Proofwright
Proofwright is the on-site agent for the EU Cyber Resilience Act (CRA). It builds the provable evidence behind a CRA due-diligence posture — and the foundation is free: a rigorous Software Bill of Materials, a deterministic readiness score, and the CRA paperwork.
Inventory & SBOM. Inventories every component — core, plugins, must-use plugins, drop-ins, themes (and parents), the PHP runtime, and Composer dependencies (direct vs transitive) — and emits a machine-readable Software Bill of Materials in both SPDX 2.3 and CycloneDX 1.5, with package URLs (PURLs).
Immutable, hash-chained snapshots. Each SBOM is stored as a dated, tamper-evident snapshot with diff-over-time, so you can prove how your component graph changed.
CRA readiness, in your dashboard. A deterministic posture score; an on-site readiness engine mapped to CRA Annex I (no external calls — no data leaves your server); a scope-classification wizard; a CRA document generator (Vulnerability Disclosure Policy, EU Declaration of Conformity, risk assessment, technical-documentation outline); a consolidated compliance calendar with iCal export; a cross-framework crosswalk (ISO/IEC 27001, SOC 2, NIS2); and a /.well-known/security.txt + Vulnerability Disclosure Policy publisher.
Tamper-evident evidence log. An append-only, cryptographically verifiable log of the material actions taken on your site.
Not legal advice. A «not legal advice» disclaimer appears on every generated document and report.
Related plugin
This plugin is complete and fully functional on its own. Some further capabilities — continuous vulnerability monitoring, the SRP incident workflow, the supplier-conformity register, exportable evidence packs, a cross-site fleet console and team review — are provided by a separate plugin, Proofwright Pro, available from proofwright.eu. They are not part of, and not required by, the plugin in this directory.
Disclaimer
Proofwright is a workflow and evidence tool, not legal advice and not a guarantee of compliance. It helps you build and maintain the documentation and evidence that support a Cyber Resilience Act due-diligence posture; it does not make any product or site compliant. Consult qualified counsel for your obligations under Regulation (EU) 2024/2847.
