Linux 软件免费装
Banner图

Tracefern Image Check for C2PA

开发者 mauricevanloon
更新时间 2026年10月3日 20:16
PHP版本: 8.3 及以上
WordPress版本: 7.1
版权: MIT
版权网址: 版权信息

标签

media library ai c2pa content credentials provenance

下载

0.1.0 0.1.5 0.1.6 0.1.2 0.1.3 0.1.4 0.1.1 0.1.7 0.1.8

详情介绍:

Verified, not just detected. Finding a C2PA manifest in a file is easy; knowing whether it is genuine is not. A manifest can be copied onto another image, and an image can be changed after it was signed while its manifest still claims what it did before. Tracefern checks the signature, the hash that ties the manifest to the image's own bytes, and the signer's certificate against the C2PA trust lists. Only when the signature and the hash hold does it show "AI-generated (signed)", and only when the signer is also on the trust list does it say "Verified". Content Credentials (C2PA) are a signed record inside an image file: who made or edited it, with which tool, and whether generative AI was used. Tracefern Image Check for C2PA verifies that record for every JPEG, PNG and WebP you upload and shows the verdict where you already work with media. The verdicts: What it does not do: Verification is done by provemark/c2pa-verifier, a C2PA verifier written in PHP, bundled with the plugin.

安装:

  1. Install and activate the plugin. The server needs PHP 8.3 or later with the openssl and mbstring extensions.
  2. Upload images as usual. Each JPEG, PNG and WebP is checked in the background, usually within seconds; until then it shows "Check pending".
  3. Optional: under Settings → Tracefern, choose whether to trust DigiCert timestamps, or paste your own trust settings.
  4. Images uploaded before the plugin was active show "Not checked". Press "Check images that were never checked" under Settings → Tracefern.

屏幕截图:

  • The attachment details of a verified, AI-generated image.
  • Settings → Tracefern: the bundled trust list, DigiCert timestamps and custom trust settings.
  • The Media Library list filtered to AI-generated images, with the verdict filter above the list.

常见问题:

How is this different from plugins that label AI images?

Many plugins look for C2PA or IPTC metadata and label an image as AI-generated when they find it. Some count any C2PA manifest as AI, so a camera photo with Content Credentials is labelled AI-generated. Others read what the manifest claims without checking it, so an AI image that was changed after signing keeps its label. Tracefern verifies first: a camera photo stays a camera photo, and a changed image says "Does not verify" and loses the label. A few plugins verify too. Tracefern does it on the server, by itself, for every upload, and checks the signer against the bundled C2PA trust lists, so it can say "Verified" rather than only that the signature holds. It adds no badges to your pages; it gives you the verdict a label can rely on.

What is the difference between "Verified" and "Intact"?

Both mean the file is exactly as it was signed. "Verified" also means the signer's certificate comes from an authority on the trust list, by default the C2PA conformance programme's list. "Intact" means nobody on that list vouches for who the signer is.

Why does a genuine photo say "Does not verify"?

The file was changed after it was signed, for example by an editor or an image optimizer that kept the old Content Credentials but rewrote the image data (assertion.dataHash.mismatch in the details). An optimizer that resizes the original on upload removes them: the image then shows "No Content Credentials". Either way it also says "Changed after upload".

Why do most of my images show "No Content Credentials"?

Most cameras and apps do not add them yet, and many services remove them when an image is shared or downloaded.

Does "AI-generated (signed)" detect AI images?

No. It shows what a verified manifest says about the image or the earlier versions it was made from, each of which must verify too. An AI image without Content Credentials gets no label. Next to "Intact: signer not trusted" the claim comes from a signer nobody on the trust list vouches for.

Does it change my images or send data anywhere?

No. It only reads the original file and stores the result with the image. Settings → Privacy offers suggested text for your privacy policy.

Why does an image say "Check pending"?

The check runs in the background through WP-Cron, on the next request to the site after the upload, usually within seconds. If WP-Cron is switched off (DISABLE_WP_CRON), the checks run with the site's own cron job. After an hour without a result the image shows "Not checked"; check it again under Settings → Tracefern.

Why does an image say "Changed since its check"?

Its file was replaced after the check by something WordPress did not report, such as another plugin or an upload over FTP. The old verdict no longer applies, so none is shown; check it again with wp tracefern check <ID>. An image edited in WordPress's own image editor, or restored to its original, is checked again automatically. After moving a site with a tool that does not keep file modification times, or with media moved to external storage, every image can show this; check them again with wp tracefern check --all. Images whose original another plugin keeps in cloud storage are checked there, up to 64 MB.

Which formats are checked?

JPEG, PNG and WebP. HEIC files are converted to JPEG by the browser before upload and arrive without their Content Credentials. Video and audio are not checked.

How do I check images again after changing the trust settings?

Under Settings → Tracefern, press "Check all images again"; the checks run in the background. Or with WP-CLI: wp tracefern check --all, or --state=Invalid,error, or attachment IDs; --dry-run shows what would be checked.

Does it work on multisite?

Yes. Each site checks its own uploads and has its own settings. Deleting the plugin removes its data from every site of the network, in one request; on a network of thousands of sites, prefer WP-CLI.

Can other plugins use the verdict?

Yes, through a filter, with no dependency on this plugin: apply_filters( 'tracefern_verdict', null, $attachment_id ). It returns null when the plugin is not active or the ID is not an attachment, and otherwise an array: status (checked, pending, not_checked, changed, unreadable), state, intact, trusted, ai (true exactly when the Media Library shows "AI-generated (signed)"), ai_edited (the same for "AI-edited (signed)"), signer, signed_at, codes and more. signer comes from the file: escape it where you output it.

Why PHP 8.3?

The bundled verifier requires PHP 8.3 or later.

更新日志:

0.1.8 Earlier versions: https://github.com/provemark/tracefern-image-check/releases