Tracefern Image Check for C2PA
Download Tracefern Image Check for C2PA 0.1.5Description
At a glance
Tracefern Image Check for C2PA v0.1.5 — free WordPress plugin download. Key facts: updated September 29, 2026 · requires WordPress 7.1+ & PHP 8.3+.
Verified, not just detected. Finding a C2PA manifest in a file is
easy; knowing whether it is genuine is not. A manifest can be copied onto
another image, and an image can be changed after it was signed while its
manifest still claims what it did before. Tracefern checks the signature,
the hash that ties the manifest to the image’s own bytes, and the signer’s
certificate against the C2PA trust lists. Only when the signature and the
hash hold does it show “AI-generated (signed)”, and only when the signer
is also on the trust list does it say “Verified”.
Content Credentials (C2PA) are a signed record inside an image file: who
made or edited it, with which tool, and whether generative AI was used.
Tracefern Image Check for C2PA verifies that record for every JPEG, PNG and WebP you
upload and shows the verdict where you already work with media.
- Checked right after upload, on the original file, not on the
resized copies WordPress or your browser makes. The check runs in the
background, so a file that trips it up can never break an upload. - A verdict per image in a Media Library column and in the attachment
details: who signed it, when, and against which trust list. - “AI-generated (signed)” when a manifest that verifies says the image
was made by generative AI, also after later edits, and “AI-edited
(signed)” when AI edited it. Never on a file that does not verify. - Sort and filter the Media Library list by verdict, including all
AI-generated images. - Check existing images again under Settings Tracefern, or with
WP-CLI:wp tracefern check --all.
The verdicts:
- Verified: trusted signer — the credentials verify and the signer’s
certificate chains to a trusted certificate authority. - Intact: signer not trusted — the credentials verify, but the signer
is not on the trust list. The file is unchanged since signing; who
signed it is not vouched for. - Does not verify — something failed, for example the image was
changed after signing. The details list the C2PA status codes. - No Content Credentials — the file carries none. Most images today.
- Could not be checked — the file could not be read or the check did
not finish. The upload always proceeds.
What it does not do:
- It never signs anything and holds no keys.
- It never blocks an upload.
- It makes no network calls. A manifest that is only referenced by URL is
not fetched, and trust lists are never downloaded.
Verification is done by
provemark/c2pa-verifier, a
C2PA verifier written in PHP, bundled with the plugin.
Development
The source code, the tests and the build are public at
https://github.com/provemark/tracefern-image-check. composer build makes the
plugin’s zip from it: it installs the bundled verifier and prefixes its
namespace with Strauss, so it cannot collide with another copy. The
verifier itself is developed at https://github.com/provemark/c2pa-verifier.
Trust lists
By default the plugin trusts the certificate authorities on the C2PA
conformance programme’s trust lists, bundled with the plugin (see
trust/README.md for the date and source), and, optionally, the DigiCert
Trusted Root G4 for timestamps. Settings Tracefern shows the date of the
bundled copy and lets an administrator replace the lists with their own
trust settings. The plugin never downloads a list; a new copy comes with a
plugin update.
The C2PA trust lists are © the Coalition for Content Provenance and
Authenticity (C2PA), from https://github.com/c2pa-org/conformance-public,
licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/).
Frequently asked questions
What is Tracefern Image Check for C2PA?
Tracefern Image Check for C2PA is a free WordPress plugin available under the GPL license. The current version is 0.1.5.
Is Tracefern Image Check for C2PA free to download?
Yes — Tracefern Image Check for C2PA 0.1.5 is a free GPL download with no hidden fees, no account needed, and no feature locked behind a paywall in this package.
How do I install Tracefern Image Check for C2PA 0.1.5?
Download the ZIP file from this page, then in your WordPress dashboard go to Plugins → Add New → Upload Plugin, choose the file, click Install Now, then Activate. The plugin works immediately after activation — no license key or extra setup is required for the core features.
What are the requirements for Tracefern Image Check for C2PA?
Tracefern Image Check for C2PA 0.1.5 requires WordPress 7.1 or higher and PHP 8.3 or higher. Most modern WordPress hosts already meet these versions. Running older versions may cause features to break, so update WordPress and PHP first if your site is behind.
When was Tracefern Image Check for C2PA last updated?
Version 0.1.5 was last updated on September 29, 2026. This page is refreshed automatically, so the download here always matches the newest version we have verified.
Is the Tracefern Image Check for C2PA download safe?
The file is sourced directly from the official WordPress.org repository — the same file the developer published. It is served unmodified, so what you install here is byte-identical to the official release.
Technical details
| Version | 0.1.5 |
|---|---|
| Last updated | September 29, 2026 |
| Requires WordPress | 7.1 or higher |
| Requires PHP | 8.3 or higher |
| Author | mauricevanloon |
| Tags | ai, c2pa, content-credentials, media-library, provenance |
Download Tracefern Image Check for C2PA
Download Tracefern Image Check for C2PA WP PluginNote: if the download does not start, disable your ad blocker and try again.