Description
Previous admins, old themes and WooCommerce product imports leave behind images nobody has a license record for. PixGuard Scanner checks your Media Library and pages for copyright risk signals and gives each image a 0 to 100 risk score with the reasons behind it, so you know which images to investigate first.
A risk score is an estimate, not proof. PixGuard flags images for review; it does not confirm who owns an image and it is not legal advice.
Features:
- One-click “Scan All Media Library” with live progress, pause on rate limits and cancel
- Scan button and risk column in the Media Library
- Scan the images on any page of your site, or queue your published pages and posts
- Optional scan of new images as they are uploaded
- Results page showing the signals behind each score
- Dashboard with risk summary, recent scans and your plan’s remaining image scans
- Weekly email summary of flagged images
What each account scan checks:
- EXIF, IPTC and XMP copyright fields (photographer, agency, license notes)
- Watermark text and logos from major stock agencies
- Matches against a database of reference image fingerprints
- An estimate of whether the image is AI-generated
Pro and Business plans add similarity matching for edited or cropped copies, an AI vision review of borderline images, and source lookup: web pages where a matching image appears. In the plugin, source lookup runs on Media Library and website scans of images PixGuard hasn’t checked before.
Plans:
- Free: 30 image scans, valid for 30 days after signup, no credit card. Up to 10 image scans a day.
- Each new image uses 1 image scan. Images PixGuard has checked before are free to rescan.
- Pro and Business include more image scans each month. See pricing.
How it works:
- Install the plugin and create a free PixGuard account
- Copy an API key from Settings on pixguard.io and paste it into PixGuard > Settings
- Scan your Media Library or a page, then review the flagged images
External Services
This plugin connects to the PixGuard service (api.pixguard.io) to analyze images for copyright risk signals. It is required for the plugin to work, and it needs a PixGuard account with an API key.
What is sent, and when:
- When you scan a Media Library image (by hand, with Scan All, or on upload if you turn that on), the image URL is sent. If PixGuard can’t download it (for example on a local or password-protected site), the image file is uploaded instead.
- When you scan a page or queue pages, the page URLs are sent and PixGuard downloads the images on those pages.
- Your API key is sent with every request, and the plugin reads your plan and remaining image scans from your account.
Image files are not kept after analysis. PixGuard keeps image fingerprints, metadata and scan results so that images it has already checked are free to rescan. For source lookup on Pro and Business plans, the image is also sent to a web search provider. See the privacy policy for details.
- Service website: https://www.pixguard.io
- Privacy policy: https://www.pixguard.io/privacy
- Terms of service: https://www.pixguard.io/terms
Installation
- Upload the
pixguard-scannerfolder to/wp-content/plugins/, or install it from Plugins > Add New - Activate the plugin through the Plugins menu
- Create a free account at pixguard.io and copy an API key from pixguard.io/settings
- Go to PixGuard > Settings in WordPress and paste the key
FAQ
-
How much does it cost?
-
The plugin is free. Scans use the image scans in your PixGuard account: each new image uses 1 image scan, and images PixGuard has checked before are free to rescan. A free account includes 30 image scans, valid for 30 days after signup, with up to 10 image scans a day and no credit card. Pro and Business include more each month.
-
Does it find where an image came from?
-
On Pro and Business plans, Media Library and website scans of images PixGuard hasn’t checked before also look up web pages where a matching image appears, at no extra cost, and matches show on the Results page. There is no setting to turn on. Page scans don’t include source lookup.
-
Does it work with Cloudflare or a CDN?
-
Usually. Media Library scans send the image URL, and if PixGuard can’t download it the plugin uploads the file instead. Page scans need PixGuard to load the page, so a firewall or bot protection that blocks it will stop page scans.
-
Does it work on a local or staging site?
-
Yes, for Media Library scans. When an image isn’t publicly reachable (LocalWP, MAMP, XAMPP, password-protected staging, HTTP Basic Auth), the plugin uploads the file directly instead of sending its URL. Page scans need a public URL.
-
Does a high score mean an image is infringing?
-
No. The score is an estimate based on copyright risk signals. Use it to decide which images to investigate: check your license records, and replace or license images you can’t account for.
Reviews
There are no reviews for this plugin.
Contributors & Developers
“PixGuard Scanner” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “PixGuard Scanner” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
1.1.0
- New: the PixGuard fox logo in the WordPress admin menu, plus a new plugin icon and banner.
- New: source lookup now follows your plan. On Pro and Business, Media Library and website scans of new images include it automatically, at no extra cost. The “Find Image Source” setting is removed.
- New: the Results page shows why each image was flagged, and where else it was found online when a source lookup ran.
- New: the dashboard and Settings show the free plan’s limits: up to 10 image scans a day and 30 in total, valid for 30 days after signup.
- New: Settings checks your API key against your account and shows the plan it belongs to. Previously it showed “Connected” for any key.
- Fix: “Scan All Media Library” stops when you run out of image scans or reach the daily limit, instead of trying every remaining image.
- Fix: page scans that run out of image scans partway now say so, instead of looking complete. Queued pages stop and wait instead of being marked Completed.
- Fix: images whose checks didn’t finish are no longer saved as scanned, so a later Scan All picks them up again.
- Fix: auto-scan on upload now runs after WordPress creates the image sizes, so large photos on local and staging sites can be scanned.
- Fix: scan cost copy. Each new image uses 1 image scan (it said 3), and free accounts get 30 (it said 100).
- Fix: the file-upload fallback no longer runs a second analysis after server errors, only when PixGuard couldn’t download the image.
- Fix: the “Scan All” count on the dashboard no longer includes SVG files, which can’t be scanned.
- Fix: the Results page High and Low filters now include critical and safe results, matching the dashboard counts.
- Fix: the Media Library screen no longer waits on the PixGuard API.
1.0.9
- Skip SVG files in Media Library scans. Vector graphics are not raster images, so they cannot be analyzed for copyright matches. The plugin now hides the scan button for SVG attachments and excludes them from “Scan All”.
1.0.8
- Fix: corrected the API key link to point at pixguard.io/settings (previous /dashboard/settings path was outdated).
- Tested up to WordPress 7.0.
1.0.7
- Hardening: every $wpdb query now passes the table name through prepare()’s %i identifier placeholder, clearing the strictest Plugin Check rules on modern WordPress (6.2+).
- Bump minimum WordPress to 6.2 (required for %i support).
1.0.6
- Hardening: every custom-table query now escapes the table name with esc_sql() and concatenates instead of string-interpolating, eliminating the remaining Plugin Check security warnings.
- Hardening: pagination input now sanitized with absint() instead of an int cast.
1.0.5
- Compliance: removed the legacy self-hosted plugin updater (forbidden for plugins listed on WordPress.org).
- Hardening: all admin form inputs are now unslashed before sanitization; pagination output is escaped; Results page queries use prepared statements end-to-end.
- Hardening: weekly report timestamps switched from date() to gmdate() to avoid timezone drift.
1.0.4
- Improved: “Scan All Media Library” on localhost/staging sites now skips the URL attempt entirely and uploads directly, scanning twice as fast and not wasting rate-limit quota.
- New: bulk scan now pauses and auto-resumes when the API rate limit is hit, instead of failing the rest of the queue.
1.0.3
- New: Media Library scans now work on LocalWP, MAMP, XAMPP, and password-protected staging sites. When the image URL isn’t reachable from our servers, the plugin uploads the file bytes directly as a fallback.
- Improved: clearer error messages when an image scan fails.
1.0.2
- Fix: “Manage Plan” and “Get API Key” links now use the correct www subdomain so they open the right page instead of the marketing homepage.
1.0.1
- New: “Scan All Media Library” one-click bulk action on the dashboard, with live progress and cancel.
- New: dashboard banner shows your current plan + remaining image scans (synced from your PixGuard account).
- Fix: corrected scan-cost copy (each scan uses up to 3 credits depending on features, not 1).
- Fix: use strpos() instead of str_starts_with() for PHP 7.4 compatibility.
1.0.0
- Initial release
- Page scanning with full AI analysis
- Media Library integration
- Auto-scan on upload
- Dashboard with risk summary
- Weekly email reports
