SBOM generator (CycloneDX 1.6) for installed plugins — scans composer.lock, package-lock.json, and plugin headers.
Vulnerability Disclosure Policy editor (ISO/IEC 29147 conventions) — publish as a WordPress page or export as HTML, with the [mmcra_vdp] shortcode and a rate-limited, honeypot-protected submission form.
Disclosure Submissions admin page — browse, triage, and bulk-action reports received via the shortcode.
EU Declaration of Conformity template per CRA Annex V — export to HTML, print to PDF for the signed copy.
Compliance Score — a 0-100 quantified posture with a transparent, click-to-fix deduction breakdown and CRA article references.
Audit log recording the SHA-256 of every artifact at write time.
5-step setup wizard with plain-English CRA explanations.
Single “CRA Toolkit” top-level menu with an in-page sidebar nav.