Content Credentials (C2PA) are a signed record inside an image file: who
made or edited it, with which tool, and whether generative AI was used.
Tracefern Image Check for C2PA verifies that record for every JPEG, PNG and WebP you
upload and shows the verdict where you already work with media.
The verdicts:
What it does not do:
Verification is done by
provemark/c2pa-verifier, a
C2PA verifier written in PHP, bundled with the plugin.
The source code, the tests and the build are public at
https://github.com/provemark/tracefern-image-check. composer build makes the
plugin’s zip from it: it installs the bundled verifier and prefixes its
namespace with Strauss, so it cannot collide with another copy. The
verifier itself is developed at https://github.com/provemark/c2pa-verifier.
By default the plugin trusts the certificate authorities on the C2PA
conformance programme’s trust lists, bundled with the plugin (see
trust/README.md for the date and source), and, optionally, the DigiCert
Trusted Root G4 for timestamps. Settings Tracefern shows the date of the
bundled copy and lets an administrator replace the lists with their own
trust settings. The plugin never downloads a list; a new copy comes with a
plugin update.
The C2PA trust lists are © the Coalition for Content Provenance and
Authenticity (C2PA), from https://github.com/c2pa-org/conformance-public,
licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/).