Title: JAZ-X Media Provenance Inspector
Author: jazxinnovation
Published: <strong>September 29, 2026</strong>
Last modified: September 29, 2026

---

Search plugins

![](https://ps.w.org/jazx-media-provenance-inspector/assets/icon-256x256.png?rev
=3718087)

# JAZ-X Media Provenance Inspector

 By [jazxinnovation](https://profiles.wordpress.org/jazxinnovation/)

[Download](https://downloads.wordpress.org/plugin/jazx-media-provenance-inspector.0.3.4.zip)

 * [Details](https://wordpress.org/plugins/jazx-media-provenance-inspector/#description)
 * [Reviews](https://wordpress.org/plugins/jazx-media-provenance-inspector/#reviews)
 *  [Installation](https://wordpress.org/plugins/jazx-media-provenance-inspector/#installation)
 * [Development](https://wordpress.org/plugins/jazx-media-provenance-inspector/#developers)

 [Support](https://wordpress.org/support/plugin/jazx-media-provenance-inspector/)

## Description

JAZ-X Media Provenance Inspector helps WordPress administrators inventory media 
provenance and inspect C2PA metadata and credentials.

This is an independent plugin by JAZ-X Innovation. It is not affiliated with or 
endorsed by the Coalition for Content Provenance and Authenticity (C2PA) or the 
Content Authenticity Initiative.

Core features:

 * SHA-256 hashing of original media and generated image sizes.
 * Original and derivative inventory in dedicated database tables.
 * C2PA marker detection separated from generic JUMBF-only metadata.
 * Credential-loss warnings when a C2PA-bearing original produces WordPress derivatives
   that no longer contain the original credential marker.
 * Browser-side cryptographic C2PA verification using a locally bundled SDK and 
   WebAssembly runtime.
 * Validation states for Trusted, Valid / untrusted, Invalid, No valid manifest,
   and Verification error. Trusted may remain visible on stored results produced
   with a previously configured trust source.
 * Human-readable explanations for common integrity and trust findings.
 * Manifest label/title, claim generator, signer, issuer, signature time, and validation-
   code capture where supplied by the verifier.
 * Media Library status column and an administrator-only JAZ-X Media Provenance 
   Inspector dashboard.
 * Large-library scanning in safe 50-item AJAX batches with Pause/Resume and refresh-
   safe state.
 * JFIF/JPE support as part of the JPEG family.
 * Separate Unsupported, Missing source, Scan error, and Other JUMBF classifications.

JAZ-X Media Provenance Inspector 0.3.4 packages `@contentauth/c2pa-web` 0.15.1 and
its matching WASM runtime inside the plugin. It does not load third-party executable
JavaScript or WASM for cryptographic verification.

Media bytes are fetched from the same WordPress origin and processed in the administrator’s
browser. JAZ-X Media Provenance Inspector does not upload media bytes to any JAZ-
X service. Cross-origin attachment URLs (for example, some CDN/offload configurations)
are not fetched by the verifier in this release.

Remote manifest fetching, OCSP lookups, and external trust-list requests are disabled
in this release. Local integrity verification remains fully available without an
external verification-data request.

#### Third-party code and source

JAZ-X Media Provenance Inspector includes GPL-compatible third-party dependencies
under `vendor/c2pa/`. License copies and version/integrity information are included
in `THIRD-PARTY-NOTICES.txt` and `vendor/c2pa/licenses/`.

The bundled C2PA browser runtime is built from:

 * `@contentauth/c2pa-web` 0.15.1 — MIT license
 * `@contentauth/c2pa-wasm` 0.13.0 — MIT license
 * `@contentauth/c2pa-types` 0.7.4 — MIT license
 * `@contentauth/c2pa-utilities` 0.3.0 — MIT license
 * `highgain` 0.1.0 — ISC license

Upstream C2PA source code:
 https://github.com/contentauth/c2pa-js

Highgain package distribution:
 https://www.npmjs.com/package/highgain/v/0.1.0

The included `highgain.js` is the small readable ESM distribution from that package;
its package metadata and ISC license are included alongside it.

The distributed `c2pa-web.runtime.js` is the upstream npm distribution with one 
browser-resolution-only change: the bare `highgain` import is rewritten to the local`./
highgain.js` path. The local index file points to that renamed runtime chunk. Exact
package versions and npm integrity values are recorded in `vendor/c2pa/VERSIONS.
txt`.

Reproduction outline:

 1. Install Node.js and npm.
 2. Run `npm install @contentauth/c2pa-web@0.15.1 highgain@0.1.0`.
 3. Copy the package’s `dist/index.js`, runtime chunk, worker, and `dist/resources/
    c2pa_bg.wasm` into `vendor/c2pa/`.
 4. Rewrite the runtime’s bare `highgain` import to `./highgain.js`, rewrite the index
    runtime import to the local renamed chunk, and use `c2pa-web.bundle.js` as the 
    small JAZ-X Media Provenance Inspector entry module.

## Installation

 1. Upload the plugin ZIP in Plugins > Add New > Upload Plugin, or install it from 
    WordPress.org when available.
 2. Activate JAZ-X Media Provenance Inspector.
 3. Open JAZ-X Media Provenance Inspector in the WordPress admin menu. The dashboard
    is restricted to users with the `manage_options` capability by default.
 4. Scan the Media Library. Automatic mode works in 50-item batches and can be paused
    and resumed.
 5. When C2PA-bearing media is detected, use the cryptographic verification controls.
 6. Review the human-readable integrity findings and derivative credential-loss status.

Upgrades preserve existing JAZ-X Media Provenance Inspector scan and verification
records. A full Media Library rescan is not required when upgrading from 0.3.0 or
later to 0.3.4.

## FAQ

### Does JAZ-X Media Provenance Inspector upload my images to an external service?

No. Media bytes are fetched from the same WordPress origin and processed in the 
administrator’s browser by the locally packaged C2PA SDK/WASM runtime. Cross-origin
media URLs are blocked by the verifier in this release.

### Does the plugin contact external verification services?

No. JAZ-X Media Provenance Inspector 0.3.4 does not make external trust-list, remote-
manifest, or OCSP requests. WordPress itself may make its normal core requests independently
of this plugin.

### What does Invalid mean?

It means the C2PA verifier reported a validation failure. For example, `assertion.
dataHash.mismatch` means the current asset bytes do not match the bytes covered 
by the signed data-hash assertion. It should not be interpreted by itself as a claim
about why the file changed.

### What does Valid / untrusted mean?

Cryptographic validation passed, but JAZ-X Media Provenance Inspector did not establish
signer trust. JAZ-X Media Provenance Inspector 0.3.4 does not make an external trust-
list request, so it does not newly claim official C2PA trust-list status. Previously
stored results from an earlier configured trust evaluation are preserved until an
asset is verified again.

### What does Other JUMBF metadata mean?

JUMBF is a generic metadata container. A generic JUMBF marker alone is not treated
as confirmation that the file contains a valid C2PA manifest.

### What is stored in the database?

JAZ-X Media Provenance Inspector stores attachment identifiers, relative media paths,
MIME/dimension data, SHA-256 hashes, scan/verification status, selected C2PA manifest
metadata, validation codes, derivative records, timestamps, and errors needed for
the audit dashboard.

### What happens to data on uninstall?

JAZ-X Media Provenance Inspector currently preserves the two audit tables on uninstall
so provenance history is not silently destroyed. Operational options and per-user
bulk-scan state are removed. A future release may add an explicit delete-audit-data
setting.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“JAZ-X Media Provenance Inspector” is open source software. The following people
have contributed to this plugin.

Contributors

 *   [ jazxinnovation ](https://profiles.wordpress.org/jazxinnovation/)

[Translate “JAZ-X Media Provenance Inspector” into your language.](https://translate.wordpress.org/projects/wp-plugins/jazx-media-provenance-inspector)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/jazx-media-provenance-inspector/),
check out the [SVN repository](https://plugins.svn.wordpress.org/jazx-media-provenance-inspector/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/jazx-media-provenance-inspector/)
by [RSS](https://plugins.trac.wordpress.org/log/jazx-media-provenance-inspector/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 0.3.4

 * Updated the public plugin name and WordPress.org slug metadata to JAZ-X Media
   Provenance Inspector.
 * Shortened the plugin header description and removed the non-unique Plugin URI.
 * Replaced candidate-stage wording with final-release wording.
 * Moved older release history to `changelog.txt` to keep this readme compact.
 * No database schema or verification-engine change; existing scan and verification
   records are retained.

#### 0.3.3

 * Reworked prepared database calls so Plugin Check can statically recognize the
   inline `wpdb::prepare()` calls instead of seeing intermediate query variables.
 * Kept `%i` identifier placeholders for custom and core table names; minimum WordPress
   remains 6.2.
 * Added narrow PHPCS no-cache rationale to the three remaining write-through audit-
   table operations reported by Plugin Check.
 * No database schema change; existing scan and verification records are retained.

Older release history is available in `changelog.txt`.

## Meta

 *  Version **0.3.4**
 *  Last updated **2 days ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.2 or higher **
 *  Tested up to **7.1.2**
 *  PHP version ** 7.4 or higher **
 * Tags
 * [authenticity](https://wordpress.org/plugins/tags/authenticity/)[c2pa](https://wordpress.org/plugins/tags/c2pa/)
   [media](https://wordpress.org/plugins/tags/media/)[provenance](https://wordpress.org/plugins/tags/provenance/)
   [verification](https://wordpress.org/plugins/tags/verification/)
 *  [Advanced View](https://wordpress.org/plugins/jazx-media-provenance-inspector/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/jazx-media-provenance-inspector/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/jazx-media-provenance-inspector/reviews/)

## Contributors

 *   [ jazxinnovation ](https://profiles.wordpress.org/jazxinnovation/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/jazx-media-provenance-inspector/)