ScanBase – 152-FZ Website Compliance Check

Description

The plugin checks your website’s compliance with the Russian Federal Law No. 152-FZ “On Personal Data” and related requirements, using the API of the ScanBase service (scanbase.ru). It is aimed at owners of websites that fall under Russian personal data law; the admin interface is in Russian.

Right from your WordPress dashboard you get:

  • Compliance score of your site (0-100).
  • List of violations with the relevant article of law and the potential fine under the Russian Administrative Code.
  • Items to verify manually – things the automated checks could not confirm.
  • A traffic-light indicator in the admin bar showing the current score on every admin page.
  • A link to the full report in your ScanBase account: developer task list, document templates, remediation services.

The plugin works only in the admin area and outputs nothing to your site’s visitors.

How it works

The plugin is a thin client of the ScanBase API. All checks run on the service side; your API key is stored only on your site and is used solely for API requests. Your tier (free, scan package or subscription) is determined by your ScanBase account.

External service (mandatory disclosure)

The plugin is a client of the ScanBase cloud service (https://scanbase.ru) and does not work without it. What is sent to scanbase.ru and when:

  • When you start a check (button in wp-admin): your site URL and your API key. The service scans the site and returns the report.
  • During the optional one-click connect flow: your site URL and the admin email (used to sign in to the ScanBase account via a magic link and issue an API key).
  • No data about your site’s visitors is collected or transmitted: the plugin runs only in the admin area.

ScanBase service documents:

  • Privacy policy (personal data processing): https://scanbase.ru/legal/
  • API terms of use (tiers, limits): https://scanbase.ru/api/

Tiers

  • Free – 5 checks per day, condensed report.
  • Scan packages – full report for any domain, one-time payment.
  • Subscription – full report plus server-side monitoring.

All tiers are managed in the ScanBase account: https://scanbase.ru/cabinet/ The plugin code itself is not restricted – tiers only affect how much detail the API returns.

Screenshots

Installation

  1. Install and activate the plugin.
  2. Open the ScanBase menu in wp-admin.
  3. Click “Connect ScanBase” (one-click connect), or get a free key in the ScanBase account (Account -> API access -> “Create free key”) and paste it into the plugin.
  4. Click “Check site”.

FAQ

Do I need a ScanBase account?

Yes. Signing in is done by email (magic link), no password. A free API key is issued self-service.

Does my API key leave my site?

It is stored in your site’s options and is sent only to the scanbase.ru API when a check is requested.

What is checked for free?

The compliance score, the number of violations and the total potential fine. Some violation details are hidden on the free tier – the full list is available with a scan package or a subscription.

Does the plugin output anything to my site’s visitors?

No. The plugin works only in the admin area: no banners, links or scripts on visitor-facing pages.

What happens when I delete the plugin?

All settings and stored check results are removed from your site. If needed, revoke the API key in your ScanBase account.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“ScanBase – 152-FZ Website Compliance Check” is open source software. The following people have contributed to this plugin.

Contributors

Changelog

1.5.3

  • Fixed fine amounts display: values from the API are in rubles and were mistakenly divided by 100.

1.5.2

  • Contributors field fixed to the owner’s WordPress.org username.

1.5.1

  • readme rewritten in English (directory requirement); Plugin Check fixes.

1.5.0

  • The plugin is focused on its core: site compliance check (free and paid report). The email reminders and cookie banner modules were removed; the cron schedule left by older versions is cleaned up automatically.
  • The plugin no longer outputs anything on visitor-facing pages – admin area only.

1.4.1

  • Security: the last check’s data is passed to the script as JSON with HTML-significant characters escaped (strings from the scanned site cannot break out of the script context).
  • The “Verified by ScanBase” note enabled before 1.4.0 (when it was on by default) is no longer treated as consent – it is shown only after being explicitly enabled in settings.
  • Admin page scripts and styles are enqueued via standard WordPress mechanisms instead of inline output.
  • The external redirect to scanbase.ru in the connect flow goes through wp_safe_redirect with an explicit allowlist of hosts.

1.4.0

  • Preparation for the wordpress.org directory: the “Verified by ScanBase” note in the cookie banner became strictly opt-in (off by default).
  • Full cleanup of settings on plugin deletion (uninstall.php).
  • Explicit description of transmitted data and the external service in the readme.

1.3.0

  • Cookie banner for the site: cookie processing notice on all pages, visitor choice remembered, policy link, configurable text and buttons.

1.2.1

  • Reminder frequency: “monthly” (recommended) and “weekly”. Daily re-checks removed as excessive.

1.2.0

  • Compliance traffic light in the admin bar (like the Yoast indicator) – visible on every admin page.
  • Full report with “how to fix” recommendations right in WordPress; the last check is shown on page load.
  • Email reminders: periodic re-check with an email when compliance degrades.

1.1.0

  • One-click connect (“Connect ScanBase”): sign in by email, the key returns to the plugin automatically – no copying from the account.
  • Manual key entry kept as a fallback.

1.0.0

  • First release: site check from wp-admin, compliance score, violations, account status.