MMCRA Toolkit — Features

Every document the CRA asks for, generated inside WordPress

The EU Cyber Resilience Act wants an SBOM, a Vulnerability Disclosure Policy, and a signed Declaration of Conformity for every commercial plugin you ship — plus ongoing vulnerability monitoring and incident reporting. MMCRA Toolkit produces all of it from your existing WordPress admin. Self-hosted, no external account, no data leaving your site. Here's each piece.

SBOM generator

Generate a valid CycloneDX 1.6 Software Bill of Materials for your WordPress plugin in one click. MMCRA Toolkit reads your composer.lock and package-lock.json and emits PURLs, licenses, and supplier metadata — the dependency inventory CRA Annex II expects.

Read More

Plugin Scanner

Map your plugin's attack surface the way an auditor would: REST routes, AJAX handlers, capability checks, custom tables, outbound HTTP, and risk flags, written up as HTML and JSON for your CRA technical file.

Read More

Vulnerability Disclosure Policy

Draft and publish a vulnerability disclosure policy along ISO/IEC 29147 lines, with the [mmcra_vdp] shortcode and a rate-limited intake form. Give researchers the discoverable reporting channel CRA Article 13 requires — published from inside WordPress in minutes.

Read More

EU Declaration of Conformity

Produce a signed EU Declaration of Conformity for each plugin you ship, structured to CRA Annex V. MMCRA Toolkit fills in manufacturer identity, applied standards, and conformity route from your settings — export to HTML, print to PDF, sign, and file.

Read More

Vulnerability monitoring & incident reporting

Weekly OSV.dev monitoring of every dependency in your plugins, with email alerts and AI triage — the ongoing vulnerability handling CRA Article 14 expects, running quietly inside your WordPress. A Pro control, tiered by how many plugins you monitor.

Read More