JAZ-X Media Provenance Inspector

Description

JAZ-X Media Provenance Inspector helps WordPress administrators inventory media provenance and inspect C2PA metadata and credentials.

This is an independent plugin by JAZ-X Innovation. It is not affiliated with or endorsed by the Coalition for Content Provenance and Authenticity (C2PA) or the Content Authenticity Initiative.

Core features:

  • SHA-256 hashing of original media and generated image sizes.
  • Original and derivative inventory in dedicated database tables.
  • C2PA marker detection separated from generic JUMBF-only metadata.
  • Credential-loss warnings when a C2PA-bearing original produces WordPress derivatives that no longer contain the original credential marker.
  • Browser-side cryptographic C2PA verification using a locally bundled SDK and WebAssembly runtime.
  • Validation states for Trusted, Valid / untrusted, Invalid, No valid manifest, and Verification error. Trusted may remain visible on stored results produced with a previously configured trust source.
  • Human-readable explanations for common integrity and trust findings.
  • Manifest label/title, claim generator, signer, issuer, signature time, and validation-code capture where supplied by the verifier.
  • Media Library status column and an administrator-only JAZ-X Media Provenance Inspector dashboard.
  • Large-library scanning in safe 50-item AJAX batches with Pause/Resume and refresh-safe state.
  • JFIF/JPE support as part of the JPEG family.
  • Separate Unsupported, Missing source, Scan error, and Other JUMBF classifications.

JAZ-X Media Provenance Inspector 0.3.4 packages @contentauth/c2pa-web 0.15.1 and its matching WASM runtime inside the plugin. It does not load third-party executable JavaScript or WASM for cryptographic verification.

Media bytes are fetched from the same WordPress origin and processed in the administrator’s browser. JAZ-X Media Provenance Inspector does not upload media bytes to any JAZ-X service. Cross-origin attachment URLs (for example, some CDN/offload configurations) are not fetched by the verifier in this release.

Remote manifest fetching, OCSP lookups, and external trust-list requests are disabled in this release. Local integrity verification remains fully available without an external verification-data request.

Third-party code and source

JAZ-X Media Provenance Inspector includes GPL-compatible third-party dependencies under vendor/c2pa/. License copies and version/integrity information are included in THIRD-PARTY-NOTICES.txt and vendor/c2pa/licenses/.

The bundled C2PA browser runtime is built from:

  • @contentauth/c2pa-web 0.15.1 — MIT license
  • @contentauth/c2pa-wasm 0.13.0 — MIT license
  • @contentauth/c2pa-types 0.7.4 — MIT license
  • @contentauth/c2pa-utilities 0.3.0 — MIT license
  • highgain 0.1.0 — ISC license

Upstream C2PA source code:
https://github.com/contentauth/c2pa-js

Highgain package distribution:
https://www.npmjs.com/package/highgain/v/0.1.0

The included highgain.js is the small readable ESM distribution from that package; its package metadata and ISC license are included alongside it.

The distributed c2pa-web.runtime.js is the upstream npm distribution with one browser-resolution-only change: the bare highgain import is rewritten to the local ./highgain.js path. The local index file points to that renamed runtime chunk. Exact package versions and npm integrity values are recorded in vendor/c2pa/VERSIONS.txt.

Reproduction outline:

  1. Install Node.js and npm.
  2. Run npm install @contentauth/c2pa-web@0.15.1 highgain@0.1.0.
  3. Copy the package’s dist/index.js, runtime chunk, worker, and dist/resources/c2pa_bg.wasm into vendor/c2pa/.
  4. Rewrite the runtime’s bare highgain import to ./highgain.js, rewrite the index runtime import to the local renamed chunk, and use c2pa-web.bundle.js as the small JAZ-X Media Provenance Inspector entry module.

Installation

  1. Upload the plugin ZIP in Plugins > Add New > Upload Plugin, or install it from WordPress.org when available.
  2. Activate JAZ-X Media Provenance Inspector.
  3. Open JAZ-X Media Provenance Inspector in the WordPress admin menu. The dashboard is restricted to users with the manage_options capability by default.
  4. Scan the Media Library. Automatic mode works in 50-item batches and can be paused and resumed.
  5. When C2PA-bearing media is detected, use the cryptographic verification controls.
  6. Review the human-readable integrity findings and derivative credential-loss status.

Upgrades preserve existing JAZ-X Media Provenance Inspector scan and verification records. A full Media Library rescan is not required when upgrading from 0.3.0 or later to 0.3.4.

FAQ

Does JAZ-X Media Provenance Inspector upload my images to an external service?

No. Media bytes are fetched from the same WordPress origin and processed in the administrator’s browser by the locally packaged C2PA SDK/WASM runtime. Cross-origin media URLs are blocked by the verifier in this release.

Does the plugin contact external verification services?

No. JAZ-X Media Provenance Inspector 0.3.4 does not make external trust-list, remote-manifest, or OCSP requests. WordPress itself may make its normal core requests independently of this plugin.

What does Invalid mean?

It means the C2PA verifier reported a validation failure. For example, assertion.dataHash.mismatch means the current asset bytes do not match the bytes covered by the signed data-hash assertion. It should not be interpreted by itself as a claim about why the file changed.

What does Valid / untrusted mean?

Cryptographic validation passed, but JAZ-X Media Provenance Inspector did not establish signer trust. JAZ-X Media Provenance Inspector 0.3.4 does not make an external trust-list request, so it does not newly claim official C2PA trust-list status. Previously stored results from an earlier configured trust evaluation are preserved until an asset is verified again.

What does Other JUMBF metadata mean?

JUMBF is a generic metadata container. A generic JUMBF marker alone is not treated as confirmation that the file contains a valid C2PA manifest.

What is stored in the database?

JAZ-X Media Provenance Inspector stores attachment identifiers, relative media paths, MIME/dimension data, SHA-256 hashes, scan/verification status, selected C2PA manifest metadata, validation codes, derivative records, timestamps, and errors needed for the audit dashboard.

What happens to data on uninstall?

JAZ-X Media Provenance Inspector currently preserves the two audit tables on uninstall so provenance history is not silently destroyed. Operational options and per-user bulk-scan state are removed. A future release may add an explicit delete-audit-data setting.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“JAZ-X Media Provenance Inspector” is open source software. The following people have contributed to this plugin.

Contributors

Changelog

0.3.4

  • Updated the public plugin name and WordPress.org slug metadata to JAZ-X Media Provenance Inspector.
  • Shortened the plugin header description and removed the non-unique Plugin URI.
  • Replaced candidate-stage wording with final-release wording.
  • Moved older release history to changelog.txt to keep this readme compact.
  • No database schema or verification-engine change; existing scan and verification records are retained.

0.3.3

  • Reworked prepared database calls so Plugin Check can statically recognize the inline wpdb::prepare() calls instead of seeing intermediate query variables.
  • Kept %i identifier placeholders for custom and core table names; minimum WordPress remains 6.2.
  • Added narrow PHPCS no-cache rationale to the three remaining write-through audit-table operations reported by Plugin Check.
  • No database schema change; existing scan and verification records are retained.

Older release history is available in changelog.txt.