Vulnerability Monitor for the EU Cyber Resilience Act
by Mecanik Dev Ltd 0 (0 reviews)

Vulnerability Monitor for the EU Cyber Resilience Act

EU Cyber Resilience Act readiness for WordPress: build a CycloneDX SBOM, monitor vulnerabilities and export the documents auditors require.

Vulnerability Monitor for the EU Cyber Resilience Act ranks #64,708 among WordPress.org plugins with 0+ active installations, is #3,416 of 4,488 in the Security category, and was last updated Jun 30, 2026. Data from WordPress.org, refreshed twice daily — see methodology.

Tested up to WP 7.0.4 (Current: 7.1)
v1.0.0 Current Version v1.0.0
Updated 2 months ago Last Update on 30 Jun, 2026
Refreshed 8 hours ago Last Refreshed on
#3,416 of 4,488 in Security
View on WordPress.org
Rank
#64,708
No change
Active Installs
0+
-100%
KW Avg Position
65.3
0.3 worse
Downloads
153
+7 today
Support Resolved
0%
No change
Rating
0%
Review 0 out of 5
0 (0 reviews)

Next Milestone 10

Total Progress 10%
0+ 10+
32,284
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 9 more installs to reach 10+

Rank Changes

46,818 51,708 56,599 61,490 66,380 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
46,818 51,708 56,599 61,490 66,380 01-09-2026 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
Current #64,708
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

0 10 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
0 10 01-09-2026 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

0.0
0 reviews
Overall 0%
5
0 (0%)
4
0 (0%)
3
0 (0%)
2
0 (0%)
1
0 (0%)

Frequently Asked Questions

Common questions about Vulnerability Monitor for the EU Cyber Resilience Act

The EU Cyber Resilience Act (Regulation (EU) 2024/2847) is European law that sets cybersecurity requirements for products with digital elements placed on the EU market. It expects makers of such products to know what their software is made of, to track and handle vulnerabilities, and to document conformity.
The CRA applies to manufacturers, importers and distributors of products with digital elements placed on the EU market, which includes commercial WordPress plugins and themes and other distributed software products built on or shipped with WordPress. (Purely online services are generally covered by NIS2 rather than the CRA.) Non-compliance can mean fines of up to 15 million euro or 2.5% of worldwide annual turnover, and products being withdrawn from the EU market. The main obligations apply from 11 December 2027, with vulnerability reporting from 11 September 2026.
No single tool can make you fully compliant, because the CRA also covers your internal processes. This plugin provides core technical evidence for a WordPress site: a component inventory, a CycloneDX SBOM, vulnerability monitoring, and the CSAF/VEX and Declaration of Conformity documents that support a CRA vulnerability handling process.
Yes. The core is free and GPL-licensed: the component inventory, the CycloneDX SBOM export, the CSAF/VEX, SECURITY.md, EU Declaration of Conformity and compliance-report exports, plugin/theme health and integrity checks, the on-screen compliance dashboard, the audit log and the WP-CLI commands. Continuous vulnerability monitoring and automated alerts require a premium license; that license is what fills the free documents with actual vulnerability findings.
No. The component inventory, the CycloneDX SBOM and every document export (CSAF/VEX, SECURITY.md, Declaration of Conformity and the compliance report) run locally on your server and are completely free. A license adds the live vulnerability data and alerts; until a scan runs, the documents simply list no vulnerabilities.
Your inventory is sent to the Mecanik API, which matches it against the U.S. National Vulnerability Database (NVD), OSV.dev and Wordfence Intelligence, and returns the findings enriched with CVSS, EPSS and CISA KEV signals. No post content, user data or visitor data is ever sent, and no upstream API keys are bundled in the plugin.
Yes. The core compliance tasks are available through WP-CLI, including the inventory, SBOM, scanning, the document exports and the policy gate, for example wp cravm generate-sbom and wp cravm policy-check, the latter exiting non-zero so a pipeline can block a release. (Configuration such as alert settings and suppression rules is done in wp-admin.)

Sign In / Register

You need to sign in or register to use this feature.