Description
JAZ-X Media Provenance Inspector helps WordPress administrators inventory media provenance and inspect C2PA metadata and credentials.
This is an independent plugin by JAZ-X Innovation. It is not affiliated with or endorsed by the Coalition for Content Provenance and Authenticity (C2PA) or the Content Authenticity Initiative.
Core features:
- SHA-256 hashing of original media and generated image sizes.
- Original and derivative inventory in dedicated database tables.
- C2PA marker detection separated from generic JUMBF-only metadata.
- Credential-loss warnings when a C2PA-bearing original produces WordPress derivatives that no longer contain the original credential marker.
- Browser-side cryptographic C2PA verification using a locally bundled SDK and WebAssembly runtime.
- Validation states for Trusted, Valid / untrusted, Invalid, No valid manifest, and Verification error. Trusted may remain visible on stored results produced with a previously configured trust source.
- Human-readable explanations for common integrity and trust findings.
- Manifest label/title, claim generator, signer, issuer, signature time, and validation-code capture where supplied by the verifier.
- Media Library status column and an administrator-only JAZ-X Media Provenance Inspector dashboard.
- Large-library scanning in safe 50-item AJAX batches with Pause/Resume and refresh-safe state.
- JFIF/JPE support as part of the JPEG family.
- Separate Unsupported, Missing source, Scan error, and Other JUMBF classifications.
JAZ-X Media Provenance Inspector 0.3.4 packages @contentauth/c2pa-web 0.15.1 and its matching WASM runtime inside the plugin. It does not load third-party executable JavaScript or WASM for cryptographic verification.
Media bytes are fetched from the same WordPress origin and processed in the administrator’s browser. JAZ-X Media Provenance Inspector does not upload media bytes to any JAZ-X service. Cross-origin attachment URLs (for example, some CDN/offload configurations) are not fetched by the verifier in this release.
Remote manifest fetching, OCSP lookups, and external trust-list requests are disabled in this release. Local integrity verification remains fully available without an external verification-data request.
Third-party code and source
JAZ-X Media Provenance Inspector includes GPL-compatible third-party dependencies under vendor/c2pa/. License copies and version/integrity information are included in THIRD-PARTY-NOTICES.txt and vendor/c2pa/licenses/.
The bundled C2PA browser runtime is built from:
@contentauth/c2pa-web0.15.1 — MIT license@contentauth/c2pa-wasm0.13.0 — MIT license@contentauth/c2pa-types0.7.4 — MIT license@contentauth/c2pa-utilities0.3.0 — MIT licensehighgain0.1.0 — ISC license
Upstream C2PA source code:
https://github.com/contentauth/c2pa-js
Highgain package distribution:
https://www.npmjs.com/package/highgain/v/0.1.0
The included highgain.js is the small readable ESM distribution from that package; its package metadata and ISC license are included alongside it.
The distributed c2pa-web.runtime.js is the upstream npm distribution with one browser-resolution-only change: the bare highgain import is rewritten to the local ./highgain.js path. The local index file points to that renamed runtime chunk. Exact package versions and npm integrity values are recorded in vendor/c2pa/VERSIONS.txt.
Reproduction outline:
- Install Node.js and npm.
- Run
npm install @contentauth/c2pa-web@0.15.1 highgain@0.1.0. - Copy the package’s
dist/index.js, runtime chunk, worker, anddist/resources/c2pa_bg.wasmintovendor/c2pa/. - Rewrite the runtime’s bare
highgainimport to./highgain.js, rewrite the index runtime import to the local renamed chunk, and usec2pa-web.bundle.jsas the small JAZ-X Media Provenance Inspector entry module.
Installation
- Upload the plugin ZIP in Plugins > Add New > Upload Plugin, or install it from WordPress.org when available.
- Activate JAZ-X Media Provenance Inspector.
- Open JAZ-X Media Provenance Inspector in the WordPress admin menu. The dashboard is restricted to users with the
manage_optionscapability by default. - Scan the Media Library. Automatic mode works in 50-item batches and can be paused and resumed.
- When C2PA-bearing media is detected, use the cryptographic verification controls.
- Review the human-readable integrity findings and derivative credential-loss status.
Upgrades preserve existing JAZ-X Media Provenance Inspector scan and verification records. A full Media Library rescan is not required when upgrading from 0.3.0 or later to 0.3.4.
FAQ
-
Does JAZ-X Media Provenance Inspector upload my images to an external service?
-
No. Media bytes are fetched from the same WordPress origin and processed in the administrator’s browser by the locally packaged C2PA SDK/WASM runtime. Cross-origin media URLs are blocked by the verifier in this release.
-
Does the plugin contact external verification services?
-
No. JAZ-X Media Provenance Inspector 0.3.4 does not make external trust-list, remote-manifest, or OCSP requests. WordPress itself may make its normal core requests independently of this plugin.
-
What does Invalid mean?
-
It means the C2PA verifier reported a validation failure. For example,
assertion.dataHash.mismatchmeans the current asset bytes do not match the bytes covered by the signed data-hash assertion. It should not be interpreted by itself as a claim about why the file changed. -
What does Valid / untrusted mean?
-
Cryptographic validation passed, but JAZ-X Media Provenance Inspector did not establish signer trust. JAZ-X Media Provenance Inspector 0.3.4 does not make an external trust-list request, so it does not newly claim official C2PA trust-list status. Previously stored results from an earlier configured trust evaluation are preserved until an asset is verified again.
-
What does Other JUMBF metadata mean?
-
JUMBF is a generic metadata container. A generic JUMBF marker alone is not treated as confirmation that the file contains a valid C2PA manifest.
-
What is stored in the database?
-
JAZ-X Media Provenance Inspector stores attachment identifiers, relative media paths, MIME/dimension data, SHA-256 hashes, scan/verification status, selected C2PA manifest metadata, validation codes, derivative records, timestamps, and errors needed for the audit dashboard.
-
What happens to data on uninstall?
-
JAZ-X Media Provenance Inspector currently preserves the two audit tables on uninstall so provenance history is not silently destroyed. Operational options and per-user bulk-scan state are removed. A future release may add an explicit delete-audit-data setting.
Reviews
There are no reviews for this plugin.
Contributors & Developers
“JAZ-X Media Provenance Inspector” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “JAZ-X Media Provenance Inspector” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
0.3.4
- Updated the public plugin name and WordPress.org slug metadata to JAZ-X Media Provenance Inspector.
- Shortened the plugin header description and removed the non-unique Plugin URI.
- Replaced candidate-stage wording with final-release wording.
- Moved older release history to
changelog.txtto keep this readme compact. - No database schema or verification-engine change; existing scan and verification records are retained.
0.3.3
- Reworked prepared database calls so Plugin Check can statically recognize the inline
wpdb::prepare()calls instead of seeing intermediate query variables. - Kept
%iidentifier placeholders for custom and core table names; minimum WordPress remains 6.2. - Added narrow PHPCS no-cache rationale to the three remaining write-through audit-table operations reported by Plugin Check.
- No database schema change; existing scan and verification records are retained.
Older release history is available in changelog.txt.