
內容簡介
Dragon Compliance 是一款專為滿足歐盟網路韌性法案與 NIS2 指令而設計的 WordPress 外掛,幫助企業管理軟體清單、監控漏洞並提供合規證明,確保網站安全性與合規性。
【主要功能】
• 軟體清單管理:列出 WordPress 核心、外掛與佈景主題的版本、作者與授權資訊
• 漏洞監控:每日掃描並比對 Wordfence Intelligence 漏洞資料庫
• CRA 準備檢查表:自動檢查網站安全性與合規性
• 證據日誌:記錄每次掃描、檢測與變更的時間戳
• SBOM 匯出:下載符合標準的 CycloneDX JSON 軟體材料清單
外掛標籤
開發者團隊
原文外掛簡介
The EU Cyber Resilience Act (CRA) and NIS2 directive expect businesses to know
what software they run, monitor it for known vulnerabilities, patch without
delay — and to be able to prove all of that. Dragon Compliance turns your
WordPress site into something you can hand to an auditor:
Software inventory — WordPress core, every plugin and theme with version,
author and license, plus the PHP/database/server environment.
SBOM export — download a standards-compliant CycloneDX 1.6 JSON Software
Bill of Materials, the artifact auditors and enterprise customers ask for.
Vulnerability monitoring — a daily scan matches your inventory against
the Wordfence Intelligence vulnerability database and lists affected
components by severity. New critical findings can email the site admin.
CRA readiness checklist — automatic checks (HTTPS, auto-updates coverage,
debug mode, file editing, 2FA, default admin account, open criticals) plus
manual attestations for process facts like your update policy and backups,
with a completion score.
Evidence log — every scan, detection, resolution and attestation change
is recorded with a timestamp, building the audit trail regulators expect.
Everything is processed locally on your server. Your inventory is never
uploaded anywhere — the only outbound request is downloading the public
vulnerability database.
Everything above is free, fully functional and unlimited.
Dragon Compliance Pro
For agencies and businesses that answer to clients or auditors:
White-label scheduled compliance reports
SBOM snapshots with diffs, and SPDX 2.3 export
Tamper-evident hash-chained evidence log
Time-to-patch metrics
Alert routing: multiple recipients, signed webhooks, Slack
NIS2 mapping view
See Dragon Compliance Pro for details.
External services
This plugin can connect to the Wordfence Intelligence vulnerability database
(a service by Defiant Inc.) to download its public list of known WordPress
vulnerabilities. This is required for the vulnerability-monitoring feature
and happens once daily, and when you press “Scan now”.
Only a standard HTTP request with your Wordfence Intelligence API token is
sent — no data about your site, its inventory or its users is transmitted.
You need a free wordfence.com account to generate a token; without one, the
plugin’s other features work normally and monitoring stays off.
Wordfence terms of service: https://www.wordfence.com/terms-of-use/
Wordfence privacy policy: https://www.wordfence.com/privacy-policy/
If the separate Dragon Compliance Pro add-on is installed and licensed, the
same vulnerability list is downloaded from Dragon Core (api.dragoncore.ltd)
instead, so no Wordfence account is needed. That request carries only your
Dragon Core licence key and site hostname (for licence validation) — again,
nothing about your inventory or users. Dragon Core serves an unmodified copy of
the Wordfence Intelligence feed, including its copyright notices. This
plugin only ever downloads the feed from www.wordfence.com or
api.dragoncore.ltd; no other host is accepted.
Dragon Core terms: https://dragoncore.ltd/terms
Dragon Core privacy policy: https://dragoncore.ltd/privacy
