CRAGuard automates EU Cyber Resilience Act compliance for WordPress. Generate SBOMs, deploy secure VDPs, and track 24h ENISA deadlines.
This plugin acts as a client connecting to a secure, external API gateway (hosted on Supabase) to process and store Vulnerability Disclosure Program (VDP) reports remotely. This prevents sensitive zero-day exploit data from being exposed in your local WordPress database.
CRAGuard provides the core architecture necessary to satisfy EU market regulations, protecting your clients and maintaining strict security telemetry logs.
[craguard_vdp] shortcode to satisfy the CRA mandate for a public researcher point-of-contact.For agencies managing critical B2B infrastructure or high-volume client sites, the premium tier connects the plugin to our secure cloud environment:
* Encrypted Cloud Telemetry: Routes incoming bug reports securely to a centralized database via our API Gateway, preventing zero-day vulnerabilities from sitting in your local database.
* VDP Cloud Telemetry Dashboard: View and manage external security logs directly from your WordPress admin panel.
* 24-Hour ENISA Urgency Dashboard: Tracks active, unresolved security incidents with a live, visual countdown timer pulling from cloud telemetry, ensuring your development team never misses a mandatory reporting deadline.