Title: ncdLabs Assure &#8211; Security &amp; Compliance Scanner
Author: ncdLabs
Published: <strong>15 septembre 2026</strong>
Last modified: 3 octobre 2026

---

Recherche d’extensions

![](https://ps.w.org/ncdlabs-assure/assets/banner-772x250.png?rev=3696057)

![](https://ps.w.org/ncdlabs-assure/assets/icon-256x256.png?rev=3696057)

# ncdLabs Assure – Security & Compliance Scanner

 Par [ncdLabs](https://profiles.wordpress.org/ncdlou/)

[Télécharger](https://downloads.wordpress.org/plugin/ncdlabs-assure.0.1.18.zip)

[Prévisualisation en direct](https://fr.wordpress.org/plugins/ncdlabs-assure/?preview=1)

 * [Détails](https://fr.wordpress.org/plugins/ncdlabs-assure/#description)
 * [Avis](https://fr.wordpress.org/plugins/ncdlabs-assure/#reviews)
 *  [Installation](https://fr.wordpress.org/plugins/ncdlabs-assure/#installation)
 * [Développement](https://fr.wordpress.org/plugins/ncdlabs-assure/#developers)

 [Support](https://wordpress.org/support/plugin/ncdlabs-assure/)

## Description

ncdLabs Assure helps WordPress site owners and operators run **technical** GDPR 
readiness work inside wp-admin: site discovery, control evaluation, consent management,
script enforcement, evidence collection, remediation helpers, and audit reporting.

ncdLabs Assure verifies controls it can observe on your site, records evidence, 
and flags items that need manual review. **It does not replace legal counsel and
does not certify legal compliance.**

#### Free frameworks (included)

 * Built-in GDPR control catalog (59 technical controls across consent, analytics,
   forms, embeds, and WordPress configuration)
 * Built-in OWASP Top 10 control catalog (38 WordPress-focused security controls
   mapped to OWASP Top 10 2025 categories)
 * Built-in NIST CSF 2.0 control catalog (17 WordPress-focused cybersecurity readiness
   controls)
 * Site discovery for plugins, scripts, iframes, forms, and third-party services
 * Native consent banner and preference center (defers to an active third-party 
   CMP when one is detected)
 * Google Consent Mode v2 defaults, optional GA/GTM deferral, and script blocking
   before consent
 * YouTube embed gating until External Media consent is granted
 * Scheduled monitoring and configuration drift detection
 * Audit runs with scored results, findings, history, and exportable reports
 * Evidence log with JSON, CSV, and PDF export
 * Technical readiness reports with audience packs (Executive, Security, Compliance
   auditor, Vendor, Customer), integrity hash, and JSON/CSV/PDF export
 * In-app Documentation, Request a feature, and Report a bug (optional email via
   this site’s WordPress mail)
 * One-click remediation helpers for supported controls
 * Optional one-click hosted browser verification connect (email confirm; credentials
   save automatically)

#### Optional compliance packs (sold separately, not included in this plugin)

HIPAA, SOC 2, CCPA, WCAG, and other framework catalogs are **not bundled** in the
WordPress.org plugin. Purchase a yearly subscription through Stripe Checkout at 
[ncdLabs Assure](https://ncdlabs.com/products/assure/store/), download the encrypted`.
assure-pack` file from your order confirmation, then import it from **Manage  Settings
Controls  Install framework pack** with your unlock key. **Packs are not required
for GDPR, OWASP, or NIST CSF functionality.**

#### Who this is for

 * WordPress admins responsible for privacy-related technical controls
 * Agencies operating client sites who need repeatable evidence and audit history
 * Teams preparing for GDPR-related technical reviews (not a substitute for legal
   advice)

#### External services

ncdLabs Assure connects to external services only in the cases below. Hostnames 
such as `js.stripe.com`, `connect.facebook.net`, `googletagmanager.com`, and `youtube.
com` that appear in plugin source are **local detection / verification signature
strings** used to recognize scripts already present on your site. The plugin does**
not** load those third-party scripts, call those vendors’ APIs, or send visitor 
data to them.

**Pack activation (ncdlabs.com)** — When you import a purchased compliance pack,
ncdLabs Assure sends your pack unlock key, framework identifier, and this site’s
URL to the ncdLabs activation API to verify the Stripe purchase and bind the license
to one site:

 * Endpoint: `https://ncdlabs.com/products/assure/api/activate`
 * Data sent: unlock key, framework ID, site URL
 * When: only when you preview or install an encrypted pack you purchased and downloaded
   from Stripe Checkout
 * Terms of use: [https://ncdlabs.com/products/assure/terms/](https://ncdlabs.com/products/assure/terms/)
 * Privacy policy: [https://ncdlabs.com/privacy/](https://ncdlabs.com/privacy/);
   product: [https://ncdlabs.com/products/assure/privacy/](https://ncdlabs.com/products/assure/privacy/)

**Browser verification (ncdlabs.com, optional)** — Hosted browser verification is
optional. Free sites can connect with one click from the setup wizard or **Manage
Settings  Remote browser**: the plugin starts an exchange, you confirm the administrator
email, and sealed site credentials are delivered locally. Purchased compliance packs
may still call the provisioning API after import. When connected, audits and discovery
may send scan targets to the hosted browser verification service:

 * Connect bootstrap: `https://ncdlabs.com/products/assure/api/browser-verification/
   request/bootstrap`
 * Connect status: `https://ncdlabs.com/products/assure/api/browser-verification/
   request/status`
 * Email confirmation: `…/request/confirm-email/…` (auto-approves; credentials delivered
   on status poll)
 * Pack provision (alternate): `https://ncdlabs.com/products/assure/api/browser-
   verification/provision`
 * Default service: `https://browser-verify.ncdlabs.com`
 * Data sent (connect): site URL, administrator email, client commitment / client
   secret proof, optional return URL; later scan target URL and verification token
   when hosted scans run
 * Data sent (pack provision): pack unlock key, site URL
 * When: when an administrator starts Connect hosted browser; optionally after pack
   import provisioning; during audits/discovery when hosted browser verification
   is enabled under **Manage  Settings  Remote browser**
 * Security: verification endpoints must use HTTPS. Self-hosted endpoint domains
   must be explicitly allowed with the `assure_browser_verification_allowed_hosts`
   filter.
 * Terms of use: [https://ncdlabs.com/products/assure/terms/](https://ncdlabs.com/products/assure/terms/)
 * Privacy policy: [https://ncdlabs.com/privacy/](https://ncdlabs.com/privacy/);
   product: [https://ncdlabs.com/products/assure/privacy/](https://ncdlabs.com/products/assure/privacy/)

**Google Analytics / Google Tag Manager OAuth (Google + ncdlabs.com, optional)**—
When an administrator connects Google Analytics or Google Tag Manager from **Manage
Settings  Integrations**, ncdLabs Assure may use Google OAuth plus the Google Analytics
Admin API and/or Google Tag Manager API. If you have not configured your own Google
OAuth client credentials, ncdLabs Assure uses an ncdLabs OAuth proxy:

 * Proxy endpoints: `https://ncdlabs.com/products/assure/api/google/oauth/start`
   and `.../exchange`
 * Google endpoints: `accounts.google.com`, `oauth2.googleapis.com`, `www.googleapis.
   com`, `analyticsadmin.googleapis.com`, `tagmanager.googleapis.com`
 * Data sent: OAuth state, authorization code, and Google Analytics account/property
   or Tag Manager account/container metadata needed to verify configuration
 * When: only when an administrator starts or completes a Google Analytics or Google
   Tag Manager connection
 * Terms of use: [https://ncdlabs.com/products/assure/terms/](https://ncdlabs.com/products/assure/terms/);
   Google: [https://policies.google.com/terms](https://policies.google.com/terms)
 * Privacy policy: [https://ncdlabs.com/privacy/](https://ncdlabs.com/privacy/);
   Google: [https://policies.google.com/privacy](https://policies.google.com/privacy)

**Third-party script detection signatures (no outbound calls)** — During discovery,
audits, and optional browser verification, ncdLabs Assure matches HTML, network 
requests, and installed plugins against known vendor hostname patterns (examples:
Google Analytics/Tag Manager, Meta Pixel / `connect.facebook.net`, LinkedIn Insight,
Hotjar, Microsoft Clarity, YouTube, Vimeo, HubSpot, Mailchimp, Brevo, Stripe / `
js.stripe.com`). Examples also include CDN hostnames such as `gstatic.com`, `cloudflare.
com`, `unpkg.com`, and `cdnjs.cloudflare.com` that appear only as local classification
signatures in discovery code. Matching is local string comparison against content
already on your site or observed in a verification scan of your site. ncdLabs Assure
does not call these vendors, load their scripts, or transmit data to them.

**Site self-scan (your own WordPress site)** — During discovery and audits, ncdLabs
Assure may request your site’s public homepage and REST API to detect scripts, embeds,
forms, and integrations. These requests stay on your site; ncdLabs Assure does not
send discovery results to ncdLabs.

**Optional deactivation feedback (wp_mail)** — When an administrator deactivates
the plugin, an optional survey may appear. Feedback is never required: **Skip & 
deactivate**, Close, Escape, or Cancel leave without sending anything. If the administrator
submits feedback, the selected reason and optional comments are emailed to ncdLabs(`
feedback+assure@ncdlabs.com`) using this site’s WordPress mail. A separate checkbox(
unchecked by default) can include plugin, WordPress, and PHP versions only — never
the site URL or admin email. Mail/API failure still proceeds to deactivate.

**Optional product feedback (wp_mail)** — From the admin right-rail, administrators
may open **Documentation**, **Request a feature**, or **Report a bug**. Documentation
stays local. Feature requests and bug reports are emailed to ncdLabs (`feedback+
assure@ncdlabs.com`) using this site’s WordPress mail only when an administrator
submits the form. Bug reports may include the current admin page URL/title, optional
contact details the administrator enters, optional console lines buffered in that
session, optional diagnostics (plugin/WordPress/PHP versions), and an optional annotated
screenshot the administrator chooses to attach. Nothing is sent unless the form 
is submitted.

 * Terms of use: [https://ncdlabs.com/products/assure/terms/](https://ncdlabs.com/products/assure/terms/)
 * Privacy policy: [https://ncdlabs.com/privacy/](https://ncdlabs.com/privacy/);
   product: [https://ncdlabs.com/products/assure/privacy/](https://ncdlabs.com/products/assure/privacy/)

No usage telemetry or analytics are sent to ncdLabs by the plugin.

#### Source code for built assets

Admin, front-end, and plugins.php deactivation-feedback JavaScript and CSS are built
with `@wordpress/scripts` (`package.json` and `webpack.config.js`). Human-readable
sources ship in the plugin under `assets/src/`. Production builds ship in `build/`.

#### Third-party libraries

Composer production dependencies are MIT-licensed and GPL-compatible:

 * chrome-php/chrome, chrome-php/wrench
 * evenement/evenement
 * monolog/monolog
 * psr/log
 * symfony/filesystem, symfony/process, symfony/polyfill-ctype, symfony/polyfill-
   mbstring, symfony/polyfill-php80

See each package’s LICENSE file under `vendor/` for copyright notices.

npm production dependency (bundled into admin build assets; MIT-licensed and GPL-
compatible):

 * html2canvas (optional annotated screenshots for in-app bug reports)

## Captures d’écrans

[⌊ncdLabs Assure dashboard with readiness score and control summary⌉⌊ncdLabs Assure
dashboard with readiness score and control summary⌉[

ncdLabs Assure dashboard with readiness score and control summary

[⌊Controls list with GDPR, OWASP Top 10, and pack management⌉⌊Controls list with
GDPR, OWASP Top 10, and pack management⌉[

Controls list with GDPR, OWASP Top 10, and pack management

[⌊Consent banner configuration and preview⌉⌊Consent banner configuration and preview⌉[

Consent banner configuration and preview

[⌊Findings view with remediation actions⌉⌊Findings view with remediation actions⌉[

Findings view with remediation actions

## Installation

 1. Upload the plugin folder to `/wp-content/plugins/ncdlabs-assure/` or install through
    the WordPress Plugins screen.
 2. Activate **ncdLabs Assure** through the **Plugins** menu.
 3. Open **ncdLabs Assure** in the admin sidebar.
 4. Run **Assure  Audits  Run audit** to generate your first GDPR technical readiness
    snapshot.
 5. Configure **Manage  Settings** (General, Controls, Integrations, Consent, Remote
    browser) as needed for your stack.

#### Development build

If you clone the repository, run `npm install && npm run build` before activating
so `build/` assets exist.

## FAQ

### Do I need a paid pack to use ncdLabs Assure?

No. The free plugin includes complete GDPR, OWASP Top 10, and NIST CSF 2.0 technical
control catalogs, consent manager, enforcement tools, audits, evidence, and reporting.
Paid yearly packs add optional frameworks such as HIPAA, SOC 2, CCPA, and WCAG.

### Does ncdLabs Assure make my site legally compliant?

No. ncdLabs Assure documents **technical** observations and helps you operate controls
on your WordPress site. Legal compliance depends on your organization, data processing,
policies, and jurisdiction. Consult qualified counsel.

### How do compliance packs work?

Purchase a pack at [ncdlabs.com](https://ncdlabs.com/products/assure/store/) via
Stripe Checkout, download the encrypted `.assure-pack` from your order confirmation,
then use **Manage  Settings  Controls  Install framework pack** and enter your unlock
key. Activation binds the pack to the current site URL. Paid pack files are never
included in the free WordPress.org download.

### How do I enable hosted browser verification?

Use **Connect hosted browser** in the first-run setup wizard or under **Manage  
Settings  Remote browser**. Confirm the administrator email, wait for ncdLabs site
approval, and credentials are sealed into the plugin. Without hosted browser verification,
some visitor-facing controls remain **Needs review**.

### Does ncdLabs Assure work with Complianz or other CMPs?

Yes. When a supported third-party consent plugin is active, ncdLabs Assure defers
to it and disables the native consent banner to avoid conflicts.

### What data does ncdLabs Assure store?

Audit results, evidence, activity log entries, and settings are stored in your WordPress
database. Installed framework pack catalogs are stored under `wp-content/assure/
frameworks/` (outside uploads when that directory is writable; otherwise uploads).
Consent preferences are stored in the visitor’s browser (localStorage) when using
the native banner.

### Does ncdLabs Assure contact external servers?

Only in the cases documented under External services (pack activation, optional 
browser verification, optional Google OAuth, and optional deactivation or in-app
product feedback if an administrator submits a form). Feedback is never required
to use or deactivate the plugin.

### What happens when I uninstall ncdLabs Assure?

Uninstalling deletes ncdLabs Assure database tables, plugin settings, scheduled 
monitoring events, and uploaded framework pack files under `wp-content/uploads/assure/`.
This cannot be undone.

## Avis

Il n’y a aucun avis pour cette extension.

## Contributeurs/contributrices & développeurs/développeuses

« ncdLabs Assure – Security & Compliance Scanner » est un logiciel libre. Les personnes
suivantes ont contribué à cette extension.

Contributeurs

 *   [ ncdLabs ](https://profiles.wordpress.org/ncdlou/)

[Traduisez « ncdLabs Assure – Security & Compliance Scanner » dans votre langue.](https://translate.wordpress.org/projects/wp-plugins/ncdlabs-assure)

### Le développement vous intéresse ?

[Parcourir le code](https://plugins.trac.wordpress.org/browser/ncdlabs-assure/),
consulter le [SVN dépôt](https://plugins.svn.wordpress.org/ncdlabs-assure/), ou 
s’inscrire au [journal de développement](https://plugins.trac.wordpress.org/log/ncdlabs-assure/)
par [RSS](https://plugins.trac.wordpress.org/log/ncdlabs-assure/?limit=100&mode=stop_on_copy&format=rss).

## Journal des modifications

#### 0.1.18

 * Fix: Readiness over time chart shows date labels vertically so they no longer
   overlap.

#### 0.1.17

 * Fix: Remote browser Settings Status shows readiness and last audit scan (no longer
   looks Unavailable from skipped integrations discovery).
 * Enhancement: Audit results list marks controls verified with the hosted remote
   browser.

#### 0.1.16

 * Enhancement: audit progress modal with Hide and Notify Me When Done (toast + 
   notification bell).
 * Fix: Results defaults to Failed + Warning so action-required warnings are visible.
 * Fix: automatic checks that were false UNKNOWN now return WARNING (consent mechanism/
   blocking, monitoring, registration, admin limits, privacy tools, Consent Mode
   signals).

#### 0.1.15

 * Enhancement: Apply Fix can enable baseline security headers (HSTS on HTTPS, X-
   Frame-Options, Referrer-Policy, X-Content-Type-Options).
 * Fix: Apply Recommended Controls skips remediations that would not change site
   state (no-op Apply Fix).

#### 0.1.14

 * Fix: Apply Recommended Controls modal no longer snaps back to How To Fix after
   apply; closes after dashboard refresh.
 * Fix: How To Fix lists only queued automatic remediations and shows framework:
   control_id chips.

#### 0.1.13

 * Security: neutralize CSV formula injection in evidence and report exports.
 * Security: SecretBox is GCM-only; legacy CBC secrets migrate to GCM on read.
 * Enhancement: WordPress.org review prompt capped at three lifetime impressions
   with an I’ve Already Left a Review dismiss.
 * Docs: accurate free control counts (59 GDPR, 38 OWASP Top 10 2025, 17 NIST CSF
   2.0); clarify pack key derivation comments.

#### 0.1.12

 * Fix: OWASP A03/A07 controls no longer bind to unrelated plugin-update/abandonment/
   stale-admin checks; never-PASS Automatic free controls moved to Manual review.
 * Fix: Apply Fix refreshes audit scores; REST /users check has a local fallback
   when hosted browser is unavailable.
 * Security: BV token preview is manage-only on Integrations; site-facing remediations
   require manage_options; installed packs store under wp-content/assure/frameworks
   with deny files.
 * Enhancement: pack install surfaces hosted browser provision failures; legacy 
   evaluators defer when a shared test_key is present.

#### 0.1.11

 * Fix: automatic control checks stop false PASSes (core checksum file compare, 
   GPC with Sec-GPC, Consent Mode signals, MFA/rate-limit plugin presence, export/
   erasure tool measurement, HTTPS live probe, missing security headers, monitoring/
   retention cron evidence).
 * Fix: Compliance pack axe/GPC checks no longer fatally error when browser verification
   is unavailable.
 * Enhancement: admin last-login tracking for stale-account review; REST user check
   messaging scoped to /wp/v2/users.

#### 0.1.10

 * Enhancement: delayed in-app WordPress.org review prompt after four Assure admin
   visit days and a successful audit or remediation (Maybe Later / Don’t Ask Again).
 * Security: harden XML-RPC disable via empty xmlrpc_methods and align exposure 
   checks with external reachability plus hosted browser verification.

#### 0.1.9

 * Enhancement: findings include operator remediation guidance, framework citations,
   and control recheck from Results.
 * Enhancement: Manual Review right-rail for attestation controls; UNKNOWN status
   clarified as Needs review.
 * Enhancement: evidence attestation export and Collecting Evidence details for 
   manual controls.
 * Security: harden trust boundaries (attestation-only recheck rejection, pack directory
   deny, manage-only token preview, BV header SSRF review).
 * Fix: rescore audits when evidence is saved; XML-RPC auto-remediation helper.

#### 0.1.8

 * Enhancement: runtime script-blocking verification — browser snapshots capture
   blocked scripts; consent controls PASS on blocked markers without live tracking.
 * Enhancement: Apply Recommended Controls status dialog (preview  Continue  per-
   action apply  summary).
 * Fix: setup wizard resumes on the browser step after hosted email confirm; admin
   views refresh after audits/setup.
 * Fix: XML-RPC control evaluates PASS/FAIL via xmlrpc_enabled; transport security
   headers require fresh_visitor browser verification.

#### 0.1.7

 * Fix: disable hosted remote browser connect, test, verify, and provision in WordPress
   Playground (sites are not publicly reachable).

#### 0.1.6

 * Enhancement: WordPress.org Live Preview via Playground blueprint (assets/blueprints/
   blueprint.json).

#### 0.1.5

 * Enhancement: default report and dashboard scope covers all active frameworks 
   with control-weighted readiness rollups.
 * Fix: multi-framework Failed / Action required deep-links open Results across 
   frameworks instead of an empty single-audit list.
 * Fix: Not tested and Manual review filters align with stored audit counts (including
   informational controls).
 * Fix: System health open failures and Monitoring status match the selected framework
   rollup and settings.

#### 0.1.4

 * Security: hosted browser connect requires WordPress site-control proof after 
   email confirm (stops claiming another site_url).
 * Security: report/evidence export requires manage_assure; pack install binds framework
   hint to decrypted catalog; AES-GCM for stored secrets.
 * Fix: monitoring cron self-heals lost schedules, avoids overlapping runs, and 
   records missed-cron health.
 * Enhancement: Integrations shows when enforcement is configured but inactive (
   native consent / third-party CMP).
 * Enhancement: Apply recommended controls works across selected frameworks via 
   shared test_key handlers.

#### 0.1.3

 * Feature: Assure  Reports audience packs (Executive, Security, Compliance auditor,
   Vendor, Customer) with preview and JSON/CSV/PDF export.
 * Feature: in-app Documentation, Request a feature, and Report a bug from the admin
   right-rail (optional email via wp_mail).
 * Enhancement: ncdLabs admin menu folder flyout lists plugins only; support utilities
   sit above the footer separator.

#### 0.1.2

 * Hosted browser connect finishes after email confirmation (no ops approval wait).
 * Faster post-confirm polling and clearer Remote browser / setup wizard copy.

#### 0.1.1

 * Feature: one-click hosted browser verification connect (email confirm + ncdLabs
   site approval  sealed credentials); Settings  Remote browser.
 * Feature: multi-tab technical readiness Reports suite with consolidated package,
   content hash, and JSON/CSV/PDF export.
 * Feature: Manage  Settings consolidates General, Controls, Integrations, Consent,
   and Remote browser (legacy menu slugs redirect).
 * Enhancement: timezone labels on user-facing timestamps; optional ncdLabs admin
   menu folder for suite nesting.
 * Docs: External services disclosure updated for free-path browser connect endpoints.

#### 0.1.0

 * Initial release: GDPR control catalog, discovery, audits, consent manager, enforcement,
   YouTube gating, evidence export, remediation helpers, and optional encrypted 
   compliance pack import.
 * Feature: optional deactivation feedback survey on Plugins  Deactivate (skip anytime;
   diagnostics opt-in only).
 * Privacy: product privacy notice documents optional deactivation feedback.

## Méta

 *  Version **0.1.18**
 *  Dernière mise à jour **il y a 4 heures**
 *  Installations actives **Moins de 10**
 *  Version de WordPress ** 6.6 ou plus **
 *  Testé jusqu’à **7.1.2**
 *  Version de PHP ** 8.1 ou plus **
 *  Langue
 * [English (US)](https://wordpress.org/plugins/ncdlabs-assure/)
 * Étiquettes
 * [audit](https://fr.wordpress.org/plugins/tags/audit/)[compliance](https://fr.wordpress.org/plugins/tags/compliance/)
   [consent](https://fr.wordpress.org/plugins/tags/consent/)[GDPR](https://fr.wordpress.org/plugins/tags/gdpr/)
   [privacy](https://fr.wordpress.org/plugins/tags/privacy/)
 *  [Vue avancée](https://fr.wordpress.org/plugins/ncdlabs-assure/advanced/)

## Évaluations

Aucun avis n’a encore été envoyé.

[Votre avis](https://wordpress.org/support/plugin/ncdlabs-assure/reviews/#new-post)

[Tout voir](https://wordpress.org/support/plugin/ncdlabs-assure/reviews/)

## Contributeurs

 *   [ ncdLabs ](https://profiles.wordpress.org/ncdlou/)

## Support

Quelque chose à dire ? Besoin d’aide ?

 [Voir le forum de support](https://wordpress.org/support/plugin/ncdlabs-assure/)