JAZ-X Media Provenance Inspector Wordpress Plugin - Rating, Reviews, Demo & Download
Plugin Description
JAZ-X Media Provenance Inspector helps WordPress administrators inventory media provenance and inspect C2PA metadata and credentials.
This is an independent plugin by JAZ-X Innovation. It is not affiliated with or endorsed by the Coalition for Content Provenance and Authenticity (C2PA) or the Content Authenticity Initiative.
Core features:
- SHA-256 hashing of original media and generated image sizes.
- Original and derivative inventory in dedicated database tables.
- C2PA marker detection separated from generic JUMBF-only metadata.
- Credential-loss warnings when a C2PA-bearing original produces WordPress derivatives that no longer contain the original credential marker.
- Browser-side cryptographic C2PA verification using a locally bundled SDK and WebAssembly runtime.
- Validation states for Trusted, Valid / untrusted, Invalid, No valid manifest, and Verification error. Trusted may remain visible on stored results produced with a previously configured trust source.
- Human-readable explanations for common integrity and trust findings.
- Manifest label/title, claim generator, signer, issuer, signature time, and validation-code capture where supplied by the verifier.
- Media Library status column and an administrator-only JAZ-X Media Provenance Inspector dashboard.
- Large-library scanning in safe 50-item AJAX batches with Pause/Resume and refresh-safe state.
- JFIF/JPE support as part of the JPEG family.
- Separate Unsupported, Missing source, Scan error, and Other JUMBF classifications.
JAZ-X Media Provenance Inspector 0.3.4 packages @contentauth/c2pa-web 0.15.1 and its matching WASM runtime inside the plugin. It does not load third-party executable JavaScript or WASM for cryptographic verification.
Media bytes are fetched from the same WordPress origin and processed in the administrator’s browser. JAZ-X Media Provenance Inspector does not upload media bytes to any JAZ-X service. Cross-origin attachment URLs (for example, some CDN/offload configurations) are not fetched by the verifier in this release.
Remote manifest fetching, OCSP lookups, and external trust-list requests are disabled in this release. Local integrity verification remains fully available without an external verification-data request.
Third-party code and source
JAZ-X Media Provenance Inspector includes GPL-compatible third-party dependencies under vendor/c2pa/. License copies and version/integrity information are included in THIRD-PARTY-NOTICES.txt and vendor/c2pa/licenses/.
The bundled C2PA browser runtime is built from:
@contentauth/c2pa-web0.15.1 — MIT license@contentauth/c2pa-wasm0.13.0 — MIT license@contentauth/c2pa-types0.7.4 — MIT license@contentauth/c2pa-utilities0.3.0 — MIT licensehighgain0.1.0 — ISC license
Upstream C2PA source code:
https://github.com/contentauth/c2pa-js
Highgain package distribution:
https://www.npmjs.com/package/highgain/v/0.1.0
The included highgain.js is the small readable ESM distribution from that package; its package metadata and ISC license are included alongside it.
The distributed c2pa-web.runtime.js is the upstream npm distribution with one browser-resolution-only change: the bare highgain import is rewritten to the local ./highgain.js path. The local index file points to that renamed runtime chunk. Exact package versions and npm integrity values are recorded in vendor/c2pa/VERSIONS.txt.
Reproduction outline:
- Install Node.js and npm.
- Run
npm install @contentauth/c2pa-web@0.15.1 highgain@0.1.0. - Copy the package’s
dist/index.js, runtime chunk, worker, anddist/resources/c2pa_bg.wasmintovendor/c2pa/. - Rewrite the runtime’s bare
highgainimport to./highgain.js, rewrite the index runtime import to the local renamed chunk, and usec2pa-web.bundle.jsas the small JAZ-X Media Provenance Inspector entry module.
Screenshots
No screenshots provided
