BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off →
ncdLabs Assure – Security & Compliance Scanner icon
Actively maintained Tested with WP 7.1 #48 in audit

ncdLabs Assure – Security & Compliance Scanner

Continuous technical compliance for WordPress: discover, enforce, monitor, remediate, verify, and report.

Active installs<10New
Downloads · 30d595• 0% vs prev. 30d
Rating—0 reviews
Health score64/100Good
All-time downloads602Since Sep 2026
Support resolved—No recent threads
RequiresWP 6.6PHP 8.1+
Downloads · 7d216▲ +180.5% week over week
Our verdict

Solid choice

ncdLabs Assure is a solid plugin choice in 2026, with a few things worth checking first. Was last updated 22 hours ago, and scores 64/100 on our health check.

  • Actively developed — last update 22 hours ago
  • Tested with the latest WordPress (7.1)
  • Small user base (<10 active installs)
  • Very few reviews so far
  • Needs PHP 8.1 or newer

How does it stack up?

Side-by-side on installs, updates, ratings & support

Daily downloads

255075Sep 15Sep 26Oct 8
Yesterday25
Daily average (1y)25
Peak day101Oct 3, 2026
Last 12 months595

Download spikes usually follow a new release — each site that auto-updates counts as a download.

Rankings

Where ncdLabs Assure stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
audit >100 2,777 Best audit plugins →
compliance >100 5,847 Best compliance plugins →
consent >100 3,399 Best consent plugins →
GDPR >100 3,756 Best GDPR plugins →
privacy >100 10,000 Best privacy plugins →

About ncdLabs Assure

From the official readme · v0.1.20

Description

ncdLabs Assure helps WordPress site owners and operators run technical GDPR readiness work inside wp-admin: site discovery, control evaluation, consent management, script enforcement, evidence collection, remediation helpers, and audit reporting.

ncdLabs Assure verifies controls it can observe on your site, records evidence, and flags items that need manual review. It does not replace legal counsel and does not certify legal compliance.

Free frameworks (included)

  • Built-in GDPR control catalog (59 technical controls across consent, analytics, forms, embeds, and WordPress configuration)
  • Built-in OWASP Top 10 control catalog (38 WordPress-focused security controls mapped to OWASP Top 10 2025 categories)
  • Built-in NIST CSF 2.0 control catalog (17 WordPress-focused cybersecurity readiness controls)
  • Site discovery for plugins, scripts, iframes, forms, and third-party services
  • Native consent banner and preference center (defers to an active third-party CMP when one is detected)
  • Google Consent Mode v2 defaults, optional GA/GTM deferral, and script blocking before consent
  • YouTube embed gating until External Media consent is granted
  • Scheduled monitoring and configuration drift detection
  • Audit runs with scored results, findings, history, and exportable reports
  • Evidence log with JSON, CSV, and PDF export
  • Technical readiness reports with audience packs (Executive, Security, Compliance auditor, Vendor, Customer), integrity hash, and JSON/CSV/PDF export
  • In-app Documentation, Request a feature, and Report a bug (optional email via this site’s WordPress mail)
  • One-click remediation helpers for supported controls
  • Optional one-click hosted browser verification connect (email confirm; credentials save automatically)

Optional compliance packs (sold separately, not included in this plugin)

HIPAA, SOC 2, CCPA, WCAG, and other framework catalogs are not bundled in the WordPress.org plugin. Purchase a yearly subscription through Stripe Checkout at ncdLabs Assure, download the encrypted .assure-pack file from your order confirmation, then import it from Manage → Settings → Controls → Install framework pack with your unlock key. Packs are not required for GDPR, OWASP, or NIST CSF functionality.

Who this is for

  • WordPress admins responsible for privacy-related technical controls
  • Agencies operating client sites who need repeatable evidence and audit history
  • Teams preparing for GDPR-related technical reviews (not a substitute for legal advice)

External services

ncdLabs Assure connects to external services only in the cases below. Hostnames such as js.stripe.com, connect.facebook.net, googletagmanager.com, and youtube.com that appear in plugin source are local detection / verification signature strings used to recognize scripts already present on your site. The plugin does not load those third-party scripts, call those vendors’ APIs, or send visitor data to them.

Pack activation (ncdlabs.com) — When you import a purchased compliance pack, ncdLabs Assure sends your pack unlock key, framework identifier, and this site’s URL to the ncdLabs activation API to verify the Stripe purchase and bind the license to one site:

Browser verification (ncdlabs.com, optional) — Hosted browser verification is optional. Free sites can connect with one click from the setup wizard or Manage → Settings → Remote browser: the plugin starts an exchange, you confirm the administrator email, and sealed site credentials are delivered locally. Purchased compliance packs may still call the provisioning API after import. When connected, audits and discovery may send scan targets to the hosted browser verification service:

  • Connect bootstrap: https://ncdlabs.com/products/assure/api/browser-verification/request/bootstrap
  • Connect status: https://ncdlabs.com/products/assure/api/browser-verification/request/status
  • Email confirmation: …/request/confirm-email/… (auto-approves; credentials delivered on status poll)
  • Pack provision (alternate): https://ncdlabs.com/products/assure/api/browser-verification/provision
  • Default service: https://browser-verify.ncdlabs.com
  • Data sent (connect): site URL, administrator email, client commitment / client secret proof, optional return URL; later scan target URL and verification token when hosted scans run
  • Data sent (pack provision): pack unlock key, site URL
  • When: when an administrator starts Connect hosted browser; optionally after pack import provisioning; during audits/discovery when hosted browser verification is enabled under Manage → Settings → Remote browser
  • Security: verification endpoints must use HTTPS. Self-hosted endpoint domains must be explicitly allowed with the assure_browser_verification_allowed_hosts filter.
  • Terms of use: https://ncdlabs.com/products/assure/terms/
  • Privacy policy: https://ncdlabs.com/privacy/; product: https://ncdlabs.com/products/assure/privacy/

Google Analytics / Google Tag Manager OAuth (Google + ncdlabs.com, optional) — When an administrator connects Google Analytics or Google Tag Manager from Manage → Settings → Integrations, ncdLabs Assure may use Google OAuth plus the Google Analytics Admin API and/or Google Tag Manager API. If you have not configured your own Google OAuth client credentials, ncdLabs Assure uses an ncdLabs OAuth proxy:

Third-party script detection signatures (no outbound calls) — During discovery, audits, and optional browser verification, ncdLabs Assure matches HTML, network requests, and installed plugins against known vendor hostname patterns (examples: Google Analytics/Tag Manager, Meta Pixel / connect.facebook.net, LinkedIn Insight, Hotjar, Microsoft Clarity, YouTube, Vimeo, HubSpot, Mailchimp, Brevo, Stripe / js.stripe.com). Examples also include CDN hostnames such as gstatic.com, cloudflare.com, unpkg.com, and cdnjs.cloudflare.com that appear only as local classification signatures in discovery code. Matching is local string comparison against content already on your site or observed in a verification scan of your site. ncdLabs Assure does not call these vendors, load their scripts, or transmit data to them.

Site self-scan (your own WordPress site) — During discovery and audits, ncdLabs Assure may request your site’s public homepage and REST API to detect scripts, embeds, forms, and integrations. These requests stay on your site; ncdLabs Assure does not send discovery results to ncdLabs.

Optional deactivation feedback (wp_mail) — When an administrator deactivates the plugin, an optional survey may appear. Feedback is never required: Skip & deactivate, Close, Escape, or Cancel leave without sending anything. If the administrator submits feedback, the selected reason and optional comments are emailed to ncdLabs (feedback+assure@ncdlabs.com) using this site’s WordPress mail. A separate checkbox (unchecked by default) can include plugin, WordPress, and PHP versions only — never the site URL or admin email. Mail/API failure still proceeds to deactivate.

Optional product feedback (wp_mail) — From the admin right-rail, administrators may open Documentation, Request a feature, or Report a bug. Documentation stays local. Feature requests and bug reports are emailed to ncdLabs (feedback+assure@ncdlabs.com) using this site’s WordPress mail only when an administrator submits the form. Bug reports may include the current admin page URL/title, optional contact details the administrator enters, optional console lines buffered in that session, optional diagnostics (plugin/WordPress/PHP versions), and an optional annotated screenshot the administrator chooses to attach. Nothing is sent unless the form is submitted.

No usage telemetry or analytics are sent to ncdLabs by the plugin.

Source code for built assets

Admin, front-end, and plugins.php deactivation-feedback JavaScript and CSS are built with @wordpress/scripts (package.json and webpack.config.js). Human-readable sources ship in the plugin under assets/src/. Production builds ship in build/.

Third-party libraries

Composer production dependencies are MIT-licensed and GPL-compatible:

  • chrome-php/chrome, chrome-php/wrench
  • evenement/evenement
  • monolog/monolog
  • psr/log
  • symfony/filesystem, symfony/process, symfony/polyfill-ctype, symfony/polyfill-mbstring, symfony/polyfill-php80

See each package’s LICENSE file under vendor/ for copyright notices.

npm production dependency (bundled into admin build assets; MIT-licensed and GPL-compatible):

  • html2canvas (optional annotated screenshots for in-app bug reports)

Installation

  1. Upload the plugin folder to /wp-content/plugins/ncdlabs-assure/ or install through the WordPress Plugins screen.
  2. Activate ncdLabs Assure through the Plugins menu.
  3. Open ncdLabs Assure in the admin sidebar.
  4. Run Assure → Audits → Run audit to generate your first GDPR technical readiness snapshot.
  5. Configure Manage → Settings (General, Controls, Integrations, Consent, Remote browser) as needed for your stack.

Development build

If you clone the repository, run npm install && npm run build before activating so build/ assets exist.

Frequently asked questions

Do I need a paid pack to use ncdLabs Assure?

No. The free plugin includes complete GDPR, OWASP Top 10, and NIST CSF 2.0 technical control catalogs, consent manager, enforcement tools, audits, evidence, and reporting. Paid yearly packs add optional frameworks such as HIPAA, SOC 2, CCPA, and WCAG.

Does ncdLabs Assure make my site legally compliant?

No. ncdLabs Assure documents technical observations and helps you operate controls on your WordPress site. Legal compliance depends on your organization, data processing, policies, and jurisdiction. Consult qualified counsel.

How do compliance packs work?

Purchase a pack at ncdlabs.com via Stripe Checkout, download the encrypted .assure-pack from your order confirmation, then use Manage → Settings → Controls → Install framework pack and enter your unlock key. Activation binds the pack to the current site URL. Paid pack files are never included in the free WordPress.org download.

How do I enable hosted browser verification?

Use Connect hosted browser in the first-run setup wizard or under Manage → Settings → Remote browser. Confirm the administrator email, wait for ncdLabs site approval, and credentials are sealed into the plugin. Without hosted browser verification, some visitor-facing controls remain Needs review.

Does ncdLabs Assure work with Complianz or other CMPs?

Yes. When a supported third-party consent plugin is active, ncdLabs Assure defers to it and disables the native consent banner to avoid conflicts.

What data does ncdLabs Assure store?

Audit results, evidence, activity log entries, and settings are stored in your WordPress database. Installed framework pack catalogs are stored under wp-content/assure/frameworks/ (outside uploads when that directory is writable; otherwise uploads). Consent preferences are stored in the visitor’s browser (localStorage) when using the native banner.

Does ncdLabs Assure contact external servers?

Only in the cases documented under External services (pack activation, optional browser verification, optional Google OAuth, and optional deactivation or in-app product feedback if an administrator submits a form). Feedback is never required to use or deactivate the plugin.

What happens when I uninstall ncdLabs Assure?

Uninstalling deletes ncdLabs Assure database tables, plugin settings, scheduled monitoring events, and uploaded framework pack files under wp-content/uploads/assure/. This cannot be undone.

Changelog

Readiness over time chart date labels are vertical and readable.

0.1.20

  • Fix: Setup wizard no longer crashes when hosted browser verification is disabled.

0.1.19

  • Enhancement: Privacy settings reopen button now uses a cookie icon instead of text.

0.1.18

  • Fix: Readiness over time chart shows date labels vertically so they no longer overlap.

0.1.17

  • Fix: Remote browser Settings Status shows readiness and last audit scan (no longer looks Unavailable from skipped integrations discovery).
  • Enhancement: Audit results list marks controls verified with the hosted remote browser.

0.1.16

  • Enhancement: audit progress modal with Hide and Notify Me When Done (toast + notification bell).
  • Fix: Results defaults to Failed + Warning so action-required warnings are visible.
  • Fix: automatic checks that were false UNKNOWN now return WARNING (consent mechanism/blocking, monitoring, registration, admin limits, privacy tools, Consent Mode signals).

0.1.15

  • Enhancement: Apply Fix can enable baseline security headers (HSTS on HTTPS, X-Frame-Options, Referrer-Policy, X-Content-Type-Options).
  • Fix: Apply Recommended Controls skips remediations that would not change site state (no-op Apply Fix).

Full changelog on WordPress.org →

Screenshots

ncdLabs Assure dashboard with readiness score and control summary
ncdLabs Assure dashboard with readiness score and control summary
Controls list with GDPR, OWASP Top 10, and pack management
Controls list with GDPR, OWASP Top 10, and pack management
Consent banner configuration and preview
Consent banner configuration and preview
Findings view with remediation actions
Findings view with remediation actions

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.

Active installs badge Rating badge Health score badge

Best ncdLabs Assure alternatives

All audit plugins →
Alternatives
Rank Plugin Active installs Rating Updated Health
1 Audit Trail Audit Trail Audit Trail is a plugin to keep track of what is going on inside your blog by monitoring… by John Godley 20K+ ★★★★★★★★★★ 2.8 (4) 9 years ago 30
2 MYAIO – Your AI-Powered Co-Founder MYAIO – Your AI-Powered Co-Founder AI-powered WordPress SEO plugin with real-time audits, smart recommendations, and… by gabrielwillkinson1 400+ ★★★★★★★★★★ No reviews 2 months ago 61
3 Sa11y, the accessibility quality assurance assistant | Accessibility Checker Sa11y, the accessibility quality assurance assistant Geared towards content authors, Sa11y straightforwardly identifies accessibility issues at… by Adam Chaboryk 300+ ★★★★★★★★★★ 5 (1) 2 months ago 67
4 CMS ADMINS Security Check Report CMS ADMINS Security Check Report Read-only security audit for WordPress: 61 checks, an A to F grade, and a checklist that… by Patrick Schlesinger 100+ ★★★★★★★★★★ No reviews 2 weeks ago 68
5 Destino Access Audit Destino Access Audit Audit who has access to your site: Application Passwords, admin accounts, and connected… by destinoexterior 100+ ★★★★★★★★★★ No reviews 2 weeks ago 68
6 Pluginventory Pluginventory Know exactly which plugins run across your WordPress portfolio — search any plugin… by pluginventoryteam 100+ ★★★★★★★★★★ No reviews 4 months ago 46
7 Aipatch Security Scanner Aipatch Security Scanner WordPress security scanner with 36 checks, malware scanning, core integrity verification… by Esteban 100+ ★★★★★★★★★★ No reviews 5 months ago 53
8 BCC All Emails BCC All Emails A quick plugin to create an audit trail of emails sent from your site to another email… by wphelpdeskuk 100+ ★★★★★★★★★★ No reviews 3 years ago 25
9 Content Audit Content Audit Lets you create a content inventory right in the WordPress Edit screens. You can mark… by Stephanie Leary 70+ ★★★★★★★★★★ 4.5 (8) 7 years ago 35
10 Post Author IP Post Author IP Records the IP address of the original post author when a post first gets created. by Scott Reilly 60+ ★★★★★★★★★★ No reviews 5 years ago 25

FAQ

ncdLabs Assure: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org · checked Oct 9, 2026

Is ncdLabs Assure free?

Yes. ncdLabs Assure is free to download and use from the official WordPress.org plugin directory.

Is ncdLabs Assure safe to use in 2026?

ncdLabs Assure is a solid plugin choice in 2026, with a few things worth checking first. Was last updated 22 hours ago, and scores 64/100 on our health check.

How many websites use ncdLabs Assure?

ncdLabs Assure is active on <10 WordPress websites and has been downloaded 602 times since it launched in September 2026. It was downloaded 595 times in the last 30 days.

Does ncdLabs Assure work with WordPress 7.1?

Yes. The developer has tested ncdLabs Assure up to WordPress 7.1.3, the latest release. It requires WordPress 6.6 or newer.

What PHP version does ncdLabs Assure need?

ncdLabs Assure requires PHP 8.1 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was ncdLabs Assure last updated?

The latest version, 0.1.20, was released on October 8, 2026 (22 hours ago).

Who makes ncdLabs Assure?

ncdLabs Assure is developed and maintained by ncdLabs.

What are the best alternatives to ncdLabs Assure?

The most popular alternatives to ncdLabs Assure are Audit Trail (20K+ installs), MYAIO (400+ installs) and Sa11y, the accessibility qu… (300+ installs).

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org — no credit card
Sarah is here to help!
Hi there! 👋 Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! 👋 Need help finding what you're looking for?

We'll use this to continue our conversation

Just now ✓ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.