BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off β†’
MMCRA Toolkit icon
Maintained Tested up to 7.0.7 #71 in compliance

MMCRA Toolkit

EU CRA compliance for WordPress plugins. Generate the SBOM, VDP, and Declaration of Conformity the EU Cyber Resilience Act requires.

Active installs<10New
Downloads Β· 30d55β–² +31% vs prev. 30d
Ratingβ€”0 reviews
Health score49/100Fair
All-time downloads235Since Jul 2026
Support resolvedβ€”No recent threads
RequiresWP 6.2PHP 7.4+
Downloads Β· 7d9β–Ό -35.7% week over week
Our verdict

Use with caution

MMCRA Toolkit works, but test it on a staging site before relying on it in 2026. Was last updated 3 months ago, and scores 49/100 on our health check.

  • Small user base (<10 active installs)
  • Very few reviews so far

How does it stack up?

Side-by-side on installs, updates, ratings & support

Daily downloads

134Jul 12Aug 25Oct 9
Yesterday2
Daily average (1y)3
Peak day54Jul 5, 2026
Last 12 months243

Download spikes usually follow a new release β€” each site that auto-updates counts as a download.

Rankings

Where MMCRA Toolkit stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
compliance >100 5,852 Best compliance plugins β†’
cra #8 17 Best cra plugins β†’
CycloneDX #4 9 Best CycloneDX plugins β†’
sbom #6 14 Best sbom plugins β†’
vulnerability-disclosure >100 1,106 Best vulnerability-disclosure plugins β†’

About MMCRA Toolkit

From the official readme Β· v1.0.0

Description

Selling a commercial WordPress plugin in the EU? Starting September 11, 2026 you need a Software Bill of Materials, a Vulnerability Disclosure Policy, and an EU Declaration of Conformity in your plugin’s technical file. MMCRA Toolkit generates all three from your plugin’s headers and dependency files, in an afternoon, with no servers or accounts.

Links

What this plugin generates

  • Software Bill of Materials β€” valid CycloneDX 1.6 JSON. Scans composer.lock, package-lock.json, and plugin headers. One click per plugin.
  • Vulnerability Disclosure Policy β€” drafted to ISO/IEC 29147 conventions. Publish as a WordPress page on your marketing site, or export as standalone HTML.
  • EU Declaration of Conformity β€” per-product template structured to CRA Annex V (manufacturer identity, conformity assessment route, applied standards). Export to HTML; print to PDF for the signed copy.
  • Audit log β€” every artifact written, with the SHA-256 of its content at write time. Tamper-evident evidence that you produced the file on a given date.

Who this is for

Independent WordPress plugin developers and small teams who sell commercial plugins to EU customers and need to ship the technical-file artifacts the CRA mandates. The free version covers every plugin you have installed, with no limit. Ongoing OSV.dev vulnerability monitoring, incident tracking, and PDF audit reports are in MMCRA Toolkit Pro.

5-step setup wizard

The wizard walks you through company identity, vulnerability disclosure policy, SBOM generation, and monitoring activation. It also explains the underlying CRA articles in plain English so you understand what each artifact is for, not just how to click the buttons.

What this is NOT

  • Not legal advice. Consult qualified counsel for CRA interpretation.
  • Not a guarantee of regulatory approval. Compliance is your responsibility.
  • Not a substitute for secure development practices.
  • Not a replacement for an EU authorised representative if your business needs one (CRA Article 17).

Pro features

MMCRA Toolkit Pro adds: weekly OSV.dev vulnerability monitoring with email alerts (tiered by how many plugins you monitor), incident tracking, AI-assisted advisory triage and remediation drafting (Claude), PDF audit reports, the Compliance Bundle export (single zip per plugin combining SBOM + VDP + DoC + audit log), Plugin Scanner static analysis, SBOM-from-zip uploads for third-party code, and audit log CSV export.

Translations

MMCRA Toolkit is translation-ready. The included .pot file in languages/ covers every translatable string. Priority locales for the EU market β€” German, French, Italian, Spanish, Dutch β€” are open for community translation via translate.wordpress.org.

Shortcodes

[mmcra_vdp]

Embed the Vulnerability Disclosure Policy and an optional report form on any WordPress page or post. Useful for putting the disclosure form at /security/ or wherever your security contact page lives.

Attributes:

  • show="all" (default) β€” render both the policy and the report form
  • show="policy" β€” policy only
  • show="form" β€” submission form only
  • pgp="yes" β€” include the PGP key block (default: off)
  • style="default" (default) | style="minimal" β€” minimal drops the styled wrapper for tighter theme integration

Examples:

[mmcra_vdp]

[mmcra_vdp show="form"]

[mmcra_vdp show="policy" pgp="yes"]

Submissions are saved to the mmcra_vdp_submissions option (capped at 100 entries, FIFO) and emailed to the contact address configured under CRA Toolkit β†’ Vulnerability Disclosure. Rate-limited to one submission per IP per minute. Includes a honeypot field for bot protection.

Installation

  1. Upload via Plugins β†’ Add New β†’ Upload Plugin, or extract to wp-content/plugins/mmcra-toolkit/.
  2. Activate the plugin.
  3. Open CRA Toolkit β†’ Setup Wizard and follow the 5 steps.
  4. Generate SBOMs, publish your VDP, and sign your Declaration of Conformity as you ship releases.

Frequently asked questions

What does the CRA require of WordPress plugin developers?

The EU Cyber Resilience Act (Regulation 2024/2847) applies to any commercial digital product placed on the EU market. For a plugin developer that means you need to identify your manufacturer entity, produce a Software Bill of Materials, publish a coordinated vulnerability disclosure policy, and ship a signed Declaration of Conformity per product. From September 11, 2026, you also have to report actively exploited vulnerabilities to ENISA within 24 hours.

Do I need this if I only sell to UK or US customers?

The CRA applies to any product placed on the EU market. If you sell to EU customers β€” directly or through a marketplace β€” you’re in scope. If you only sell to non-EU customers, the CRA does not apply, but the technical artifacts the toolkit produces are still useful as evidence of secure development practice.

How is the free version different from Pro?

The free version generates SBOMs, Disclosure Policies, and Declarations of Conformity for every plugin you have installed β€” no plugin limit. Pro adds ongoing weekly OSV.dev vulnerability monitoring (tiered by how many plugins you monitor), incident tracking, AI-assisted triage and drafting, PDF audit reports, and the single-zip Compliance Bundle export for regulator handoff.

Is the SBOM compatible with regulator tooling?

Yes. The toolkit outputs CycloneDX 1.6 JSON, which is one of the two SBOM formats explicitly named in the CRA’s harmonised standards. The same format works with OWASP Dependency-Track, GitHub Advanced Security, and most enterprise procurement portals.

Where does the audit log live?

In a custom table in your WordPress database (wp_mmcra_audit_log). Every artifact written by the toolkit is recorded with timestamp, user, plugin slug, path, and the SHA-256 of the content at write time. This gives you tamper-evident evidence that you produced the file on the date it claims.

Does this plugin send any data to external services?

No. The free plugin operates entirely on your WordPress install. No telemetry, no phone-home, no third-party API calls. Pro optionally talks to OSV.dev (Google’s open-source vulnerability database) for weekly monitoring and to Anthropic’s Claude API for AI-assisted triage, both opt-in.

Why a wizard instead of just a settings page?

Because the CRA is unfamiliar territory for most plugin developers. The wizard explains what each step is, why the CRA requires it, and what happens if you skip it. You can re-run it any time from CRA Toolkit β†’ Setup Wizard.

Changelog

Initial release.

1.0.0

Initial public release.

  • SBOM generator (CycloneDX 1.6) for installed plugins β€” scans composer.lock, package-lock.json, and plugin headers.
  • Vulnerability Disclosure Policy editor (ISO/IEC 29147 conventions) β€” publish as a WordPress page or export as HTML, with the [mmcra_vdp] shortcode and a rate-limited, honeypot-protected submission form.
  • Disclosure Submissions admin page β€” browse, triage, and bulk-action reports received via the shortcode.
  • EU Declaration of Conformity template per CRA Annex V β€” export to HTML, print to PDF for the signed copy.
  • Compliance Score β€” a 0-100 quantified posture with a transparent, click-to-fix deduction breakdown and CRA article references.
  • Audit log recording the SHA-256 of every artifact at write time.
  • 5-step setup wizard with plain-English CRA explanations.
  • Single “CRA Toolkit” top-level menu with an in-page sidebar nav.
  • Translation-ready (.pot template included).

Full changelog on WordPress.org β†’

Screenshots

Dashboard β€” CRA deadline countdown, KPI tiles (plugins covered, SBOM coverage, open advisories, monitor status), and readiness checklist.
Dashboard β€” CRA deadline countdown, KPI tiles (plugins covered, SBOM coverage, open…
Setup Wizard β€” five-step flow walking through company identity, VDP, SBOM generation, and monitoring activation.
Setup Wizard β€” five-step flow walking through company identity, VDP, SBOM generation, and…
SBOM Generator β€” pick a plugin, generate a valid CycloneDX 1.6 file, view recent SBOMs with download links.
SBOM Generator β€” pick a plugin, generate a valid CycloneDX 1.6 file, view recent SBOMs…
Vulnerability Disclosure Policy editor β€” contact channels, in-scope and out-of-scope guidance, optional PGP key, with publish-as-page and export-as-HTML actions.
Vulnerability Disclosure Policy editor β€” contact channels, in-scope and out-of-scope…
Declaration of Conformity editor β€” per-product CRA Annex V form covering manufacturer identity, risk class, conformity assessment route, applied standards, and signature block.
Declaration of Conformity editor β€” per-product CRA Annex V form covering manufacturer…
Audit log β€” every artifact written, with timestamp, user, plugin slug, path, and SHA-256 hash.
Audit log β€” every artifact written, with timestamp, user, plugin slug, path, and SHA-256…
Company Settings β€” manufacturer identity and optional EU authorised representative section per CRA Article 17.
Company Settings β€” manufacturer identity and optional EU authorised representative…

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own β€” no account needed.

Active installs badge Rating badge Health score badge

Best MMCRA Toolkit alternatives

All compliance plugins β†’
Alternatives
Rank Plugin Active installs Rating Updated Health
1 Cookie Compliance for WordPress – Cookie Consent, GDPR & CCPA Cookie Compliance for WordPress Consent management for WordPress β€” GDPR, CCPA & ePrivacy, autoblocking, Google Consent… by Humanityco 800K+ β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜… 4.8 (3K) 16 hours ago 77
2 WP Consent API WP Consent API Simple Consent API to read and register the current consent category. by Rogier Lankhorst 200K+ β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜… 5 (2) 4 weeks ago 86
3 Cookiez – GDPR & CCPA Cookie Banner & Consent Manager Cookiez – GDPR & CCPA Cookie Banner & Consent Manager Simplify cookie consent with a customizable banner that helps you cover global privacy laws… by Elementor 40K+ β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜… 4.3 (4) 1 week ago 63
4 One Stop Shop for WooCommerce One Stop Shop for WooCommerce The One Stop Shop compliance helper allows you to easily monitor your One Stop Shop… by vendidero 10K+ β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜… 5 (5) 3 weeks ago 85
5 LegalBlink for Aruba LegalBlink for Aruba LegalBlink for Aruba is a plugin that allows you to integrate the LegalBlink services from… by LegalBlink 10K+ β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜… No reviews 4 months ago 51
6 The GDPR Framework By Data443 The GDPR Framework By Data443 Easy to use tools to help make your website GDPR-compliant. Fully documented, extendable… by Data443 Risk Mitigation, Inc. 10K+ β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜… 4.8 (65) 2 months ago 77
7 GDPR GDPR This plugin is meant to assist with the GDPR obligations of a Data processor and Controller. by Trew Knowledge 10K+ β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜… 4.3 (58) 3 months ago 78
8 Cookie-Script.com Cookie-Script.com Cookie-Script.com WordPress plugin. by csarturas 10K+ β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜… 3.1 (14) 9 months ago 49
9 Free Cookie Notice & Consent Banner for Privacy Compliance (GDPR, CCPA, DSGVO and others) Free Cookie Notice & Consent Banner for Privacy Compliance… Install a Cookie Notice or Consent Banner as Required by Privacy Laws (GDPR & CCPA). by GDPR Info 7K+ β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜… 4 (16) 5 days ago 80
10 EU Order Withdrawal Button for WooCommerce EU Order Withdrawal Button for WooCommerce This plugin helps to comply with the latest EU directive 2023/2673 by embedding a… by vendidero 6K+ β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜… 4.6 (7) 2 days ago 86

FAQ

MMCRA Toolkit: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org Β· checked Oct 10, 2026

Is MMCRA Toolkit free?

Yes. MMCRA Toolkit is free to download and use from the official WordPress.org plugin directory.

Is MMCRA Toolkit safe to use in 2026?

MMCRA Toolkit works, but test it on a staging site before relying on it in 2026. Was last updated 3 months ago, and scores 49/100 on our health check.

How many websites use MMCRA Toolkit?

MMCRA Toolkit is active on <10 WordPress websites and has been downloaded 235 times since it launched in July 2026. It was downloaded 55 times in the last 30 days.

Does MMCRA Toolkit work with WordPress 7.1?

MMCRA Toolkit is officially tested up to WordPress 7.0.7, while the latest release is 7.1.3. It may still work, but try it on a staging site first.

What PHP version does MMCRA Toolkit need?

MMCRA Toolkit requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was MMCRA Toolkit last updated?

The latest version, 1.0.0, was released on July 5, 2026 (3 months ago).

Who makes MMCRA Toolkit?

MMCRA Toolkit is developed and maintained by masseym.

What are the best alternatives to MMCRA Toolkit?

The most popular alternatives to MMCRA Toolkit are Cookie Compliance for WordP… (800K+ installs), WP Consent API (200K+ installs) and Cookiez (40K+ installs).

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages β€” with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org β€” no credit card
Sarah is here to help!
Hi there! πŸ‘‹ Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! πŸ‘‹ Need help finding what you're looking for?

We'll use this to continue our conversation

Just now βœ“ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.