{"id":376738,"date":"2026-09-29T00:55:07","date_gmt":"2026-09-29T00:55:07","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/contentproof-content-credentials-media-provenance\/"},"modified":"2026-09-29T00:53:23","modified_gmt":"2026-09-29T00:53:23","slug":"jazx-media-provenance-inspector","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/jazx-media-provenance-inspector\/","author":23558679,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.3.4","stable_tag":"0.3.4","tested":"7.1.2","requires":"6.2","requires_php":"7.4","requires_plugins":null,"header_name":"JAZ-X Media Provenance Inspector","header_author":"JAZ-X Innovation","header_description":"Inspect C2PA provenance, inventory media hashes, and track credential loss across WordPress image derivatives.","assets_banners_color":"","last_updated":"2026-09-29 00:53:23","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/www.jazx.online\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":54,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.3.4":{"tag":"0.3.4","author":"jazxinnovation","date":"2026-09-29 00:53:23","revision":3718088}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3718087,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3718087,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.3.4"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[225241,274596,84,261422,712],"plugin_category":[50],"plugin_contributors":[279727],"plugin_business_model":[],"class_list":["post-376738","plugin","type-plugin","status-publish","hentry","plugin_tags-authenticity","plugin_tags-c2pa","plugin_tags-media","plugin_tags-provenance","plugin_tags-verification","plugin_category-media","plugin_contributors-jazxinnovation","plugin_committers-jazxinnovation"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/jazx-media-provenance-inspector\/assets\/icon-128x128.png?rev=3718087","icon_2x":"https:\/\/ps.w.org\/jazx-media-provenance-inspector\/assets\/icon-256x256.png?rev=3718087","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>JAZ-X Media Provenance Inspector helps WordPress administrators inventory media provenance and inspect C2PA metadata and credentials.<\/p>\n\n<p>This is an independent plugin by JAZ-X Innovation. It is not affiliated with or endorsed by the Coalition for Content Provenance and Authenticity (C2PA) or the Content Authenticity Initiative.<\/p>\n\n<p>Core features:<\/p>\n\n<ul>\n<li>SHA-256 hashing of original media and generated image sizes.<\/li>\n<li>Original and derivative inventory in dedicated database tables.<\/li>\n<li>C2PA marker detection separated from generic JUMBF-only metadata.<\/li>\n<li>Credential-loss warnings when a C2PA-bearing original produces WordPress derivatives that no longer contain the original credential marker.<\/li>\n<li>Browser-side cryptographic C2PA verification using a locally bundled SDK and WebAssembly runtime.<\/li>\n<li>Validation states for Trusted, Valid \/ untrusted, Invalid, No valid manifest, and Verification error. Trusted may remain visible on stored results produced with a previously configured trust source.<\/li>\n<li>Human-readable explanations for common integrity and trust findings.<\/li>\n<li>Manifest label\/title, claim generator, signer, issuer, signature time, and validation-code capture where supplied by the verifier.<\/li>\n<li>Media Library status column and an administrator-only JAZ-X Media Provenance Inspector dashboard.<\/li>\n<li>Large-library scanning in safe 50-item AJAX batches with Pause\/Resume and refresh-safe state.<\/li>\n<li>JFIF\/JPE support as part of the JPEG family.<\/li>\n<li>Separate Unsupported, Missing source, Scan error, and Other JUMBF classifications.<\/li>\n<\/ul>\n\n<p>JAZ-X Media Provenance Inspector 0.3.4 packages <code>@contentauth\/c2pa-web<\/code> 0.15.1 and its matching WASM runtime inside the plugin. It does not load third-party executable JavaScript or WASM for cryptographic verification.<\/p>\n\n<p>Media bytes are fetched from the same WordPress origin and processed in the administrator's browser. JAZ-X Media Provenance Inspector does not upload media bytes to any JAZ-X service. Cross-origin attachment URLs (for example, some CDN\/offload configurations) are not fetched by the verifier in this release.<\/p>\n\n<p>Remote manifest fetching, OCSP lookups, and external trust-list requests are disabled in this release. Local integrity verification remains fully available without an external verification-data request.<\/p>\n\n<h4>Third-party code and source<\/h4>\n\n<p>JAZ-X Media Provenance Inspector includes GPL-compatible third-party dependencies under <code>vendor\/c2pa\/<\/code>. License copies and version\/integrity information are included in <code>THIRD-PARTY-NOTICES.txt<\/code> and <code>vendor\/c2pa\/licenses\/<\/code>.<\/p>\n\n<p>The bundled C2PA browser runtime is built from:<\/p>\n\n<ul>\n<li><code>@contentauth\/c2pa-web<\/code> 0.15.1 \u2014 MIT license<\/li>\n<li><code>@contentauth\/c2pa-wasm<\/code> 0.13.0 \u2014 MIT license<\/li>\n<li><code>@contentauth\/c2pa-types<\/code> 0.7.4 \u2014 MIT license<\/li>\n<li><code>@contentauth\/c2pa-utilities<\/code> 0.3.0 \u2014 MIT license<\/li>\n<li><code>highgain<\/code> 0.1.0 \u2014 ISC license<\/li>\n<\/ul>\n\n<p>Upstream C2PA source code:\nhttps:\/\/github.com\/contentauth\/c2pa-js<\/p>\n\n<p>Highgain package distribution:\nhttps:\/\/www.npmjs.com\/package\/highgain\/v\/0.1.0<\/p>\n\n<p>The included <code>highgain.js<\/code> is the small readable ESM distribution from that package; its package metadata and ISC license are included alongside it.<\/p>\n\n<p>The distributed <code>c2pa-web.runtime.js<\/code> is the upstream npm distribution with one browser-resolution-only change: the bare <code>highgain<\/code> import is rewritten to the local <code>.\/highgain.js<\/code> path. The local index file points to that renamed runtime chunk. Exact package versions and npm integrity values are recorded in <code>vendor\/c2pa\/VERSIONS.txt<\/code>.<\/p>\n\n<p>Reproduction outline:<\/p>\n\n<ol>\n<li>Install Node.js and npm.<\/li>\n<li>Run <code>npm install @contentauth\/c2pa-web@0.15.1 highgain@0.1.0<\/code>.<\/li>\n<li>Copy the package's <code>dist\/index.js<\/code>, runtime chunk, worker, and <code>dist\/resources\/c2pa_bg.wasm<\/code> into <code>vendor\/c2pa\/<\/code>.<\/li>\n<li>Rewrite the runtime's bare <code>highgain<\/code> import to <code>.\/highgain.js<\/code>, rewrite the index runtime import to the local renamed chunk, and use <code>c2pa-web.bundle.js<\/code> as the small JAZ-X Media Provenance Inspector entry module.<\/li>\n<\/ol>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin ZIP in Plugins &gt; Add New &gt; Upload Plugin, or install it from WordPress.org when available.<\/li>\n<li>Activate JAZ-X Media Provenance Inspector.<\/li>\n<li>Open JAZ-X Media Provenance Inspector in the WordPress admin menu. The dashboard is restricted to users with the <code>manage_options<\/code> capability by default.<\/li>\n<li>Scan the Media Library. Automatic mode works in 50-item batches and can be paused and resumed.<\/li>\n<li>When C2PA-bearing media is detected, use the cryptographic verification controls.<\/li>\n<li>Review the human-readable integrity findings and derivative credential-loss status.<\/li>\n<\/ol>\n\n<p>Upgrades preserve existing JAZ-X Media Provenance Inspector scan and verification records. A full Media Library rescan is not required when upgrading from 0.3.0 or later to 0.3.4.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20jaz-x%20media%20provenance%20inspector%20upload%20my%20images%20to%20an%20external%20service%3F\"><h3>Does JAZ-X Media Provenance Inspector upload my images to an external service?<\/h3><\/dt>\n<dd><p>No. Media bytes are fetched from the same WordPress origin and processed in the administrator's browser by the locally packaged C2PA SDK\/WASM runtime. Cross-origin media URLs are blocked by the verifier in this release.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20contact%20external%20verification%20services%3F\"><h3>Does the plugin contact external verification services?<\/h3><\/dt>\n<dd><p>No. JAZ-X Media Provenance Inspector 0.3.4 does not make external trust-list, remote-manifest, or OCSP requests. WordPress itself may make its normal core requests independently of this plugin.<\/p><\/dd>\n<dt id=\"what%20does%20invalid%20mean%3F\"><h3>What does Invalid mean?<\/h3><\/dt>\n<dd><p>It means the C2PA verifier reported a validation failure. For example, <code>assertion.dataHash.mismatch<\/code> means the current asset bytes do not match the bytes covered by the signed data-hash assertion. It should not be interpreted by itself as a claim about why the file changed.<\/p><\/dd>\n<dt id=\"what%20does%20valid%20%2F%20untrusted%20mean%3F\"><h3>What does Valid \/ untrusted mean?<\/h3><\/dt>\n<dd><p>Cryptographic validation passed, but JAZ-X Media Provenance Inspector did not establish signer trust. JAZ-X Media Provenance Inspector 0.3.4 does not make an external trust-list request, so it does not newly claim official C2PA trust-list status. Previously stored results from an earlier configured trust evaluation are preserved until an asset is verified again.<\/p><\/dd>\n<dt id=\"what%20does%20other%20jumbf%20metadata%20mean%3F\"><h3>What does Other JUMBF metadata mean?<\/h3><\/dt>\n<dd><p>JUMBF is a generic metadata container. A generic JUMBF marker alone is not treated as confirmation that the file contains a valid C2PA manifest.<\/p><\/dd>\n<dt id=\"what%20is%20stored%20in%20the%20database%3F\"><h3>What is stored in the database?<\/h3><\/dt>\n<dd><p>JAZ-X Media Provenance Inspector stores attachment identifiers, relative media paths, MIME\/dimension data, SHA-256 hashes, scan\/verification status, selected C2PA manifest metadata, validation codes, derivative records, timestamps, and errors needed for the audit dashboard.<\/p><\/dd>\n<dt id=\"what%20happens%20to%20data%20on%20uninstall%3F\"><h3>What happens to data on uninstall?<\/h3><\/dt>\n<dd><p>JAZ-X Media Provenance Inspector currently preserves the two audit tables on uninstall so provenance history is not silently destroyed. Operational options and per-user bulk-scan state are removed. A future release may add an explicit delete-audit-data setting.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>0.3.4<\/h4>\n\n<ul>\n<li>Updated the public plugin name and WordPress.org slug metadata to JAZ-X Media Provenance Inspector.<\/li>\n<li>Shortened the plugin header description and removed the non-unique Plugin URI.<\/li>\n<li>Replaced candidate-stage wording with final-release wording.<\/li>\n<li>Moved older release history to <code>changelog.txt<\/code> to keep this readme compact.<\/li>\n<li>No database schema or verification-engine change; existing scan and verification records are retained.<\/li>\n<\/ul>\n\n<h4>0.3.3<\/h4>\n\n<ul>\n<li>Reworked prepared database calls so Plugin Check can statically recognize the inline <code>wpdb::prepare()<\/code> calls instead of seeing intermediate query variables.<\/li>\n<li>Kept <code>%i<\/code> identifier placeholders for custom and core table names; minimum WordPress remains 6.2.<\/li>\n<li>Added narrow PHPCS no-cache rationale to the three remaining write-through audit-table operations reported by Plugin Check.<\/li>\n<li>No database schema change; existing scan and verification records are retained.<\/li>\n<\/ul>\n\n<p>Older release history is available in <code>changelog.txt<\/code>.<\/p>","raw_excerpt":"Inspect WordPress media provenance, track derivative credential loss, and verify C2PA data locally in the browser.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/376738","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=376738"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/jazxinnovation"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=376738"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=376738"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=376738"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=376738"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=376738"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=376738"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}