ncdLabs Assure helps WordPress site owners and operators run technical GDPR readiness work inside wp-admin: site discovery, control evaluation, consent management, script enforcement, evidence collection, remediation helpers, and audit reporting.
ncdLabs Assure verifies controls it can observe on your site, records evidence, and flags items that need manual review. It does not replace legal counsel and does not certify legal compliance.
HIPAA, SOC 2, CCPA, WCAG, and other framework catalogs are not bundled in the WordPress.org plugin. Purchase a yearly subscription through Stripe Checkout at ncdLabs Assure, download the encrypted .assure-pack file from your order confirmation, then import it from ncdLabs Assure Controls Install framework pack with your unlock key. Packs are not required for GDPR, OWASP, or NIST CSF functionality.
ncdLabs Assure connects to external services only in the cases below. Hostnames such as js.stripe.com, connect.facebook.net, googletagmanager.com, and youtube.com that appear in plugin source are local detection / verification signature strings used to recognize scripts already present on your site. The plugin does not load those third-party scripts, call those vendors’ APIs, or send visitor data to them.
Pack activation (ncdlabs.com) — When you import a purchased compliance pack, ncdLabs Assure sends your pack unlock key, framework identifier, and this site’s URL to the ncdLabs activation API to verify the Stripe purchase and bind the license to one site:
https://ncdlabs.com/products/assure/api/activateBrowser verification (ncdlabs.com, optional) — When you import a purchased compliance pack, ncdLabs Assure may call the ncdLabs provisioning API to enable hosted browser verification for consent and analytics checks. If configured, audit and discovery may also send scan targets to your configured browser verification service:
https://ncdlabs.com/products/assure/api/browser-verification/provisionhttps://browser-verify.ncdlabs.comassure_browser_verification_allowed_hosts filter.Google Analytics / Google Tag Manager OAuth (Google + ncdlabs.com, optional) — When an administrator connects Google Analytics or Google Tag Manager from Manage Integrations, ncdLabs Assure may use Google OAuth plus the Google Analytics Admin API and/or Google Tag Manager API. If you have not configured your own Google OAuth client credentials, ncdLabs Assure uses an ncdLabs OAuth proxy:
https://ncdlabs.com/products/assure/api/google/oauth/start and .../exchangeaccounts.google.com, oauth2.googleapis.com, www.googleapis.com, analyticsadmin.googleapis.com, tagmanager.googleapis.comThird-party script detection signatures (no outbound calls) — During discovery, audits, and optional browser verification, ncdLabs Assure matches HTML, network requests, and installed plugins against known vendor hostname patterns (examples: Google Analytics/Tag Manager, Meta Pixel / connect.facebook.net, LinkedIn Insight, Hotjar, Microsoft Clarity, YouTube, Vimeo, HubSpot, Mailchimp, Brevo, Stripe / js.stripe.com). Examples also include CDN hostnames such as gstatic.com, cloudflare.com, unpkg.com, and cdnjs.cloudflare.com that appear only as local classification signatures in discovery code. Matching is local string comparison against content already on your site or observed in a verification scan of your site. ncdLabs Assure does not call these vendors, load their scripts, or transmit data to them.
Site self-scan (your own WordPress site) — During discovery and audits, ncdLabs Assure may request your site’s public homepage and REST API to detect scripts, embeds, forms, and integrations. These requests stay on your site; ncdLabs Assure does not send discovery results to ncdLabs.
Optional deactivation feedback (wp_mail) — When an administrator deactivates the plugin, an optional survey may appear. Feedback is never required: Skip & deactivate, Close, Escape, or Cancel leave without sending anything. If the administrator submits feedback, the selected reason and optional comments are emailed to ncdLabs (feedback+assure@ncdlabs.com) using this site’s WordPress mail. A separate checkbox (unchecked by default) can include plugin, WordPress, and PHP versions only — never the site URL or admin email. Mail/API failure still proceeds to deactivate.
No usage telemetry or analytics are sent to ncdLabs by the plugin.
Admin, front-end, and plugins.php deactivation-feedback JavaScript and CSS are built with @wordpress/scripts (package.json and webpack.config.js). Human-readable sources ship in the plugin under assets/src/. Production builds ship in build/.
Composer production dependencies are MIT-licensed and GPL-compatible:
See each package’s LICENSE file under vendor/ for copyright notices.