Skip to main content
WP HealthKit
The EU Cyber Resilience Act bites 11 September 2026

You sell WordPress products in the EU. The CRA now wants your paperwork.

Security audit trail. Software Bill of Materials. Vulnerability disclosure process. Missing any of them and you're selling non-compliant software — fines up to €15M or 2.5% of global turnover. One bundle produces all of it for your plugin. 48 hours. £99.

counting down…

One product, one version, one price. Not legal advice — the artifacts, done properly.

14-day money-back No subscription Signed + verifiable receipt
cra-pack · your-plugin.zipgenerated per audit
62-layer security audit58 scanners + 4 AI engines
Fix Plan — findings, with diffsmarkdown + JSON
SBOM — CycloneDX 1.6every dependency, version + license
OpenVEX exploitability statementsper-CVE, with corroboration
Signed provenance receipted25519 · publicly verifiable
SECURITY.md + VDP templatesdrop-in, your slug filled
your-plugin-cra-pack.zip6 artifacts

This isn't a guideline. It's market access.

Three ways September goes badly for non-compliant products — and they're all mechanical, not judgement calls.

€15M / 2.5%

Administrative fines

Maximum penalty for supplying a non-compliant product with digital elements — whichever of €15M or 2.5% of total worldwide annual turnover is higher.

CRA · Art. 64
Delisted

Marketplace enforcement

Envato, CodeCanyon and ThemeForest will ask for compliance documentation from sellers — they always do, eventually, and they delist first and negotiate later.

Market access
Blocked

Enterprise procurement

EU enterprise and public-sector buyers already ask for SBOMs in RFPs. From September, "we don't have one" ends the conversation before it starts.

Sales pipeline

Three ways to get the same paperwork.

Compliance consultant
£2,000–5,000 / product

Manual audit, hand-written SBOM, 3–6 week lead time. Re-billed every major release. Right answer, wrong price for most sellers.

DIY
2–3 weeks / your time

Read the regulation, hand-roll CycloneDX tooling, write your own VEX statements, hope you interpreted Annex I right. Possible. Miserable. Easy to get wrong.

The bundle
£99 / product

Upload a ZIP, get the pack. Audit, SBOM, OpenVEX, receipt, templates — generated from the actual code, signed where it matters.

See exactly what £99 produces.

Real output formats, real signatures. This is what lands in your download folder — click through the artifacts. (Demo plugin shown.)

Full security audit + Fix Plan
# formforge 5.2.0 — audit summary
grade B+ · 3 findings · 62 layers · 4m 12s

[HIGH] REST route /wp-json/formforge/v1/entries
  permission_callback => '__return_true' — unauthenticated read
  fix: gate behind current_user_can('edit_posts') + nonce

[MED] Unescaped $atts['title'] in shortcode render
  fix: esc_attr($atts['title']) before interpolation

[LOW] Option 'formforge_secret' never deleted on uninstall
  fix: add delete_option() to uninstall.php

fix-plan.md · 3 items with diffs · agent-ready

Nothing hand-waved.

What the Act demands → what the pack contains.

Security by design and by defaultAnnex I, Part I §162-layer audit + Fix Plan — findings with evidence and the diff to close them
Identify and document components (SBOM)Annex I, Part I §2SBOM (CycloneDX 1.6) — every dependency, version and license, machine-readable
Handle and remediate vulnerabilitiesAnnex I, Part I §3OpenVEX — per-CVE exploitability statements with corroboration
Vulnerability disclosure processAnnex I, Part I §4SECURITY.md + VDP with response SLAs + RFC 9116 security.txt
Technical documentation available to authoritiesAnnex I, Part I §5Signed provenance receipt — verifiable audit attestation for your exact ZIP

Everything in the £99 bundle

Five artifacts, generated from one audit run. This is the paperwork the CRA expects to exist — produced properly, not templated.

Artifact 01

Full security audit + Fix Plan

The same 62-layer pipeline we run for agencies: 58 deterministic scanners, 4 AI engines, and a structured remediation plan your developer (or AI agent) can apply line by line.

Artifact 02

SBOM — CycloneDX 1.6

A machine-readable Software Bill of Materials from your composer.lock and package-lock.json — the artifact the CRA explicitly requires you to produce and maintain.

Artifact 03

OpenVEX document

Per-CVE exploitability statements with corroboration evidence — the companion document procurement teams and enterprise buyers ask for alongside the SBOM.

Artifact 04

Signed provenance receipt

An ed25519-signed attestation that your exact ZIP passed audit — publicly verifiable by anyone, no WP HealthKit account needed.

Artifact 05

SECURITY.md + VDP + security.txt

A drop-in SECURITY.md, a Vulnerability Disclosure Policy with response SLAs, and an RFC 9116 security.txt — the process paperwork the CRA expects to exist.

Who this is for

Marketplace sellers

Envato, CodeCanyon, and ThemeForest authors selling into the EU. Marketplaces will ask for this documentation — they always do, eventually.

Premium plugin & extension shops

WooCommerce extensions, premium plugins, SaaS-connected plugins. If EU customers pay you, the CRA applies to your product.

Agencies building client products

You ship plugins or stores for EU clients. Hand them the audit, SBOM, and receipt as part of delivery — instant professionalism.

48 hours, start to pack

STEP 1

Checkout

£99 one-off. No subscription, no card-on-file tricks.

STEP 2

Upload your ZIP

The audit runs in minutes. Everything in the bundle generates automatically from the result.

STEP 3

Download the pack

Report, SBOM, OpenVEX, signed receipt, and templates — ready for your marketplace, buyers, and records.

The honest part: the CRA isn't one-and-done

The bundle makes you compliant today. The law expects you to stay that way as vulnerabilities are discovered — which is exactly what Living Audits does: your plugin's claims are re-verified continuously, and you get a signed challenge with evidence when a fact breaks (a PHP version EOLs, a CVE lands in a bundled library). Bundle buyers get 50% off Platform or Enterprise for their first 3 months — the code is on your confirmation page.

Questions sellers actually ask

Is this legal advice?

No. We produce the technical artifacts the CRA requires — the audit, SBOM, vulnerability documentation, and disclosure-process templates. Whether your specific product is in scope is a question for your lawyer. Our job is to make sure that if it is, the paperwork exists.

I only sell outside the EU — does this matter?

If any of your customers are in the EU, it applies to you regardless of where you're based. If you genuinely sell nowhere near the EU, you're out of scope — but most marketplaces will standardise on this documentation anyway, the way they did with GPL.

Is one bundle enough forever?

No — and we won't pretend otherwise. The CRA is a continuing obligation: vulnerabilities must be handled as they're discovered. The bundle gets you compliant today; monitoring keeps you there. Bundle buyers get 50% off Platform or Enterprise for 3 months, shown after checkout.

What exactly counts as my 'product'?

Each plugin or theme you sell. One bundle covers one product (one ZIP, one version). Re-run it per major release — most sellers bundle it into their release checklist.

The deadline doesn't move. The paperwork takes two days.

£99, one product, everything the CRA expects to exist. Do it this week and it's done.