Clockdo – Publish Date Proof & Content Timestamp

Maelezo

Clockdo helps WordPress site owners protect their publish date by generating a verifiable content timestamp.

Clockdo creates a deterministic fingerprint (SHA-256) and requests an OpenTimestamps proof. Public posts use the public proof flow. Draft and private versions use a private, hash-only protocol and never send the title, author, URL, WordPress post ID, or post body. When full-text archive mode is enabled, every meaningful save in draft, pending, scheduled, private, or published state is first stored as an immutable local snapshot.

Features

  • Generate per-post timestamp records
  • Request OpenTimestamps proof
  • Export .ots and manifest files
  • Automatic draft, publish, update, and opt-in private-post workflows
  • Separate article coverage and immutable proof-history views
  • Immutable full-text snapshots for every meaningful save when full-text archive mode is enabled
  • Snapshot validation, idempotent requests, and recoverable asynchronous retries
  • Optional public meta tags and post footer with verification link
  • Independent verification using standard tools

Use Cases

  • Prove when an article was first published
  • Add a visible publication record to your posts
  • Protect against plagiarism disputes
  • Maintain an independent timestamp history
  • Provide verification material for disputes or takedown cases

English (Summary)
* Generate per-post records and proof history in the dashboard.
* Save proof artifacts to your WordPress uploads folder.
* Optionally inject public meta tags and/or a “Verify” footer link.
* Proofs are designed to be independently verifiable with standard OpenTimestamps tools.

Privacy

This plugin may process and store locally:
* WordPress post metadata (post ID, URL, timestamps),
* immutable full-text snapshots containing post title, body, excerpt, slug, author ID, status, and audit timestamps when full-text archive mode is enabled,
* deterministic hashes (SHA-256),
* proof IDs/statuses,
* proof artifacts written to local disk under wp-content/uploads/clockdo-ots-private/.

Outbound requests:
* This plugin connects to a remote timestamping API (configured by you) to request proofs.
* Full-text archive v3 submissions upload only a manifest commitment; the exact snapshot and post body remain in the local WordPress database. Public manifests may include already-public identity fields such as URL, title, author, and timestamps.
* Legacy export workflows may upload export.json, including post content when the operator explicitly enables that older combination of settings.
* Private and draft submissions upload a hash-only manifest. They do not upload the title, author, URL, WordPress post ID, or post body.
* A SHA-256 commitment is an integrity fingerprint, not encryption. It reveals when two committed snapshots are equal, and low-entropy content may be guessable by testing candidate text.

Public disclosure:
* If you enable meta injection or public verify links, your public pages may expose a hash/canonicalization identifier and a verification link.

See the included docs (for operators):
* assets/docs/privacy.md
* assets/docs/third_party_services.md
* assets/docs/data_deletion_uninstall.md

Third Party Services

This plugin connects to the following external services:

  1. Clockdo Timestamping API (ots-api.clockdo.com)

    • Used to register sites, submit timestamp requests, and check proof status.
    • Endpoints called: /api/v1/public/sites, /api/v1/public/site-stamps, /api/v1/site/me, /api/v1/proofs/{proof_id}, and authenticated manifest/OTS artifact paths.
    • Data sent for registration: site domain.
    • Data sent for public proofs: post URL, SHA-256 hash, and manifest/export JSON according to settings.
    • Data sent for private/draft proofs: Site ID, SHA-256 content commitment, event/visibility/source-status fields, canonicalization version, and idempotency key. The per-site secret authenticates the request.
    • Service homepage: https://ots.clockdo.com
    • Privacy policy: https://ots.clockdo.com/privacy
    • Terms of service: https://ots.clockdo.com/terms
  2. Clockdo Verification Page (ots-verify.clockdo.com)

    • If public verify links are enabled, post pages may link to this domain for independent proof verification.

All outbound connections are made via the WordPress HTTP API (wp_remote_post / wp_remote_get).
The API Base URL is configurable; the above domains are defaults.

See also: assets/docs/third_party_services.md

Uninstall

Ordinary uninstall removes plugin settings, transient queue state, legacy batch tables, and mutable display metadata. It deliberately retains the immutable ots_post_snapshots and ots_post_proofs audit tables, including any full-text snapshots, and it may leave proof files under wp-content/uploads/clockdo-ots-private/.

For irreversible full deletion, first make and verify a backup, then follow assets/docs/data_deletion_uninstall.md to remove the two retained tables and the private uploads directory explicitly.

Disclaimer

This plugin provides timestamping and verification tooling. It is not legal advice, not a certification service, and does not determine ownership.

Installation

  1. Upload the plugin folder to /wp-content/plugins/ or upload the ZIP via Plugins -> Add New -> Upload Plugin.
  2. Activate the plugin.
  3. Go to the plugin Settings page and set your API Base URL and fetch/save your Site ID.
  4. Ask your Clockdo operator to provision the Site Secret if you plan to enable draft or private-post proofs. Merely entering a domain never issues this credential, and the Settings page reports only whether it is configured.
  5. Review the archive/submission settings. In legacy mode, public publish/update automation is enabled by default and draft/private automation is opt-in. Enabling export + full content + local storage activates full-text archive mode, in which every meaningful eligible save is retained and queued for its matching public/private proof.
  6. Publish or save a post, then inspect article coverage and proof history on the dashboard.

FAQ

Is this a copyright registration?

No. This plugin creates a verifiable timestamp record. It does not register copyright or determine legal ownership.

Can this help in disputes?

It provides independent timestamp evidence that may support your documentation process. Legal outcomes depend on jurisdiction and additional evidence.

Does this prove ownership/copyright?

No. It proves that a specific fingerprint existed by a certain time (via an OTS proof). Ownership depends on broader evidence and jurisdiction.

What data is timestamped?

A SHA-256 fingerprint of a canonical representation of content and/or a manifest that references it.

What happens with drafts and private posts?

Draft submissions and opted-in private-post submissions use a private protocol. The remote service receives a content hash plus protocol fields, but not the title, author, URL, WordPress post ID, or body. Private proof status and artifacts require the site’s secret. Publishing the post later creates a separate public proof.

Which WordPress states are archived automatically?

In full-text archive mode, meaningful saves of draft, pending, scheduled, private, and published posts create immutable local versions and queue their corresponding hash proof. Actual publication of a scheduled or previously private post creates a separate public version. Autosaves, revisions, auto-drafts, trash changes, and no-change saves do not create versions. Sites outside full-text archive mode retain the legacy opt-in draft/private submission behavior.

Where are snapshots and proof files stored?

Exact full-text snapshot bytes are stored in the WordPress database. Frozen manifest and .ots artifacts are stored locally under the uploads directory. Authorized users can download the snapshot, manifest, and finalized OTS from the WordPress dashboard. If you purchase a separate hosted plan, proofs may also be hosted by the Clockdo service (manifest + .ots only; never the local full-text snapshot).

The plugin applies restrictive directory/file permissions and writes Apache deny rules. nginx does not read .htaccess; nginx operators must explicitly deny /wp-content/uploads/clockdo-ots-private/ (or move that directory outside the web root).

Will this affect SEO?

Meta tags do not duplicate content. If you enable a public footer link, consider rel="nofollow" by default.

Reviews

Hakuna hakiki za programu-jalizi hii.

Wachangiaji & Wasanidi

“Clockdo – Publish Date Proof & Content Timestamp” is open source software. The following people have contributed to this plugin.

Contributors

Changelog

0.1.3

  • First public release after 0.1.1; it consolidates the unpublished 0.1.2 development line and internal 0.1.3 release candidates.
  • Archive every meaningful draft, pending, scheduled, private, and public save as exact immutable snapshot bytes in full-text mode.
  • Bind frozen single-snapshot-v3 and bulk-v3 manifests to snapshot and content hashes without uploading private article metadata or full text.
  • Add authenticated per-version snapshot, manifest, and finalized OTS downloads while retaining immutable proof history independently from current article visibility.
  • Add a unified public/private submission state machine, generation-aware ownership, durable outboxes, leases, watchdogs, idempotent retries, and accepted-Proof-ID recovery.
  • Keep accepted recovery pending until the exact Proof ID and idempotency key are present in durable local history; conflicting audit identities fail closed.
  • Freeze the additive v1 API contract, capability negotiation, wire statuses, request limits, canonicalization identifiers, and artifact digest bindings.
  • Make historical legacy aggregate proofs read-only, preserve their exact body-only hash semantics, and require bulk-v3 for new auditable full-text batches.
  • Verify local and downloaded manifests, exports, snapshots, and OTS targets against the durable proof commitment, failing closed on mismatches.
  • Harden database upgrades, private status/artifact access, file migration, network handling, logs, cleanup, and long-running proof status recovery.

0.1.1

  • Harden the initial public proof workflow, local storage, request validation, and admin display before the private protocol release.

0.1.0

  • Internal pre-directory MVP: record generation, proof requests, dashboard UI, local storage, optional public meta/link. This version was not a WordPress.org release.