JAZ-X Media Provenance Inspector helps WordPress administrators inventory media provenance and inspect C2PA metadata and credentials.
This is an independent plugin by JAZ-X Innovation. It is not affiliated with or endorsed by the Coalition for Content Provenance and Authenticity (C2PA) or the Content Authenticity Initiative.
Core features:
JAZ-X Media Provenance Inspector 0.3.4 packages @contentauth/c2pa-web 0.15.1 and its matching WASM runtime inside the plugin. It does not load third-party executable JavaScript or WASM for cryptographic verification.
Media bytes are fetched from the same WordPress origin and processed in the administrator’s browser. JAZ-X Media Provenance Inspector does not upload media bytes to any JAZ-X service. Cross-origin attachment URLs (for example, some CDN/offload configurations) are not fetched by the verifier in this release.
Remote manifest fetching, OCSP lookups, and external trust-list requests are disabled in this release. Local integrity verification remains fully available without an external verification-data request.
JAZ-X Media Provenance Inspector includes GPL-compatible third-party dependencies under vendor/c2pa/. License copies and version/integrity information are included in THIRD-PARTY-NOTICES.txt and vendor/c2pa/licenses/.
The bundled C2PA browser runtime is built from:
@contentauth/c2pa-web 0.15.1 — MIT license@contentauth/c2pa-wasm 0.13.0 — MIT license@contentauth/c2pa-types 0.7.4 — MIT license@contentauth/c2pa-utilities 0.3.0 — MIT licensehighgain 0.1.0 — ISC licenseUpstream C2PA source code:
https://github.com/contentauth/c2pa-js
Highgain package distribution:
https://www.npmjs.com/package/highgain/v/0.1.0
The included highgain.js is the small readable ESM distribution from that package; its package metadata and ISC license are included alongside it.
The distributed c2pa-web.runtime.js is the upstream npm distribution with one browser-resolution-only change: the bare highgain import is rewritten to the local ./highgain.js path. The local index file points to that renamed runtime chunk. Exact package versions and npm integrity values are recorded in vendor/c2pa/VERSIONS.txt.
Reproduction outline:
npm install @contentauth/c2pa-web@0.15.1 highgain@0.1.0.dist/index.js, runtime chunk, worker, and dist/resources/c2pa_bg.wasm into vendor/c2pa/.highgain import to ./highgain.js, rewrite the index runtime import to the local renamed chunk, and use c2pa-web.bundle.js as the small JAZ-X Media Provenance Inspector entry module.