| 开发者 | mauricevanloon |
|---|---|
| 更新时间 | 2026年10月3日 20:16 |
| PHP版本: | 8.3 及以上 |
| WordPress版本: | 7.1 |
| 版权: | MIT |
| 版权网址: | 版权信息 |
wp tracefern check --all.openssl and mbstring extensions.Many plugins look for C2PA or IPTC metadata and label an image as AI-generated when they find it. Some count any C2PA manifest as AI, so a camera photo with Content Credentials is labelled AI-generated. Others read what the manifest claims without checking it, so an AI image that was changed after signing keeps its label. Tracefern verifies first: a camera photo stays a camera photo, and a changed image says "Does not verify" and loses the label. A few plugins verify too. Tracefern does it on the server, by itself, for every upload, and checks the signer against the bundled C2PA trust lists, so it can say "Verified" rather than only that the signature holds. It adds no badges to your pages; it gives you the verdict a label can rely on.
Both mean the file is exactly as it was signed. "Verified" also means the signer's certificate comes from an authority on the trust list, by default the C2PA conformance programme's list. "Intact" means nobody on that list vouches for who the signer is.
The file was changed after it was signed, for example by an editor or an
image optimizer that kept the old Content Credentials but rewrote the
image data (assertion.dataHash.mismatch in the details). An optimizer
that resizes the original on upload removes them: the image then shows
"No Content Credentials". Either way it also says "Changed after upload".
Most cameras and apps do not add them yet, and many services remove them when an image is shared or downloaded.
No. It shows what a verified manifest says about the image or the earlier versions it was made from, each of which must verify too. An AI image without Content Credentials gets no label. Next to "Intact: signer not trusted" the claim comes from a signer nobody on the trust list vouches for.
No. It only reads the original file and stores the result with the image. Settings → Privacy offers suggested text for your privacy policy.
The check runs in the background through WP-Cron, on the next request to
the site after the upload, usually within seconds. If WP-Cron is switched
off (DISABLE_WP_CRON), the checks run with the site's own cron job.
After an hour without a result the image shows "Not checked"; check it
again under Settings → Tracefern.
Its file was replaced after the check by something WordPress did not
report, such as another plugin or an upload over FTP. The old verdict no
longer applies, so none is shown; check it again with
wp tracefern check <ID>. An image edited in WordPress's own image
editor, or restored to its original, is checked again automatically. After
moving a site with a tool that does not keep file modification times, or
with media moved to external storage, every image can show this; check
them again with wp tracefern check --all. Images whose original another
plugin keeps in cloud storage are checked there, up to 64 MB.
JPEG, PNG and WebP. HEIC files are converted to JPEG by the browser before upload and arrive without their Content Credentials. Video and audio are not checked.
Under Settings → Tracefern, press "Check all images again"; the checks
run in the background. Or with WP-CLI: wp tracefern check --all, or
--state=Invalid,error, or attachment IDs; --dry-run shows what would
be checked.
Yes. Each site checks its own uploads and has its own settings. Deleting the plugin removes its data from every site of the network, in one request; on a network of thousands of sites, prefer WP-CLI.
Yes, through a filter, with no dependency on this plugin:
apply_filters( 'tracefern_verdict', null, $attachment_id ). It returns
null when the plugin is not active or the ID is not an attachment, and
otherwise an array: status (checked, pending, not_checked,
changed, unreadable), state, intact, trusted, ai (true
exactly when the Media Library shows "AI-generated (signed)"), ai_edited
(the same for "AI-edited (signed)"), signer,
signed_at, codes and more. signer comes from the file: escape it
where you output it.
The bundled verifier requires PHP 8.3 or later.