| 开发者 | contexlabs |
|---|---|
| 更新时间 | 2026年10月2日 19:25 |
| PHP版本: | 7.4 及以上 |
| WordPress版本: | 7.1 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
transparai_label_media filter, and an optional script also labels images printed without an attachment ID and CSS backgrounds. Page-cache plugins are told to refresh whenever a label changes.
Machine-readable AI labeling, structured data and SEO
For labeled files TransparAI writes the IPTC digital source type (trainedAlgorithmicMedia, or compositeWithTrainedAlgorithmicMedia for AI-edited media) as XMP into JPEG, PNG, WebP and AVIF, every size variant included. Google documents this field and can show an "AI-generated" label in Google Image Search, so the disclosure travels with the image wherever it is indexed. Each page additionally carries Schema.org JSON-LD structured data (ImageObject, VideoObject, AudioObject and an Article node for AI-written posts) with digitalSourceType both as the Schema.org enumeration and as the IPTC vocabulary URI, so search engines and AI crawlers get the declaration without opening a file. All of it is server-rendered with no extra request and no layout shift, so the SEO signals arrive without a Core Web Vitals cost. The same declarations serve GEO (generative engine optimization): AI search and answer engines such as Google AI Overviews, ChatGPT search and Perplexity weigh structured data and provenance signals when they decide what to cite. Existing metadata is merged, not replaced; unlabeling removes exactly what the plugin wrote; writes are atomic and validated. Because image optimizers and thumbnail regeneration strip metadata, every labeled file is fingerprinted and an hourly sweep restores missing declarations.
Camera photos and human work
Not every declaration says "AI". Any media file can be declared as a camera photo (digitalCapture) or as human digital work (digitalCreation), from the attachment details, in bulk, or with WP-CLI. The declaration ends any AI label or pending detection, appears in the structured data, and is written into the file, but only where no other digital source type exists: a camera's own declaration stays untouched. A "Human made" badge is optional and off by default.
AI-written text: disclosure levels per post
Every post, page and public custom post type carries an AI level for its text: no AI used, AI-assisted, AI-generated, or AI-generated and reviewed by a person. Set it in the block editor sidebar, the classic meta box, Quick Edit or Bulk Edit; the post list gets a sortable column and a filter, the AI Content screen sums it up per post type. AI levels show a configurable note ahead of the content, after it or on both sides, as a block, an inline note, a dismissible banner, a badge or a button that opens a dialog, plus an optional AI badge behind the post title. Five blocks (AI Notice, AI Image Label, AI Systems Notice, AI Systems List, Chatbot AI Notice) and the [transparai_notice] shortcode place every notice by hand; "only where a block or shortcode is placed" switches the automatic output off. Reviewed texts record the reviewer, the date and a fingerprint of the content, so a later edit shows as "changed since review". The note can go into excerpts and RSS feed items, including a dc:description element and an optional [AI] prefix on feed titles.
Chatbot disclosure
Chatbot transparency is the Article 50 duty every visitor notices first: people must know when they talk to an AI system. TransparAI puts that notice into the first message of the bot for AI Engine, next to the chat launcher for every other widget, or as a line at the end of each page. Your answer decides whether it appears and who answers in the chat; the plugin recognizes more than 40 chat and chatbot vendors locally (plugins, theme snippets, registered scripts, your own browser as administrator) and tells you what it found, but never switches the notice on from a finding alone, because a live chat with a person behind it is not an AI system.
Audit trail, compliance report, REST API, WP-CLI
Every label, review decision, declaration and repair is recorded per file with time, previous state, trigger and the editor's name, plus a site log of settings changes, scans, sweeps, bulk actions and declarations that the dashboard shows as recent activity. Export the whole library as a CSV audit list, or open the compliance report: a print view with the readiness score, the assessment answers, the Article 4 checklist, the AI systems in use, the state of every disclosure notice, the AI-written content, the media audit list and the recent activity, sealed with a document hash over the facts, the guidance basis and the stated limitations, ready for print-to-PDF. A REST API under transparai/v1 exposes rows, per-file detail, every action and the same report for headless setups and agency tooling; nothing in it is public. WP-CLI covers scanning, labeling, declaring, auditing, the score, the assessment, the AI systems inventory, the AI levels of posts and the report. Other plugins can label media through an action, detection rules and the AI systems list are extensible via filters, WPML and Polylang are configured, and uninstalling cleans up across a multisite network on request.
Privacy by design
The plugin runs entirely on your server: no accounts, no telemetry, no external requests, and the list of AI tools ships with the plugin instead of being fetched. The only HTTP request it can make is the optional delivery check, which asks your own site for one image to see whether your CDN strips the declaration. The interface ships in 16 languages (English, German in both forms, Austrian German, French, Spanish, Italian, Dutch, Polish, Portuguese, Swedish, Danish, Finnish, Czech, Romanian, Greek and Hungarian), and a suggested paragraph for your privacy policy appears in the WordPress policy guide. Please also read the Disclaimer section.
Contact: TransparAI@cms-admins.de
exiftool -XMP-iptcExt:DigitalSourceType image.jpg), and the hourly sweep restores metadata that optimizers strip.No, and no plugin can. Detection relies on metadata that generators embed. Images whose metadata was stripped (social media re-uploads, screenshots, clipboard pastes) carry no signals. Invisible pixel watermarks such as Google SynthID can only be verified by the vendor's own service; TransparAI does not pretend otherwise. Detected metadata is an indication, not cryptographic proof. That is exactly why the review queue exists.
Anything that leaves a standard marking in the file. In practice that covers ChatGPT and DALL-E, GPT-Image, Google Gemini including Nano Banana output, Adobe Firefly and Photoshop Generative Fill, Bing Image Creator, Midjourney, Stable Diffusion (AUTOMATIC1111, ComfyUI, InvokeAI, SwarmUI, Fooocus), NovelAI, Flux by Black Forest Labs, Leonardo.Ai, Ideogram, Recraft and Seedream, plus every tool that writes a C2PA manifest or the IPTC digital source type, which is the direction the whole industry is moving in. New signatures can be added with a filter, no code fork needed. TransparAI is an independent plugin and is not affiliated with any of these vendors, nor with the makers of the plugins in its AI systems list.
Usually not, and the plugin does not pretend otherwise. As a site operator you are a deployer under the EU AI Act. Article 50(4) asks deployers to disclose deepfakes: AI-generated or AI-manipulated images that look like real people, places, objects or events and could pass for genuine, which includes realistic product shots and stock-style photos. An obvious illustration, a cartoon or a clearly artistic image is not a deepfake, and content published before 2 August 2026 is not covered retroactively. The machine-readable marking that Article 50(2) requires is the duty of the provider of the generator; the plugin writes it into your files so it is not lost on your site, and the review queue shows three questions that help you decide about the visible label. None of this is legal advice.
Article 50 has applied since 2 August 2026. The Commission published the final Code of Practice on Transparency of AI-Generated Content together with the EU icons on 10 June 2026 and its guidelines on Article 50 on 20 July 2026. The Digital Omnibus in force since 27 July 2026 gives providers of generators that were already on the market until 2 December 2026 to add the machine-readable marking; there is no such grace period for the visible disclosure by deployers.
Yes, as a badge style. The icons are the ones the European Commission published on 10 June 2026 (Fully AI-generated, Partially AI-modified and the basic AI icon, each in black and white), bundled unchanged. The Commission allows anyone to use them free of charge and without attribution. Using the icons is optional, it does not make your site a signatory of the Code of Practice, and neither the icons nor the plugin certify compliance.
Partly, and it says exactly which part. For every file with a C2PA manifest the plugin reads the manifest itself and checks whether its data hash still covers the file bytes, so a manifest that was copied from another file or that outlived an edit is caught and goes to the review queue instead of labeling automatically. It also shows the signer, the claim generator and the action time named in the manifest. It does not verify the signature, the certificate chain or any trust list; everything it shows is "according to the manifest", and the attachment panel says so.
WordPress re-encodes every size variant it generates, and that drops the C2PA manifest of the original; the same happens in image optimizers. The attachment panel and wp transparai verify-meta name how many files of an attachment lack the manifest. The IPTC digital source type this plugin writes is not affected: it goes into every size and is restored after optimizers strip it.
It gives you the technical building blocks Article 50 asks for (a visible disclosure and a machine-readable marking) and documents your decisions, but whether and how the EU AI Act or any other law applies to your site, and whether your specific setup satisfies it, is a legal question only you (or your lawyer) can answer. The readiness score is a self-check, not a verdict. See the Disclaimer section.
It is the share of checks that are done, each check being something the plugin can verify in its own state: AI-written posts carry a level (or you declared that none exist), labeled media exist and nothing waits in the review queue, the chatbot question is answered, the AI systems are inventoried with a visibility decision, and the self-assessment and Article 4 checklist are complete. 100 means every technical building block is in place and documented. It does not mean your site is compliant; the Disclaimer applies.
Six yes-or-no questions about how your site uses AI: chatbot, AI-written text, AI images, personalisation, translation and synthetic media. The answers list the obligations likely to apply, with the article of the EU AI Act and the plugin page that addresses each one. Answers are stored on your site with the name of the person who saved them, are editable any time and appear in the compliance report.
Article 4 asks providers and deployers for measures, as far as they can, toward a sufficient level of AI literacy of the people who operate or use AI systems on their behalf; it prescribes no training format or certificate. The five items are the measures that usually serve as evidence: staff know which AI tools are in use, an internal policy is written down, people who work with AI tools have had guidance, a review date is set, and the context of use and the people affected were considered. Tick what applies; the checklist counts toward the readiness score and is printed in the compliance report with the name and date of the last save.
A list of known AI plugins ships inside TransparAI and is compared with your installed plugins on your server, the same way the chatbot detection works. The list updates with the plugin, nothing is fetched and nothing about your site is sent anywhere. Active plugins the list does not know are suggested when their own name or description mentions AI, and any other system can be declared by hand. Developers can extend the list with the transparai_systems_registry filter.
Yes. The print view covers the readiness score, the assessment answers, the Article 4 checklist, the detected and declared AI systems, the state of every disclosure notice, the AI-marked content, the media audit list and the recent activity, together with a document hash over the facts, so two reports of an unchanged site carry the same hash. GET /wp-json/transparai/v1/report returns the same record as JSON, and the CSV export lists the media audit rows.
No. TransparAI is a technical tool, not legal advice, and using it creates no guarantee of compliance with any regulation. See the Disclaimer section.
Only when a file is labeled and the metadata option is enabled. The plugin then writes a small XMP block into the JPEG, PNG, WebP or AVIF file and its size variants. The image pixels are untouched. Files are replaced atomically and validated first. Unlabeling removes exactly the metadata this plugin wrote; foreign metadata is never touched.
Open the attachment details and click "Show file metadata". It lists every file of that attachment with its state (declaration present, missing, or a format that cannot carry one), the digital source type currently declared, the detection evidence in full, the recorded history and the raw XMP packet of the main file. Nothing is written while you look; it is a read of the files as they are on disk right now.
Not always, and that is worth checking. Image optimizers at the edge, Cloudflare Polish and Jetpack Photon among them, re-encode images while delivering them and drop every metadata block in the process. The file on your server stays perfect while visitors and search engines receive a bare image, and nothing in WordPress shows it. Enable the delivery check in the settings, then press "Check delivery" on a labeled image: the plugin fetches that image from your own public URL and tells you whether the declaration arrived. If it did not, the fix is in your CDN configuration (keep metadata, or exclude labeled images from re-encoding), not in this plugin.
It gives search engines exactly the signals they document. Google reads the IPTC digital source type that TransparAI writes into the image files and can show an "AI-generated" label in Image Search; the Schema.org JSON-LD in the page carries the same declaration for search engines and AI crawlers that never open the file. Everything is rendered server-side, adds no request and shifts no layout, so there is no Core Web Vitals cost. Whether and how a search engine treats labeled images in ranking is its decision, not something a plugin can promise; what the labeling avoids is the opposite risk, an undisclosed AI image that a platform or a competitor points out later. For GEO, generative engine optimization, the same structured data tells AI search and answer engines where your images and texts come from, which is part of what they weigh when they cite a source.
It recognizes more than 40 chat and chatbot vendors by their plugin directory, their script hosts, their JavaScript globals and their widget markup, entirely locally. The finding shows on the settings page with a hint whether a bot or people usually answer there. You decide whether the notice appears; the plugin never switches it on from a finding alone, because a live chat with a person behind it is not an AI system.
Yes. Every post and page has an AI level in the editor sidebar (no AI used, AI-assisted, AI-generated, AI-generated and reviewed), also available in Quick Edit and Bulk Edit of the post list. AI levels show a configurable note ahead of or after the content, or on both sides; the "AI Notice" block and the [transparai_notice] shortcode place it by hand instead, exclusively so when the position is set to "only where a block or shortcode is placed". Reviewed texts record the reviewer, the date and a fingerprint of the content, so a later edit is visible as "changed since review". Optionally the note goes into excerpts and RSS feed items too. There is also an optional site-wide note at the end of pages that contain labeled media.
Yes. Under Settings, AI-written text you choose between a block on its own line, an inline note inside the text, a dismissible banner, a small badge and a modal (a button that opens a dialog), and whether it appears ahead of the content, after it, on both sides or only where a block or shortcode is placed. Two further options add a small AI badge to the post title in lists and archives and an [AI] prefix to feed item titles. Dismissing a banner hides it for that page view only; nothing is stored in the visitor's browser.
Five, all rendered on the server so a wording change in the settings reaches every placed block at once, and all silent when nothing is declared. "AI Notice" places the note of the current post in any of the five styles, also several times per post or in a block theme template, where it replaces the automatic note. "AI Image Label" shows the label of one file from the media library, AI-generated with the generator name or Human made, for galleries, captions and builder images the automatic badge does not reach. "AI Systems Notice" is the one-sentence notice naming the visible AI systems, "AI Systems List" the same systems as a list with categories for a transparency statement. "Chatbot AI Notice" tells visitors that an AI answers in the chat. Every block has a shortcode twin in [transparai_notice].
Modern cameras embed C2PA Content Credentials into real photos. A C2PA manifest alone therefore never auto-labels. It lands in the review queue unless the manifest declares an AI source. Dismiss it with one click; dismissed files are not queued again.
The visible badge covers the block editor (every image-bearing block incl. cover, media-text, galleries, inline images in text, video and audio), the classic editor, featured images (post thumbnails), template images, text widgets, Elementor free and Pro (image, galleries, carousels, slides, image box, hotspot, flip box, call to action, posts, Theme Builder), WPBakery Page Builder (single images, galleries, carousels, row and column backgrounds, parallax, grids), Bricks Builder (every element that prints an image tag) and Divi (image, gallery, blurb, slider and fullwidth header modules through the content filter; section, row, column, slide and module background images through the Extras option below). Inside the builders' own editing screens badges are deliberately not injected, the Divi Visual Builder and Backend Builder included. Markup a theme renders itself can be passed through apply_filters( 'transparai_label_media', $html ). For images a theme prints without an attachment ID (ACF URL or array fields) and for CSS backgrounds enable the option under Extras: a small script matches those images against your labeled files. The machine-readable XMP labeling is independent of any builder and always works.
Yes. Under Settings, Visible badge you pick a background colour, a text colour and an opacity next to the four styles. Both colour fields are empty out of the box, and while they are empty the badge looks exactly as it always has, so an update changes nothing on a site that is happy with the neutral look. The text colour also draws the border, which is what the outline style and the "Human made" badge use; outline has no fill of its own, so a background colour does not show there. If you would rather set the colours in your stylesheet, the three CSS custom properties --trai-badge-bg, --trai-badge-fg and --trai-badge-opacity do the same job and can be scoped to a single container.
The settings tell you before your visitors find out. A traffic light next to the colour fields rates the contrast between the badge text and its fill while you pick, against the WCAG threshold of 4.5 to 1 that applies at the badge's text size, and it spells the verdict out in words rather than leaving the colour to say it. Because a badge fill is see-through (the dark style is 70 per cent by default) and lands on photos nobody can predict, the rating assumes the worst case: the badge is measured on a white photo and on a black one, and the poorer of the two results is the one you see. A disclosure only works if people can read it, and a light badge colour on white text is the quickest way to lose that.
Usually not, and never silently. Badges sit above typical theme layers (hover effects, zoom icons, sale badges), and a small script additionally checks the real paint order: a badge that is still covered is raised, moved to a free corner or, as the last resort, shown as a caption line below the image (this guard can be turned off under Visible badge, Extras). For manual control, give any container one of the utility classes trai-badge-top-left, trai-badge-top-right, trai-badge-bottom-left, trai-badge-bottom-right, trai-badge-below or trai-badge-hidden, or pick a position for a single image in its attachment details ("Badge position"). Both ways switch the guard off for those badges, and trai-badge-manual does the same without changing the position, for the rare case where the guard misjudges your layout. Hiding the visible badge of one image never touches the machine-readable file metadata or the structured data in the page; that part of the disclosure stays intact.
No. There are no external requests of any kind. All detection happens by reading file bytes locally on your server, and the AI systems list is a file inside the plugin.
It records who did what inside your own WordPress: the per-file history and the site log store the user ID and display name of whoever labeled, confirmed, declared or dismissed something, the assessment and the checklist store the name and date of the last save, and a post marked as reviewed stores the reviewer's name, which is shown publicly only when you enable it. Nothing leaves the server, no cookies are set, and everything is removed on uninstall with data removal enabled. See the Privacy section.
By default your labels stay in the database (reinstalling restores them) and metadata already written stays in the files. If you prefer a full cleanup, enable "Delete all plugin data" in the settings before uninstalling. Unlabel files first if you also want the in-file metadata removed.
Yes. The meta key _transparai_ai is registered for the REST API, WP-CLI commands cover bulk work, and other plugins can call do_action( 'transparai_mark_ai', $attachment_id, 'Generator name' ).
Post in the support forum here on wordpress.org, or write to TransparAI@cms-admins.de. The plugin is built and maintained by Patrick Schlesinger (cms-admins.de).
wp transparai score, content, assessment, systems and report.chatbot; new setting "only where a block or shortcode is placed" for the text note and the systems notice.transparai_label_media for markup a theme renders itself.GET /report carry the compliance summary and the site log; the document hash covers the facts only.[transparai_notice] shortcode; the note can go into excerpts and RSS feeds (dc:description).wp transparai human; written into files that carry no other digital source type, shown in the structured data, optional "Human made" badge.transparai/v1 (media rows, per-file detail, actions, re-check, report), authenticated only.