Skip to content
@provemark

provemark

PHP tooling for verifiable trust — C2PA Content Credentials (content provenance, EU AI Act) and model-based property testing.

provemark

PHP tooling for verifiable trust — from the provenance and authenticity of content to the correctness of code.

Projects

A PHP library to build, sign, read and verify C2PA manifests — a framework-agnostic Core plus an optional Laravel integration, with machine-readable marking of AI-generated content under the EU AI Act, Article 50. The private signing key stays isolated from your web application, not baked into it.

composer require provemark/content-credentials

Try it in your browser: the same PHP, compiled to WebAssembly; your file never leaves your device.

A verifier for C2PA Content Credentials in pure PHP. It reads the manifest store out of a JPEG, PNG, GIF, WebP, WAV, AVI, MP3, FLAC or ISOBMFF file (MP4, MOV, AVIF, HEIC) and checks the claim signature, the hash binding to the asset, the certificate chain against a trust list you supply, the RFC 3161 timestamp and the revocation responses a signer staples into its own signature — returning what c2patool returns: the same validation_state and the same C2PA 2.4 §15 status codes.

For hosts that can run no second process, no native extension and no binary — cheap shared hosting, where most WordPress and Drupal sites live. It does not sign, holds no keys, and opens no network connection while verifying.

A first version: thoroughly tested and never used. Every fixture is measured against c2patool, its answers compared with a second implementation in Go and a third in Python, and 111 named obligations of the specification walked one by one — but nobody has yet pointed it at their own files, their own trust list or their own hosting. Treat a verdict as something to check, not as an answer.

composer require provemark/c2pa-verifier

Tracefern Image Check for C2PA, a WordPress plugin that verifies the Content Credentials of every JPEG, PNG, GIF and WebP image and every WAV, MP3 and FLAC file uploaded to the Media Library with c2pa-verifier, and shows the verdict in a Media Library column, a filter and the attachment details: Verified: trusted signer, Intact: signer not trusted, Does not verify, No Content Credentials or Could not be checked — and AI-generated (signed) only when a manifest that verifies says so. The check runs in the background, so it never blocks or breaks an upload; the plugin signs nothing and makes no network calls. It is c2pa-verifier's first real user.

In the WordPress.org plugin directory: Tracefern Image Check for C2PA.

Model-based (stateful) property testing for PHP: generate sequences of commands, check them against a shadow model, and shrink a failure to a minimal counterexample. Also a stateless property runner and opt-in edge-biased generation. No runtime dependencies.

Pinned Loading

  1. c2pa-verifier c2pa-verifier Public

    Verifier for C2PA Content Credentials in pure PHP: JPEG, PNG, WebP and ISOBMFF, with c2patool's verdict. Read and verify only; no signing, no keys, no network.

    PHP 1

Repositories

Showing 7 of 7 repositories
  • tracefern-image-check Public

    WordPress plugin that verifies the Content Credentials (C2PA) of uploaded images and shows the result in the Media Library.

    provemark/tracefern-image-check's past year of commit activity
    PHP 0 MIT 0 0 0 Updated Oct 7, 2026
  • provemark.github.io Public

    Website van provemark, gepubliceerd via GitHub Pages

    provemark/provemark.github.io's past year of commit activity
    HTML 0 0 0 0 Updated Oct 7, 2026
  • c2pa-verifier Public

    Verifier for C2PA Content Credentials in pure PHP: JPEG, PNG, WebP and ISOBMFF, with c2patool's verdict. Read and verify only; no signing, no keys, no network.

    provemark/c2pa-verifier's past year of commit activity
    PHP 1 MIT 0 7 (7 issues need help) 0 Updated Oct 7, 2026
  • wp-image-c2pa-measurements Public

    What WordPress, image plugins and image CDNs do to C2PA Content Credentials, measured.

    provemark/wp-image-c2pa-measurements's past year of commit activity
    HTML 0 MIT 0 0 0 Updated Oct 7, 2026
  • .github Public

    provemark organization profile

    provemark/.github's past year of commit activity
    0 0 0 0 Updated Oct 7, 2026
  • content-credentials Public

    PHP library for C2PA Content Credentials: build, sign, read & verify manifests, with machine-readable marking of AI-generated content (EU AI Act, Article 50). Framework-agnostic Core + optional Laravel integration.

    provemark/content-credentials's past year of commit activity
    PHP 5 MIT 0 0 0 Updated Oct 5, 2026
  • stateful-check Public

    Model-based (stateful) property testing for PHP: generate command sequences, check them against a shadow model, and shrink failures to a minimal counterexample.

    provemark/stateful-check's past year of commit activity
    PHP 0 MIT 0 0 0 Updated Sep 6, 2026

People

This organization has no public members. You must be a member to see who’s a part of this organization.

Top languages

Loading…

Most used topics

Loading…