generated: '2026-08-12' method: probed source: https://auth.fusewp.com/ + https://fusewp.com/.well-known/ note: >- Assessed against the two first-party HTTP surfaces FuseWP actually operates — the OAuth broker at auth.fusewp.com and the WordPress MCP server on fusewp.com. FuseWP publishes no compliance claims, no certifications and no trust page, so no `Compliance` pointer is emitted; the standards below are conformance findings from observed behaviour, not a published programme. standards: - id: oauth2-authorization-code conforms: true evidence: >- auth.fusewp.com/{integration_id} issues a 302 to the partner's authorize endpoint with response_type=code and a registered redirect_uri, observed on 11 of 13 integration paths on 2026-08-12. - id: oauth2-refresh-token conforms: true evidence: >- AbstractIntegration::oauth_token_refresh calls auth.fusewp.com/{id}?refresh_token= and expects a JSON success envelope (plugin source 1.1.26.1). - id: rfc8414-oauth-authorization-server-metadata conforms: true evidence: >- https://fusewp.com/.well-known/oauth-authorization-server returns valid RFC 8414 JSON (issuer, authorization_endpoint, token_endpoint, revocation_endpoint, grant_types_supported, code_challenge_methods_supported). Note it 301s to the trailing-slash form, which strict RFC 8615 clients may not follow. - id: rfc9728-oauth-protected-resource-metadata conforms: true evidence: >- https://fusewp.com/.well-known/oauth-protected-resource returns valid RFC 9728 JSON naming the resource, its authorization server and bearer_methods_supported. - id: rfc7636-pkce conforms: true evidence: code_challenge_methods_supported = ["S256"] in the RFC 8414 document. - id: mcp conforms: partial evidence: >- An MCP endpoint is served and correctly advertised through RFC 9728, and it answers an anonymous tools/list with a 401 rather than an open surface. Conformance of the protocol itself could not be verified because the live schema is auth-gated. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on both fusewp.com and auth.fusewp.com. - id: openapi conforms: false evidence: >- No OpenAPI at any probed location on either host; the plugin registers zero REST routes. - id: rfc9457-problem-details conforms: false evidence: >- The broker's only observed failure response was an HTTP 500 with an empty body; the success envelope is a bare {"success": bool}. - id: rfc8594-sunset-header conforms: false evidence: No deprecation policy and no Sunset header; see lifecycle/fusewp-lifecycle.yml. - id: asyncapi conforms: false applicable: false evidence: >- No event, streaming or webhook surface of FuseWP's own — zero webhook references in the shipped plugin source. Not penalised; there is nothing to describe. - id: a2a conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json both 404 on fusewp.com and auth.fusewp.com. compliance_program: published: false certifications: [] probed: - {url: 'https://trust.fusewp.com/', status: 000} - {url: 'https://fusewp.com/security/', status: 404} note: >- A plugin that brokers OAuth credentials for eleven CRM platforms and moves customer contact data publishes no SOC 2, ISO 27001, GDPR-processor or DPA posture at any probed location. The privacy policy at https://fusewp.com/privacy-policy/ (200) is the only governance document found. x-evidence: fetched: '2026-08-12'