks your site against CRA, GDPR, and NIS2 requirements in under 60 seconds.
Fix the Issues
The dashboard lists every failing control with an explanation and step-by-step remediation guide. Fix issues one by one.
Generate Documentation
Once your score improves, generate your VDP, SBOM, security.txt and conformity declaration — all required documents in one place.
Frequently asked questions
Can't find what you're looking for? Open a support thread on WordPress.org.
Changelog
- + Initial release
- + CRA / GDPR / NIS2 compliance scanner
- + Visual compliance dashboard
- + PDF audit report export
- + VDP, SBOM, security.txt generators
- + EU Conformity Declaration template
More free plugins
Ready to install?
Free on WordPress.org. No account required. Works in under 2 minutes.
Download Erdo CRA Compliance