
ncdLabs Assure helps WordPress site owners and operators run technical GDPR readiness work inside wp-admin: site discovery, control evaluation, consent management, script enforcement, evidence collection, remediation helpers, and audit reporting.
ncdLabs Assure verifies controls it can observe on your site, records evidence, and flags items that need manual review. It does not replace legal counsel and does not certify legal compliance.
Free frameworks (included)
- Built-in GDPR control catalog (47 technical controls across consent, analytics, forms, embeds, and WordPress configuration)
- Built-in OWASP Top 10 control catalog (24 WordPress-focused security controls mapped to OWASP Top 10 2021 categories)
- Built-in NIST CSF 2.0 control catalog (15 WordPress-focused cybersecurity readiness controls)
- Site discovery for plugins, scripts, iframes, forms, and third-party services
- Native consent banner and preference center (defers to an active third-party CMP when one is detected)
- Google Consent Mode v2 defaults, optional GA/GTM deferral, and script blocking before consent
- YouTube embed gating until External Media consent is granted
- Scheduled monitoring and configuration drift detection
- Audit runs with scored results, findings, history, and exportable reports
- Evidence log with JSON, CSV, and PDF export
- Technical readiness reports with audience packs (Executive, Security, Compliance auditor, Vendor, Customer), integrity hash, and JSON/CSV/PDF export
- In-app Documentation, Request a feature, and Report a bug (optional email via this site’s WordPress mail)
- One-click remediation helpers for supported controls
- Optional one-click hosted browser verification connect (email confirm; credentials save automatically)
Optional compliance packs (sold separately, not included in this plugin)
HIPAA, SOC 2, CCPA, WCAG, and other framework catalogs are not bundled in the WordPress.org plugin. Purchase a yearly subscription through Stripe Checkout at ncdLabs Assure, download the encrypted .assure-pack file from your order confirmation, then import it from Manage Settings Controls Install framework pack with your unlock key. Packs are not required for GDPR, OWASP, or NIST CSF functionality.
Who this is for
- WordPress admins responsible for privacy-related technical controls
- Agencies operating client sites who need repeatable evidence and audit history
- Teams preparing for GDPR-related technical reviews (not a substitute for legal advice)
External services
ncdLabs Assure connects to external services only in the cases below. Hostnames such as js.stripe.com, connect.facebook.net, googletagmanager.com, and youtube.com that appear in plugin source are local detection / verification signature strings used to recognize scripts already present on your site. The plugin does not load those third-party scripts, call those vendors’ APIs, or send visitor data to them.
Pack activation (ncdlabs.com) — When you import a purchased compliance pack, ncdLabs Assure sends your pack unlock key, framework identifier, and this site’s URL to the ncdLabs activation API to verify the Stripe purchase and bind the license to one site:
- Endpoint:
https://ncdlabs.com/products/assure/api/activate - Data sent: unlock key, framework ID, site URL
- When: only when you preview or install an encrypted pack you purchased and downloaded from Stripe Checkout
- Terms of use: https://ncdlabs.com/products/assure/terms/
- Privacy policy: https://ncdlabs.com/privacy/; product: https://ncdlabs.com/products/assure/privacy/
Browser verification (ncdlabs.com, optional) — Hosted browser verification is optional. Free sites can connect with one click from the setup wizard or Manage Settings Remote browser: the plugin starts an exchange, you confirm the administrator email, and sealed site credentials are delivered locally. Purchased compliance packs may still call the provisioning API after import. When connected, audits and discovery may send scan targets to the hosted browser verification service:
- Connect bootstrap:
https://ncdlabs.com/products/assure/api/browser-verification/request/bootstrap - Connect status:
https://ncdlabs.com/products/assure/api/browser-verification/request/status - Email confirmation:
…/request/confirm-email/…(auto-approves; credentials delivered on status poll) - Pack provision (alternate):
https://ncdlabs.com/products/assure/api/browser-verification/provision - Default service:
https://browser-verify.ncdlabs.com - Data sent (connect): site URL, administrator email, client commitment / client secret proof, optional return URL; later scan target URL and verification token when hosted scans run
- Data sent (pack provision): pack unlock key, site URL
- When: when an administrator starts Connect hosted browser; optionally after pack import provisioning; during audits/discovery when hosted browser verification is enabled under Manage Settings Remote browser
- Security: verification endpoints must use HTTPS. Self-hosted endpoint domains must be explicitly allowed with the
assure_browser_verification_allowed_hostsfilter. - Terms of use: https://ncdlabs.com/products/assure/terms/
- Privacy policy: https://ncdlabs.com/privacy/; product: https://ncdlabs.com/products/assure/privacy/
Google Analytics / Google Tag Manager OAuth (Google + ncdlabs.com, optional) — When an administrator connects Google Analytics or Google Tag Manager from Manage Settings Integrations, ncdLabs Assure may use Google OAuth plus the Google Analytics Admin API and/or Google Tag Manager API. If you have not configured your own Google OAuth client credentials, ncdLabs Assure uses an ncdLabs OAuth proxy:
- Proxy endpoints:
https://ncdlabs.com/products/assure/api/google/oauth/startand.../exchange - Google endpoints:
accounts.google.com,oauth2.googleapis.com,www.googleapis.com,analyticsadmin.googleapis.com,tagmanager.googleapis.com - Data sent: OAuth state, authorization code, and Google Analytics account/property or Tag Manager account/container metadata needed to verify configuration
- When: only when an administrator starts or completes a Google Analytics or Google Tag Manager connection
- Terms of use: https://ncdlabs.com/products/assure/terms/; Google: https://policies.google.com/terms
- Privacy policy: https://ncdlabs.com/privacy/; Google: https://policies.google.com/privacy
Third-party script detection signatures (no outbound calls) — During discovery, audits, and optional browser verification, ncdLabs Assure matches HTML, network requests, and installed plugins against known vendor hostname patterns (examples: Google Analytics/Tag Manager, Meta Pixel / connect.facebook.net, LinkedIn Insight, Hotjar, Microsoft Clarity, YouTube, Vimeo, HubSpot, Mailchimp, Brevo, Stripe / js.stripe.com). Examples also include CDN hostnames such as gstatic.com, cloudflare.com, unpkg.com, and cdnjs.cloudflare.com that appear only as local classification signatures in discovery code. Matching is local string comparison against content already on your site or observed in a verification scan of your site. ncdLabs Assure does not call these vendors, load their scripts, or transmit data to them.
Site self-scan (your own WordPress site) — During discovery and audits, ncdLabs Assure may request your site’s public homepage and REST API to detect scripts, embeds, forms, and integrations. These requests stay on your site; ncdLabs Assure does not send discovery results to ncdLabs.
Optional deactivation feedback (wp_mail) — When an administrator deactivates the plugin, an optional survey may appear. Feedback is never required: Skip & deactivate, Close, Escape, or Cancel leave without sending anything. If the administrator submits feedback, the selected reason and optional comments are emailed to ncdLabs (feedback+assure@ncdlabs.com) using this site’s WordPress mail. A separate checkbox (unchecked by default) can include plugin, WordPress, and PHP versions only — never the site URL or admin email. Mail/API failure still proceeds to deactivate.
Optional product feedback (wp_mail) — From the admin right-rail, administrators may open Documentation, Request a feature, or Report a bug. Documentation stays local. Feature requests and bug reports are emailed to ncdLabs (feedback+assure@ncdlabs.com) using this site’s WordPress mail only when an administrator submits the form. Bug reports may include the current admin page URL/title, optional contact details the administrator enters, optional console lines buffered in that session, optional diagnostics (plugin/WordPress/PHP versions), and an optional annotated screenshot the administrator chooses to attach. Nothing is sent unless the form is submitted.
- Terms of use: https://ncdlabs.com/products/assure/terms/
- Privacy policy: https://ncdlabs.com/privacy/; product: https://ncdlabs.com/products/assure/privacy/
No usage telemetry or analytics are sent to ncdLabs by the plugin.
Source code for built assets
Admin, front-end, and plugins.php deactivation-feedback JavaScript and CSS are built with @wordpress/scripts (package.json and webpack.config.js). Human-readable sources ship in the plugin under assets/src/. Production builds ship in build/.
Third-party libraries
Composer production dependencies are MIT-licensed and GPL-compatible:
- chrome-php/chrome, chrome-php/wrench
- evenement/evenement
- monolog/monolog
- psr/log
- symfony/filesystem, symfony/process, symfony/polyfill-ctype, symfony/polyfill-mbstring, symfony/polyfill-php80
See each package’s LICENSE file under vendor/ for copyright notices.
npm production dependency (bundled into admin build assets; MIT-licensed and GPL-compatible):
- html2canvas (optional annotated screenshots for in-app bug reports)
Screenshots

ncdLabs Assure dashboard with readiness score and control summary

Controls list with GDPR, OWASP Top 10, and pack management

Consent banner configuration and preview

Findings view with remediation actions