5,148 GPL Products · Updated DailyPRO Versions Available · Instant Download
Tracefern Image Check for C2PA 0.1.5 – WordPress Plugin

Tracefern Image Check for C2PA

v0.1.5 Updated 3 days ago
Download Tracefern Image Check for C2PA 0.1.5
Free download · version 0.1.5

Description

At a glance

Tracefern Image Check for C2PA v0.1.5 — free WordPress plugin download. Key facts: updated September 29, 2026 · requires WordPress 7.1+ & PHP 8.3+.

Verified, not just detected. Finding a C2PA manifest in a file is
easy; knowing whether it is genuine is not. A manifest can be copied onto
another image, and an image can be changed after it was signed while its
manifest still claims what it did before. Tracefern checks the signature,
the hash that ties the manifest to the image’s own bytes, and the signer’s
certificate against the C2PA trust lists. Only when the signature and the
hash hold does it show “AI-generated (signed)”, and only when the signer
is also on the trust list does it say “Verified”.

Content Credentials (C2PA) are a signed record inside an image file: who
made or edited it, with which tool, and whether generative AI was used.
Tracefern Image Check for C2PA verifies that record for every JPEG, PNG and WebP you
upload and shows the verdict where you already work with media.

  • Checked right after upload, on the original file, not on the
    resized copies WordPress or your browser makes. The check runs in the
    background, so a file that trips it up can never break an upload.
  • A verdict per image in a Media Library column and in the attachment
    details: who signed it, when, and against which trust list.
  • “AI-generated (signed)” when a manifest that verifies says the image
    was made by generative AI, also after later edits, and “AI-edited
    (signed)”
    when AI edited it. Never on a file that does not verify.
  • Sort and filter the Media Library list by verdict, including all
    AI-generated images.
  • Check existing images again under Settings Tracefern, or with
    WP-CLI: wp tracefern check --all.

The verdicts:

  • Verified: trusted signer — the credentials verify and the signer’s
    certificate chains to a trusted certificate authority.
  • Intact: signer not trusted — the credentials verify, but the signer
    is not on the trust list. The file is unchanged since signing; who
    signed it is not vouched for.
  • Does not verify — something failed, for example the image was
    changed after signing. The details list the C2PA status codes.
  • No Content Credentials — the file carries none. Most images today.
  • Could not be checked — the file could not be read or the check did
    not finish. The upload always proceeds.

What it does not do:

  • It never signs anything and holds no keys.
  • It never blocks an upload.
  • It makes no network calls. A manifest that is only referenced by URL is
    not fetched, and trust lists are never downloaded.

Verification is done by
provemark/c2pa-verifier, a
C2PA verifier written in PHP, bundled with the plugin.

Development

The source code, the tests and the build are public at
https://github.com/provemark/tracefern-image-check. composer build makes the
plugin’s zip from it: it installs the bundled verifier and prefixes its
namespace with Strauss, so it cannot collide with another copy. The
verifier itself is developed at https://github.com/provemark/c2pa-verifier.

Trust lists

By default the plugin trusts the certificate authorities on the C2PA
conformance programme’s trust lists, bundled with the plugin (see
trust/README.md for the date and source), and, optionally, the DigiCert
Trusted Root G4 for timestamps. Settings Tracefern shows the date of the
bundled copy and lets an administrator replace the lists with their own
trust settings. The plugin never downloads a list; a new copy comes with a
plugin update.

The C2PA trust lists are © the Coalition for Content Provenance and
Authenticity (C2PA), from https://github.com/c2pa-org/conformance-public,
licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/).

Frequently asked questions

What is Tracefern Image Check for C2PA?

Tracefern Image Check for C2PA is a free WordPress plugin available under the GPL license. The current version is 0.1.5.

Is Tracefern Image Check for C2PA free to download?

Yes — Tracefern Image Check for C2PA 0.1.5 is a free GPL download with no hidden fees, no account needed, and no feature locked behind a paywall in this package.

How do I install Tracefern Image Check for C2PA 0.1.5?

Download the ZIP file from this page, then in your WordPress dashboard go to Plugins → Add New → Upload Plugin, choose the file, click Install Now, then Activate. The plugin works immediately after activation — no license key or extra setup is required for the core features.

What are the requirements for Tracefern Image Check for C2PA?

Tracefern Image Check for C2PA 0.1.5 requires WordPress 7.1 or higher and PHP 8.3 or higher. Most modern WordPress hosts already meet these versions. Running older versions may cause features to break, so update WordPress and PHP first if your site is behind.

When was Tracefern Image Check for C2PA last updated?

Version 0.1.5 was last updated on September 29, 2026. This page is refreshed automatically, so the download here always matches the newest version we have verified.

Is the Tracefern Image Check for C2PA download safe?

The file is sourced directly from the official WordPress.org repository — the same file the developer published. It is served unmodified, so what you install here is byte-identical to the official release.

Version: 0.1.5
Updated: October 1, 2026

Technical details

Version0.1.5
Last updatedSeptember 29, 2026
Requires WordPress7.1 or higher
Requires PHP8.3 or higher
Authormauricevanloon
Tagsai, c2pa, content-credentials, media-library, provenance

Download Tracefern Image Check for C2PA

Download Tracefern Image Check for C2PA WP Plugin

Official Page ↗

Note: if the download does not start, disable your ad blocker and try again.

Leave a Comment