Title: ncdLabs Assure &#8211; Security &amp; Compliance Scanner
Author: ncdLabs
Published: <strong>September 15, 2026</strong>
Last modified: September 15, 2026

---

Search plugins

![](https://ps.w.org/ncdlabs-assure/assets/banner-772x250.png?rev=3696057)

![](https://ps.w.org/ncdlabs-assure/assets/icon-256x256.png?rev=3696057)

# ncdLabs Assure – Security & Compliance Scanner

 By [ncdLabs](https://profiles.wordpress.org/ncdlou/)

[Download](https://downloads.wordpress.org/plugin/ncdlabs-assure.0.1.0.zip)

 * [Details](https://wordpress.org/plugins/ncdlabs-assure/#description)
 * [Reviews](https://wordpress.org/plugins/ncdlabs-assure/#reviews)
 *  [Installation](https://wordpress.org/plugins/ncdlabs-assure/#installation)
 * [Development](https://wordpress.org/plugins/ncdlabs-assure/#developers)

 [Support](https://wordpress.org/support/plugin/ncdlabs-assure/)

## Description

ncdLabs Assure helps WordPress site owners and operators run **technical** GDPR 
readiness work inside wp-admin: site discovery, control evaluation, consent management,
script enforcement, evidence collection, remediation helpers, and audit reporting.

ncdLabs Assure verifies controls it can observe on your site, records evidence, 
and flags items that need manual review. **It does not replace legal counsel and
does not certify legal compliance.**

#### Free frameworks (included)

 * Built-in GDPR control catalog (47 technical controls across consent, analytics,
   forms, embeds, and WordPress configuration)
 * Built-in OWASP Top 10 control catalog (24 WordPress-focused security controls
   mapped to OWASP Top 10 2021 categories)
 * Built-in NIST CSF 2.0 control catalog (15 WordPress-focused cybersecurity readiness
   controls)
 * Site discovery for plugins, scripts, iframes, forms, and third-party services
 * Native consent banner and preference center (defers to an active third-party 
   CMP when one is detected)
 * Google Consent Mode v2 defaults, optional GA/GTM deferral, and script blocking
   before consent
 * YouTube embed gating until External Media consent is granted
 * Scheduled monitoring and configuration drift detection
 * Audit runs with scored results, findings, history, and exportable reports
 * Evidence log with JSON, CSV, and PDF export
 * One-click remediation helpers for supported controls

#### Optional compliance packs (sold separately, not included in this plugin)

HIPAA, SOC 2, CCPA, WCAG, and other framework catalogs are **not bundled** in the
WordPress.org plugin. Purchase a yearly subscription through Stripe Checkout at 
[ncdLabs Assure](https://ncdlabs.com/products/assure/store/), download the encrypted`.
assure-pack` file from your order confirmation, then import it from **ncdLabs Assure
Controls  Install framework pack** with your unlock key. **Packs are not required
for GDPR, OWASP, or NIST CSF functionality.**

#### Who this is for

 * WordPress admins responsible for privacy-related technical controls
 * Agencies operating client sites who need repeatable evidence and audit history
 * Teams preparing for GDPR-related technical reviews (not a substitute for legal
   advice)

#### External services

ncdLabs Assure connects to external services only in the cases below. Hostnames 
such as `js.stripe.com`, `connect.facebook.net`, `googletagmanager.com`, and `youtube.
com` that appear in plugin source are **local detection / verification signature
strings** used to recognize scripts already present on your site. The plugin does**
not** load those third-party scripts, call those vendors’ APIs, or send visitor 
data to them.

**Pack activation (ncdlabs.com)** — When you import a purchased compliance pack,
ncdLabs Assure sends your pack unlock key, framework identifier, and this site’s
URL to the ncdLabs activation API to verify the Stripe purchase and bind the license
to one site:

 * Endpoint: `https://ncdlabs.com/products/assure/api/activate`
 * Data sent: unlock key, framework ID, site URL
 * When: only when you preview or install an encrypted pack you purchased and downloaded
   from Stripe Checkout
 * Terms of use: [https://ncdlabs.com/products/assure/terms/](https://ncdlabs.com/products/assure/terms/)
 * Privacy policy: [https://ncdlabs.com/privacy/](https://ncdlabs.com/privacy/);
   product: [https://ncdlabs.com/products/assure/privacy/](https://ncdlabs.com/products/assure/privacy/)

**Browser verification (ncdlabs.com, optional)** — When you import a purchased compliance
pack, ncdLabs Assure may call the ncdLabs provisioning API to enable hosted browser
verification for consent and analytics checks. If configured, audit and discovery
may also send scan targets to your configured browser verification service:

 * Provision endpoint: `https://ncdlabs.com/products/assure/api/browser-verification/
   provision`
 * Default service: `https://browser-verify.ncdlabs.com`
 * Data sent: pack unlock key, site URL (provision); scan target URL and verification
   token (when the hosted service is enabled)
 * When: pack import provisioning; during audits/discovery when hosted browser verification
   is enabled in **Manage  Integrations**
 * Security: verification endpoints must use HTTPS. Self-hosted endpoint domains
   must be explicitly allowed with the `assure_browser_verification_allowed_hosts`
   filter.
 * Terms of use: [https://ncdlabs.com/products/assure/terms/](https://ncdlabs.com/products/assure/terms/)
 * Privacy policy: [https://ncdlabs.com/privacy/](https://ncdlabs.com/privacy/);
   product: [https://ncdlabs.com/products/assure/privacy/](https://ncdlabs.com/products/assure/privacy/)

**Google Analytics / Google Tag Manager OAuth (Google + ncdlabs.com, optional)**—
When an administrator connects Google Analytics or Google Tag Manager from **Manage
Integrations**, ncdLabs Assure may use Google OAuth plus the Google Analytics Admin
API and/or Google Tag Manager API. If you have not configured your own Google OAuth
client credentials, ncdLabs Assure uses an ncdLabs OAuth proxy:

 * Proxy endpoints: `https://ncdlabs.com/products/assure/api/google/oauth/start`
   and `.../exchange`
 * Google endpoints: `accounts.google.com`, `oauth2.googleapis.com`, `www.googleapis.
   com`, `analyticsadmin.googleapis.com`, `tagmanager.googleapis.com`
 * Data sent: OAuth state, authorization code, and Google Analytics account/property
   or Tag Manager account/container metadata needed to verify configuration
 * When: only when an administrator starts or completes a Google Analytics or Google
   Tag Manager connection
 * Terms of use: [https://ncdlabs.com/products/assure/terms/](https://ncdlabs.com/products/assure/terms/);
   Google: [https://policies.google.com/terms](https://policies.google.com/terms)
 * Privacy policy: [https://ncdlabs.com/privacy/](https://ncdlabs.com/privacy/);
   Google: [https://policies.google.com/privacy](https://policies.google.com/privacy)

**Third-party script detection signatures (no outbound calls)** — During discovery,
audits, and optional browser verification, ncdLabs Assure matches HTML, network 
requests, and installed plugins against known vendor hostname patterns (examples:
Google Analytics/Tag Manager, Meta Pixel / `connect.facebook.net`, LinkedIn Insight,
Hotjar, Microsoft Clarity, YouTube, Vimeo, HubSpot, Mailchimp, Brevo, Stripe / `
js.stripe.com`). Examples also include CDN hostnames such as `gstatic.com`, `cloudflare.
com`, `unpkg.com`, and `cdnjs.cloudflare.com` that appear only as local classification
signatures in discovery code. Matching is local string comparison against content
already on your site or observed in a verification scan of your site. ncdLabs Assure
does not call these vendors, load their scripts, or transmit data to them.

**Site self-scan (your own WordPress site)** — During discovery and audits, ncdLabs
Assure may request your site’s public homepage and REST API to detect scripts, embeds,
forms, and integrations. These requests stay on your site; ncdLabs Assure does not
send discovery results to ncdLabs.

**Optional deactivation feedback (wp_mail)** — When an administrator deactivates
the plugin, an optional survey may appear. Feedback is never required: **Skip & 
deactivate**, Close, Escape, or Cancel leave without sending anything. If the administrator
submits feedback, the selected reason and optional comments are emailed to ncdLabs(`
feedback+assure@ncdlabs.com`) using this site’s WordPress mail. A separate checkbox(
unchecked by default) can include plugin, WordPress, and PHP versions only — never
the site URL or admin email. Mail/API failure still proceeds to deactivate.

 * Terms of use: [https://ncdlabs.com/products/assure/terms/](https://ncdlabs.com/products/assure/terms/)
 * Privacy policy: [https://ncdlabs.com/privacy/](https://ncdlabs.com/privacy/);
   product: [https://ncdlabs.com/products/assure/privacy/](https://ncdlabs.com/products/assure/privacy/)

No usage telemetry or analytics are sent to ncdLabs by the plugin.

#### Source code for built assets

Admin, front-end, and plugins.php deactivation-feedback JavaScript and CSS are built
with `@wordpress/scripts` (`package.json` and `webpack.config.js`). Human-readable
sources ship in the plugin under `assets/src/`. Production builds ship in `build/`.

#### Third-party libraries

Composer production dependencies are MIT-licensed and GPL-compatible:

 * chrome-php/chrome, chrome-php/wrench
 * evenement/evenement
 * monolog/monolog
 * psr/log
 * symfony/filesystem, symfony/process, symfony/polyfill-ctype, symfony/polyfill-
   mbstring, symfony/polyfill-php80

See each package’s LICENSE file under `vendor/` for copyright notices.

## Screenshots

[⌊ncdLabs Assure dashboard with readiness score and control summary⌉⌊ncdLabs Assure
dashboard with readiness score and control summary⌉[

ncdLabs Assure dashboard with readiness score and control summary

[⌊Controls list with GDPR, OWASP Top 10, and pack management⌉⌊Controls list with
GDPR, OWASP Top 10, and pack management⌉[

Controls list with GDPR, OWASP Top 10, and pack management

[⌊Consent banner configuration and preview⌉⌊Consent banner configuration and preview⌉[

Consent banner configuration and preview

[⌊Findings view with remediation actions⌉⌊Findings view with remediation actions⌉[

Findings view with remediation actions

## Installation

 1. Upload the plugin folder to `/wp-content/plugins/ncdlabs-assure/` or install through
    the WordPress Plugins screen.
 2. Activate **ncdLabs Assure** through the **Plugins** menu.
 3. Open **ncdLabs Assure** in the admin sidebar.
 4. Run **Assure  Audits  Run audit** to generate your first GDPR technical readiness
    snapshot.
 5. Configure **Manage  Consent** and **Manage  Integrations** as needed for your stack.

#### Development build

If you clone the repository, run `npm install && npm run build` before activating
so `build/` assets exist.

## FAQ

### Do I need a paid pack to use ncdLabs Assure?

No. The free plugin includes complete GDPR, OWASP Top 10, and NIST CSF 2.0 technical
control catalogs, consent manager, enforcement tools, audits, evidence, and reporting.
Paid yearly packs add optional frameworks such as HIPAA, SOC 2, CCPA, and WCAG.

### Does ncdLabs Assure make my site legally compliant?

No. ncdLabs Assure documents **technical** observations and helps you operate controls
on your WordPress site. Legal compliance depends on your organization, data processing,
policies, and jurisdiction. Consult qualified counsel.

### How do compliance packs work?

Purchase a pack at [ncdlabs.com](https://ncdlabs.com/products/assure/store/) via
Stripe Checkout, download the encrypted `.assure-pack` from your order confirmation,
then use **Controls  Install framework pack** and enter your unlock key. Activation
binds the pack to the current site URL. Paid pack files are never included in the
free WordPress.org download.

### Does ncdLabs Assure work with Complianz or other CMPs?

Yes. When a supported third-party consent plugin is active, ncdLabs Assure defers
to it and disables the native consent banner to avoid conflicts.

### What data does ncdLabs Assure store?

Audit results, evidence, activity log entries, and settings are stored in your WordPress
database. Installed framework pack catalogs are stored under your uploads directory
at `wp-content/uploads/assure/frameworks/`. Consent preferences are stored in the
visitor’s browser (localStorage) when using the native banner.

### Does ncdLabs Assure contact external servers?

Only in the cases documented under External services (pack activation, optional 
browser verification, optional Google OAuth, and optional deactivation feedback 
if an administrator submits the survey). Deactivation feedback is never required
to deactivate.

### What happens when I uninstall ncdLabs Assure?

Uninstalling deletes ncdLabs Assure database tables, plugin settings, scheduled 
monitoring events, and uploaded framework pack files under `wp-content/uploads/assure/`.
This cannot be undone.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“ncdLabs Assure – Security & Compliance Scanner” is open source software. The following
people have contributed to this plugin.

Contributors

 *   [ ncdLabs ](https://profiles.wordpress.org/ncdlou/)

[Translate “ncdLabs Assure – Security & Compliance Scanner” into your language.](https://translate.wordpress.org/projects/wp-plugins/ncdlabs-assure)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/ncdlabs-assure/), check
out the [SVN repository](https://plugins.svn.wordpress.org/ncdlabs-assure/), or 
subscribe to the [development log](https://plugins.trac.wordpress.org/log/ncdlabs-assure/)
by [RSS](https://plugins.trac.wordpress.org/log/ncdlabs-assure/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 0.1.0

 * Initial release: GDPR control catalog, discovery, audits, consent manager, enforcement,
   YouTube gating, evidence export, remediation helpers, and optional encrypted 
   compliance pack import.
 * Feature: optional deactivation feedback survey on Plugins  Deactivate (skip anytime;
   diagnostics opt-in only).
 * Privacy: product privacy notice documents optional deactivation feedback.

## Meta

 *  Version **0.1.0**
 *  Last updated **18 hours ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.6 or higher **
 *  Tested up to **7.1**
 *  PHP version ** 8.1 or higher **
 * Tags
 * [audit](https://wordpress.org/plugins/tags/audit/)[compliance](https://wordpress.org/plugins/tags/compliance/)
   [consent](https://wordpress.org/plugins/tags/consent/)[GDPR](https://wordpress.org/plugins/tags/gdpr/)
   [privacy](https://wordpress.org/plugins/tags/privacy/)
 *  [Advanced View](https://wordpress.org/plugins/ncdlabs-assure/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/ncdlabs-assure/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/ncdlabs-assure/reviews/)

## Contributors

 *   [ ncdLabs ](https://profiles.wordpress.org/ncdlou/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/ncdlabs-assure/)