{"id":339635,"date":"2026-08-02T13:41:17","date_gmt":"2026-08-02T13:41:17","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/proofwright\/"},"modified":"2026-08-06T12:55:31","modified_gmt":"2026-08-06T12:55:31","slug":"proofwright","status":"publish","type":"plugin","link":"https:\/\/gu.wordpress.org\/plugins\/proofwright\/","author":23518379,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.23.12","stable_tag":"0.23.12","tested":"7.0.4","requires":"6.0","requires_php":"8.1","requires_plugins":null,"header_name":"Proofwright","header_author":"1click2open","header_description":"EU Cyber Resilience Act (CRA) compliance & evidence agent for WordPress: a hashed, immutable, diffable SBOM (SPDX + CycloneDX) of every component, with a deterministic compliance posture score. Not legal advice.","assets_banners_color":"fbfcfd","last_updated":"2026-08-06 12:55:31","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/1click2open.com","rating":0,"author_block_rating":0,"active_installs":0,"downloads":146,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","faq","changelog"],"tags":{"0.23.10":{"tag":"0.23.10","author":"sirahama","date":"2026-08-03 12:58:00"},"0.23.11":{"tag":"0.23.11","author":"sirahama","date":"2026-08-03 18:03:50"},"0.23.12":{"tag":"0.23.12","author":"sirahama","date":"2026-08-06 12:55:31"},"0.23.8":{"tag":"0.23.8","author":"sirahama","date":"2026-08-02 13:41:03"},"0.23.9":{"tag":"0.23.9","author":"sirahama","date":"2026-08-02 14:56:50"}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3632879,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3632879,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256},"icon.svg":{"filename":"icon.svg","revision":3632879,"resolution":false,"location":"assets","locale":false}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3632807,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3632807,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250},"banner.svg":{"filename":"banner.svg","revision":3632930,"resolution":false,"location":"assets","locale":false}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.23.10","0.23.11","0.23.12","0.23.8","0.23.9"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3631866,"resolution":"1","location":"assets","locale":"","width":2880,"height":1800},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3631866,"resolution":"2","location":"assets","locale":"","width":2880,"height":1800},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3631866,"resolution":"3","location":"assets","locale":"","width":2880,"height":1800},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3631866,"resolution":"4","location":"assets","locale":"","width":2880,"height":1800}},"screenshots":{"1":"The Proofwright dashboard \u2014 deterministic posture score, CRA readiness, and guided setup.","2":"CRA conformity readiness \u2014 every Annex I requirement tracked as Met (auto-evidenced from scans) or Pending.","3":"Your path to CRA readiness \u2014 the ordered roadmap, flagged by obligation level (Must \/ Recommended \/ Optional).","4":"Posture drivers with the full factor-by-factor score breakdown, the hash-chained SBOM snapshot, and detected security controls."}},"plugin_section":[],"plugin_tags":[14361,270120,264405,269595,600],"plugin_category":[54],"plugin_contributors":[270082],"plugin_business_model":[],"class_list":["post-339635","plugin","type-plugin","status-publish","hentry","plugin_tags-compliance","plugin_tags-cra","plugin_tags-cyber-resilience-act","plugin_tags-sbom","plugin_tags-security","plugin_category-security-and-spam-protection","plugin_contributors-sirahama","plugin_committers-sirahama"],"banners":{"banner":"https:\/\/ps.w.org\/proofwright\/assets\/banner-772x250.png?rev=3632807","banner_2x":"https:\/\/ps.w.org\/proofwright\/assets\/banner-1544x500.png?rev=3632807","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":"https:\/\/ps.w.org\/proofwright\/assets\/icon.svg?rev=3632879","icon":"https:\/\/ps.w.org\/proofwright\/assets\/icon.svg?rev=3632879","icon_2x":false,"generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/proofwright\/assets\/screenshot-1.png?rev=3631866","caption":"The Proofwright dashboard \u2014 deterministic posture score, CRA readiness, and guided setup."},{"src":"https:\/\/ps.w.org\/proofwright\/assets\/screenshot-2.png?rev=3631866","caption":"CRA conformity readiness \u2014 every Annex I requirement tracked as Met (auto-evidenced from scans) or Pending."},{"src":"https:\/\/ps.w.org\/proofwright\/assets\/screenshot-3.png?rev=3631866","caption":"Your path to CRA readiness \u2014 the ordered roadmap, flagged by obligation level (Must \/ Recommended \/ Optional)."},{"src":"https:\/\/ps.w.org\/proofwright\/assets\/screenshot-4.png?rev=3631866","caption":"Posture drivers with the full factor-by-factor score breakdown, the hash-chained SBOM snapshot, and detected security controls."}],"raw_content":"<!--section=description-->\n<p>Proofwright is the on-site agent for the EU Cyber Resilience Act (CRA). It builds the <strong>provable evidence<\/strong> behind a CRA due-diligence posture \u2014 and the foundation is free: a rigorous Software Bill of Materials, a deterministic readiness score, and the CRA paperwork.<\/p>\n\n<p><strong>Inventory &amp; SBOM.<\/strong> Inventories every component \u2014 core, plugins, must-use plugins, drop-ins, themes (and parents), the PHP runtime, and Composer dependencies (direct vs transitive) \u2014 and emits a machine-readable Software Bill of Materials in both <strong>SPDX 2.3<\/strong> and <strong>CycloneDX 1.5<\/strong>, with package URLs (PURLs).<\/p>\n\n<p><strong>Immutable, hash-chained snapshots.<\/strong> Each SBOM is stored as a dated, tamper-evident snapshot with diff-over-time, so you can prove how your component graph changed.<\/p>\n\n<p><strong>CRA readiness, in your dashboard.<\/strong> A deterministic posture score; an on-site readiness engine mapped to CRA Annex I (no external calls \u2014 no data leaves your server); a scope-classification wizard; a CRA document generator (Vulnerability Disclosure Policy, EU Declaration of Conformity, risk assessment, technical-documentation outline); a consolidated compliance calendar with iCal export; a cross-framework crosswalk (ISO\/IEC 27001, SOC 2, NIS2); and a <code>\/.well-known\/security.txt<\/code> + Vulnerability Disclosure Policy publisher.<\/p>\n\n<p><strong>Tamper-evident evidence log.<\/strong> An append-only, cryptographically verifiable log of the material actions taken on your site.<\/p>\n\n<p><strong>Not legal advice.<\/strong> A \"not legal advice\" disclaimer appears on every generated document and report.<\/p>\n\n<h4>Related plugin<\/h4>\n\n<p>This plugin is complete and fully functional on its own. Some further capabilities \u2014 continuous vulnerability monitoring, the SRP incident workflow, the supplier-conformity register, exportable evidence packs, a cross-site fleet console and team review \u2014 are provided by a <strong>separate<\/strong> plugin, Proofwright Pro, available from proofwright.eu. They are not part of, and not required by, the plugin in this directory.<\/p>\n\n<h3>Disclaimer<\/h3>\n\n<p><strong>Proofwright is a workflow and evidence tool, not legal advice and not a guarantee of compliance.<\/strong> It helps you build and maintain the documentation and evidence that support a Cyber Resilience Act due-diligence posture; it does not make any product or site compliant. Consult qualified counsel for your obligations under Regulation (EU) 2024\/2847.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20this%20make%20my%20site%20cra-compliant%3F\"><h3>Does this make my site CRA-compliant?<\/h3><\/dt>\n<dd><p>No. Proofwright provides the workflow and the provable evidence; compliance is your legal responsibility. The \"not legal advice\" disclaimer appears on every generated document and report.<\/p><\/dd>\n<dt id=\"what%20does%20this%20plugin%20include%3F\"><h3>What does this plugin include?<\/h3><\/dt>\n<dd><p>Everything it needs to be useful on its own: component inventory, the SPDX 2.3 \/ CycloneDX 1.5 SBOM, immutable hash-chained snapshots with diff, the posture score and on-site readiness engine, the scope wizard, the CRA document generator, the compliance calendar, the cross-framework crosswalk, the security.txt \/ VDP publisher, and the tamper-evident evidence log \u2014 all fully functional, with no restrictions. Continuous vulnerability monitoring, the SRP incident workflow, the supplier register, exportable evidence packs and a cross-site fleet console are provided by a separate plugin, Proofwright Pro (see \"Related plugin\").<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20send%20my%20data%20anywhere%3F\"><h3>Does the plugin send my data anywhere?<\/h3><\/dt>\n<dd><p>No. This plugin runs entirely on your server \u2014 the readiness engine and SBOM make no external calls, and there is no licence check or phone-home of any kind.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>0.23.12<\/h4>\n\n<ul>\n<li>Fixed the software inventory listing build tools (npm dev dependencies) as if they were part of your site. Re-scan after updating.<\/li>\n<\/ul>\n\n<h4>0.23.11<\/h4>\n\n<ul>\n<li>Fixed a fatal error when exporting CRA documents. Now translated into all 23 EU languages plus Arabic.<\/li>\n<\/ul>\n\n<h4>0.23.10<\/h4>\n\n<ul>\n<li>Now available in 14 European languages. Bundled translations are loaded correctly.<\/li>\n<\/ul>\n\n<h4>0.23.9<\/h4>\n\n<ul>\n<li>Added the full GPL-2.0 licence text to the package; removed an unused generated file.<\/li>\n<\/ul>\n\n<h4>0.23.8<\/h4>\n\n<ul>\n<li>The posture-score breakdown, the SBOM change-since-last-snapshot view, and the attestation-renewal check now run on every install with no restrictions. Served pages load their stylesheet via the WordPress style API.<\/li>\n<\/ul>\n\n<h4>0.23.7<\/h4>\n\n<ul>\n<li>Minor packaging fix.<\/li>\n<\/ul>\n\n<h4>0.23.6<\/h4>\n\n<ul>\n<li>Housekeeping: removed unused image files from the package.<\/li>\n<\/ul>\n\n<h4>0.23.5<\/h4>\n\n<ul>\n<li>Pages the plugin serves now link a packaged stylesheet instead of embedding CSS; documents you download keep their styles inline so the saved file works on its own.<\/li>\n<\/ul>\n\n<h4>0.23.4<\/h4>\n\n<ul>\n<li>The plugin is fully functional with no restrictions of any kind: all feature gating removed, no licence checks, and the plugin no longer defines global WordPress constants. Further capabilities are provided by a separate plugin.<\/li>\n<\/ul>\n\n<h4>0.23.3<\/h4>\n\n<ul>\n<li>Packaging refresh for the plugin directory; no functional changes since 0.23.2.<\/li>\n<\/ul>\n\n<h4>0.23.2<\/h4>\n\n<ul>\n<li>Every feature in the plugin is fully functional, with no restrictions of any kind.<\/li>\n<\/ul>\n\n<h4>0.23.0<\/h4>\n\n<ul>\n<li>CRA readiness roadmap, a compliance calendar with iCal export, a cross-framework control crosswalk (ISO\/IEC 27001, SOC 2, NIS2), and the on-site readiness engine mapped to CRA Annex I.<\/li>\n<\/ul>\n\n<h4>0.20.0<\/h4>\n\n<ul>\n<li>Annex II \"Information and Instructions to the User\" document generator; front-end (npm\/yarn) dependency scanning folded into the SBOM.<\/li>\n<\/ul>\n\n<h4>0.13.0<\/h4>\n\n<ul>\n<li>Readiness engine: deterministic, on-site security-posture detection mapped to CRA Annex I (no external calls). Detected controls are shown as evidence; gaps are shown with copy-paste remediation guidance.<\/li>\n<\/ul>\n\n<h4>0.9.0<\/h4>\n\n<ul>\n<li>Inventory + SBOM (SPDX 2.3 \/ CycloneDX 1.5) with PURLs and direct\/transitive depth; immutable, hash-chained SBOM snapshots with diff-over-time and EOL flagging; deterministic posture score; scope wizard; CRA document generator; tamper-evident evidence log. Pre-flight secret + PII scan on every export.<\/li>\n<\/ul>\n\n<h4>0.1.0<\/h4>\n\n<ul>\n<li>Initial release: SBOM spine + compliance posture score.<\/li>\n<\/ul>","raw_excerpt":"EU Cyber Resilience Act toolkit: component inventory, SPDX &amp; CycloneDX SBOM, hash-chained snapshots, a posture score, and a CRA document generator.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/gu.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/339635","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/gu.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/gu.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/gu.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=339635"}],"author":[{"embeddable":true,"href":"https:\/\/gu.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/sirahama"}],"wp:attachment":[{"href":"https:\/\/gu.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=339635"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/gu.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=339635"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/gu.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=339635"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/gu.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=339635"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/gu.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=339635"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/gu.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=339635"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}