RobArt Image Guard

Description

Every image you publish is, the moment it loads, a full-resolution file sitting on a public server — free for anyone, and any automated scraper, to take. Image Guard changes that. Your original master is moved to a private store the public web can’t reach; visitors are served a controlled, resolution-limited copy through a signed delivery endpoint, so your page source never contains a link to your real file. Automated bulk harvesting — the cause of most real-world image theft — simply fails.

Image Guard is honest about what it can and can’t do. No software can make an image on a screen impossible to capture (a screenshot always works), and Image Guard never pretends otherwise. What it does is keep your high-resolution master genuinely private, make casual and automated copying fail, and give you a real evidence trail for the rare deliberate theft that gets through.

What you get

  • Private master, controlled copy. Your original is moved to a private store you choose during setup — a folder outside your public website is recommended, where no web address can reach it at all; the public only ever receives a placeholder that a small script swaps for a resolution-limited copy at runtime. The master URL never appears on the page.
  • Bulk scraping fails. Automated bots that harvest whole catalogues collect placeholders, not your originals — the economics of scraping at scale stop working.
  • WooCommerce and page builders. Protection works across WooCommerce product galleries (main image, thumbnails, click-to-enlarge, hover-zoom) and page builders such as Elementor (galleries, carousels, lightboxes).
  • Right-click deterrent. Optionally suppress the right-click menu on protected images and swap in a “protected” card, so a casual save grabs nothing useful.
  • Nothing real is public. By default a protected image publishes only the grey placeholder — no usable copy of your work is exposed, so it can’t be scraped from the page. Your master stays private either way.
  • Search previews (Pro). If you want a protected image to still appear in image search, Pro lets you publish a small, heavily watermarked “search preview” per image — a deliberate trade-off, described as licensable to search engines. The free plugin keeps every image at maximum protection.
  • Watermarks. Bake a visible text or logo watermark into what’s delivered. (An optional invisible forensic mark for traceability is a Pro feature.)
  • Copyright data (Pro). Embed your copyright into the image’s own metadata (readable, signed and tamper-evident, or encrypted), including a full IPTC/XMP metadata editor.
  • Evidence certificate (Pro). Generate a printable certificate recording your claim and a cryptographic fingerprint of your original, captured at protection time.
  • Find and prove infringement (Pro). Drop an image you found in the wild and Image Guard checks it against your protected originals, then helps you build a dated evidence record for a takedown or claim.

Who it’s for

Photographers, illustrators, artists, designers, and shop owners — anyone who publishes images they’d rather not hand out at full resolution to every scraper on the web, and who wants a genuine evidence trail if a copy turns up.

Free and Pro

Image Guard is free and fully usable on its own. The free plugin gives you the complete protection pipeline — moving your master to a private store, serving controlled reduced-resolution copies through a signed endpoint, a visible text or logo watermark, the right-click deterrent, and WooCommerce and page-builder support. Every protected image is kept at maximum protection: only the grey placeholder is public. An optional Pro upgrade adds the per-image search previews (publish a small, watermarked crawlable copy so a work can still appear in image search), the IPTC/XMP copyright-metadata editor, the invisible forensic mark, the evidence certificate, the Verify tool (drop a found image to check it against your protected originals), bulk protection (up to ten images at a time in a review carousel), and auto-protection of new uploads.

Uninstall

Image Guard cleans up after itself. When you delete the plugin from the Plugins screen (if you have enabled “Remove data on uninstall” in Settings) it removes everything it created: its settings and options, its cached licence-tier value, the private master store (your protected originals), the placeholder images it generated, and the now-empty Media Library entries for those placeholders. Deactivating keeps everything; only deleting runs the clean-up. This does not restore your originals to the Media Library first, so unprotect any images you want to keep before deleting, and always keep your own copies of your originals.

External services

Image Guard does its protection, watermarking, metadata and evidence work locally on your own server — it serves images from your site and makes no analytics or tracking requests anywhere.

Two features contact outside services, and only when you choose to use them:

  • Verified timestamps (optional). If you ask for a verified timestamp on your copyright metadata or certificate, Image Guard requests a signed timestamp token from a public RFC 3161 Timestamping Authority (TSA) you configure. Only a cryptographic hash of your claim is sent — never your image. If the TSA can’t be reached, it falls back to a local timestamp rather than failing.
  • Pro licensing (optional). If you enter a Pro licence key to upgrade, the key is validated against the licensing service. This happens only when you activate or check a licence; the free plugin makes no such request.

The plugin also makes one local self-check when you choose a private-store location: it writes a small probe file into that folder and requests it back through your own site’s URL, purely to confirm the folder is not publicly reachable. This request goes only to your own site — no third party is contacted, and no personal data is sent. It runs only when you set or change the store location.

Screenshots

Installation

  1. Upload the plugin to /wp-content/plugins/robart-image-guard, or install it from the Plugins screen in your WordPress admin.
  2. Activate it through the Plugins menu in WordPress.
  3. Open the RobArt Image Guard menu. A short welcome walks you through how protection works; then protect your first image from the Protect Images page or straight from the Media Library.

FAQ

Does this make my images impossible to copy?

No — and we won’t pretend it does. Anyone who can see an image on screen can ultimately capture it (a screenshot always works), on any website. What Image Guard guarantees is that your high-resolution master never becomes public, that automated bulk scraping fails, and that anything a determined person does capture is a reduced, watermarked, traceable copy backed by your evidence trail. The manual includes an honest, scored breakdown of how well it protects against a casual saver, a scraper, and a determined thief.

Will it work with my theme, WooCommerce, and page builders?

Yes. Protection is applied to the images your pages actually render, so it works with standard WordPress output, WooCommerce product galleries, and page builders such as Elementor — including their zoom, thumbnail and lightbox behaviours, which Image Guard handles itself for consistency.

What does a visitor actually see?

Exactly your image, at the size your page shows it — but delivered as a controlled, resolution-limited copy, optionally watermarked. Your original high-resolution file is never sent to the browser and never appears in the page source.

Can protected images still appear in Google Images?

Not in the free plugin: a protected image publishes nothing real, so it won’t appear in image search. With Pro you can opt a specific image into a “Search preview” that publishes a small, heavily watermarked copy so the work can be found and shown as licensable — a deliberate trade-off the plugin explains at the point you make it. Your master stays private in every mode.

Does it send my images anywhere?

No. Your images are processed on your own server and never sent to any third party. The only outbound requests are optional: a hash-only request to a timestamping authority if you use verified timestamps, and a licence check if you enter a Pro key. See “External services”.

What language does it appear in?

Image Guard follows your WordPress site language (Settings General) and is fully translatable.

Does deleting the plugin remove its data?

Yes, if you enable it — see the “Uninstall” section. Deleting also removes the private masters Image Guard was storing, so keep your own copies of your originals.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“RobArt Image Guard” is open source software. The following people have contributed to this plugin.

Contributors

Translate “RobArt Image Guard” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.

Changelog

0.15.3

  • Documentation accuracy: the readme now correctly presents the per-image search-visibility levels (Search preview / Abstract) as a Pro feature. The free plugin keeps every protected image at maximum protection — only the grey placeholder is public — which is exactly what the free code does. No functional change; this corrects the earlier description, which listed search previews as a free feature when the preview generator ships only with Pro.

0.15.2

  • Documentation accuracy: the readme now matches the plugin’s real free/Pro split. The evidence certificate, the Verify tool, the invisible forensic mark, and the IPTC/XMP copyright-metadata editor are Pro features; the free plugin provides the complete protection pipeline — private master store, signed reduced-resolution delivery, a visible text or logo watermark, the right-click deterrent, per-image search visibility, and WooCommerce/page-builder support.
  • Housekeeping: the XMP-writer engine (used only by the Pro metadata editor) now ships inside the Pro folder rather than the free build. No change to any feature.

0.15.1

  • Hardened the built-in documentation renderer: all text is HTML-escaped before formatting and links are passed through esc_url(), so the bundled help docs cannot introduce unsafe markup. Defensive hardening — the renderer only ever processes the plugin’s own documentation.

0.15.0

  • Delivery: protected images now lazy-load — each is fetched only as it scrolls near the viewport, which speeds up pages with many protected images and spreads out the requests. A new “Lazy-load protected images” setting lets you turn this off. When a page’s images do need fresh delivery tokens, they are now requested in a single batch rather than one at a time.
  • Security & compatibility hardening for the WordPress.org review: the private store now stores masters purely as inert data files and uses an inert directory guard (no executable files are written into the uploads area); the image-delivery endpoints return a single uniform response for any refused request (so they never reveal which images are protected) and rate-limit token requests. No change to what you see — protected images are delivered exactly as before.

0.14.1

  • Storage compliance: your protected originals are now kept as plain image data files (no executable files are ever written), and any existing files are converted automatically on update. Font files are stored only in the plugin’s own uploads sub-folder.
  • Setup now clearly recommends storing your originals in a folder outside your public website for the strongest privacy, with the uploads folder offered as a convenient but weaker choice — each option is tested and confirmed before it is used.

0.14.0

  • Protected images in cropped galleries (for example a square thumbnail grid) now match your other thumbnails exactly — same shape, clean uniform rows.
  • The right-click “protected” card now stays visible for as long as you hold the button, instead of flashing away after a moment.

0.13.0

  • Choose where your private store lives. Setup now lets you keep your originals in a protected uploads folder (recommended, works everywhere) or in a folder outside your public website — and the plugin tests the location and confirms it is truly private before saving.
  • New: right-click deterrent card picker. Choose the message shown when someone tries to right-click or drag-save a protected image — from three bundled cards.
  • Setup now strongly recommends storing your originals in a folder outside your public website — the only genuinely private location on every server — with the uploads folder offered as a convenient but weaker fallback, clearly labelled.
  • Cleaner uninstall: with “Remove data on uninstall” enabled, deleting the plugin now also removes the private store, the placeholder images it generated, and their now-empty Media Library entries — a complete clean-up.
  • Your settings and protected images carry over automatically on update.

0.12.5

  • Internal rename of the plugin’s code prefix to meet WordPress.org guidelines. Your settings and protected images are migrated automatically on update — nothing to do.
  • Fonts you upload are now kept in the plugin’s own storage area; on newer WordPress the standard Font Library location is used.
  • Small housekeeping: the fonts path shown in Settings now respects a custom content directory, and the front-end page buffer is closed explicitly.

0.12.4

  • Housekeeping: trimmed the changelog shown here to recent releases (the full history is on GitHub), and a final review-scan tidy. No change to how the plugin works.

0.12.3

  • Every way of protecting an image now ends with the same clear “Image protected” confirmation — single protect, bulk protect, and protecting straight from the Media Library.

0.12.2

  • Code-quality and standards pass: the plugin now passes the WordPress.org plugin review scan cleanly — all output is escaped through core functions, all inputs are sanitised, admin actions carry inline capability and nonce checks, and REST endpoints use proper permission checks. No change to how the plugin works.

0.12.1

  • Smaller infringement evidence documents: the found (suspect) image is now resized and compressed before it is added to the record, cutting the saved file size substantially.
  • The Attachment Details panel now shows your copyright registration details (registered name, number, authority, country and date) when you have entered them, matching what appears on the certificate.
  • Code-quality and standards pass: the plugin now runs cleanly through the WordPress Plugin Check with no outstanding issues, plus internal hardening. No change to how it works.

0.12.0

  • New: automatic image sizing (resize + WebP). Full-resolution originals are far larger than any website needs. Image Guard now saves every protected image as WebP for a much smaller file, and can optionally downscale a large image before protecting it — so the stored, protected copy is smaller and your true original never leaves your computer. There is a global setting (Settings Image sizing) and a per-image tickbox when you protect, offered only for images larger than your chosen size (1600px by default). Smaller images are never enlarged.
  • Much smaller certificate and evidence documents. The images embedded in a copyright certificate or an infringement evidence record are now resized and WebP-compressed, cutting the saved PDF from several megabytes to a fraction of the size. Both are on by default and can be turned off in Settings if you prefer full-size images.
  • Lightbox and drag protection. With the right-click deterrent on, protected images can no longer be dragged out to the desktop or into a new tab — including images opened in the built-in lightbox. (This deters casual copying only; a determined viewer can still capture what they see.)
  • Tidier Settings. The long General panel is split into focused cards — General, Display & search, Image sizing, and Protection & data — so the page reads cleanly.
  • Fixes: search-visibility previews are now correctly a Pro feature and no longer appear inactive in the free build; the bulk-protect review carousel now offers the same per-image search visibility, copyright details and live preview as single protect; a blank watermark now falls back to your default copyright line; the certificate signature button now enables straight away when opened from a “View certificate” link; and the XMP editor’s buttons are now Apply and Cancel.

0.11.1

  • Right-click deterrent, upgraded. When someone right-clicks a protected image, it now swaps for a friendly “Nice try — this image is protected” card the instant the button is pressed, so anything copied or saved is the card, not your image. It also closes a Firefox quirk (Shift + right-click) that could otherwise bypass the block, and restores your image cleanly the moment the menu closes.
  • New in the manual: an honest security scorecard. A plain, scored-out-of-ten breakdown of how well the plugin protects against a casual saver, an automated scraper, and a determined thief — including how much each protection layer raises the score — with no overclaiming.
  • The welcome screen now mentions the wider toolkit (watermarks, forensic marks, copyright data, certificates and finding copies), not just the anti-scraping core.

Earlier versions

For older releases, see the full development changelog on the plugin’s GitHub repository.