{"id":280906,"date":"2026-06-22T04:44:48","date_gmt":"2026-06-22T04:44:48","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/clockdo-publish-date-proof-content-timestamp\/"},"modified":"2026-09-28T08:03:15","modified_gmt":"2026-09-28T08:03:15","slug":"coremix-publish-date-proof","status":"publish","type":"plugin","link":"https:\/\/sw.wordpress.org\/plugins\/coremix-publish-date-proof\/","author":23448178,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.1.3","stable_tag":"0.1.3","tested":"7.1.2","requires":"6.0","requires_php":"7.4","requires_plugins":null,"header_name":"Clockdo \u2013 Publish Date Proof & Content Timestamp","header_author":"Ray Xiao","header_description":"A verifiable record of when your content went public.","assets_banners_color":"","last_updated":"2026-09-28 08:03:15","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/ots.clockdo.com\/brand\/","header_author_uri":"https:\/\/ots.clockdo.com","rating":0,"author_block_rating":0,"active_installs":0,"downloads":222,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.1.1":{"tag":"0.1.1","author":"ray5051","date":"2026-06-22 04:44:34","revision":3581165},"0.1.3":{"tag":"0.1.3","author":"ray5051","date":"2026-09-28 08:03:15","revision":3716583}},"upgrade_notice":[],"ratings":[],"assets_icons":[],"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.1.1","0.1.3"],"block_files":[],"assets_screenshots":[],"screenshots":{"1":"Admin dashboard: proof stats and recent submissions.","2":"Post list column: proof status and quick actions.","3":"Settings page: API base, site ID, public options."}},"plugin_section":[],"plugin_tags":[17224,18193,2972,1357,712],"plugin_category":[],"plugin_contributors":[268279],"plugin_business_model":[],"class_list":["post-280906","plugin","type-plugin","status-publish","hentry","plugin_tags-blockchain","plugin_tags-content-protection","plugin_tags-copyright","plugin_tags-timestamp","plugin_tags-verification","plugin_contributors-ray5051","plugin_committers-ray5051"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/s.w.org\/plugins\/geopattern-icon\/coremix-publish-date-proof.svg","icon_2x":false,"generated":true},"screenshots":[],"raw_content":"<!--section=description-->\n<p>Clockdo helps WordPress site owners protect their publish date by generating a verifiable content timestamp.<\/p>\n\n<p>Clockdo creates a deterministic fingerprint (SHA-256) and requests an OpenTimestamps proof. Public posts use the public proof flow. Draft and private versions use a private, hash-only protocol and never send the title, author, URL, WordPress post ID, or post body. When full-text archive mode is enabled, every meaningful save in draft, pending, scheduled, private, or published state is first stored as an immutable local snapshot.<\/p>\n\n<h3>Features<\/h3>\n\n<ul>\n<li>Generate per-post timestamp records<\/li>\n<li>Request OpenTimestamps proof<\/li>\n<li>Export .ots and manifest files<\/li>\n<li>Automatic draft, publish, update, and opt-in private-post workflows<\/li>\n<li>Separate article coverage and immutable proof-history views<\/li>\n<li>Immutable full-text snapshots for every meaningful save when full-text archive mode is enabled<\/li>\n<li>Snapshot validation, idempotent requests, and recoverable asynchronous retries<\/li>\n<li>Optional public meta tags and post footer with verification link<\/li>\n<li>Independent verification using standard tools<\/li>\n<\/ul>\n\n<h3>Use Cases<\/h3>\n\n<ul>\n<li>Prove when an article was first published<\/li>\n<li>Add a visible publication record to your posts<\/li>\n<li>Protect against plagiarism disputes<\/li>\n<li>Maintain an independent timestamp history<\/li>\n<li>Provide verification material for disputes or takedown cases<\/li>\n<\/ul>\n\n<p>English (Summary)\n* Generate per-post records and proof history in the dashboard.\n* Save proof artifacts to your WordPress uploads folder.\n* Optionally inject public meta tags and\/or a \"Verify\" footer link.\n* Proofs are designed to be independently verifiable with standard OpenTimestamps tools.<\/p>\n\n<h3>Privacy<\/h3>\n\n<p>This plugin may process and store locally:\n* WordPress post metadata (post ID, URL, timestamps),\n* immutable full-text snapshots containing post title, body, excerpt, slug, author ID, status, and audit timestamps when full-text archive mode is enabled,\n* deterministic hashes (SHA-256),\n* proof IDs\/statuses,\n* proof artifacts written to local disk under <code>wp-content\/uploads\/clockdo-ots-private\/<\/code>.<\/p>\n\n<p>Outbound requests:\n* This plugin connects to a remote timestamping API (configured by you) to request proofs.\n* Full-text archive v3 submissions upload only a manifest commitment; the exact snapshot and post body remain in the local WordPress database. Public manifests may include already-public identity fields such as URL, title, author, and timestamps.\n* Legacy export workflows may upload <code>export.json<\/code>, including post content when the operator explicitly enables that older combination of settings.\n* Private and draft submissions upload a hash-only manifest. They do not upload the title, author, URL, WordPress post ID, or post body.\n* A SHA-256 commitment is an integrity fingerprint, not encryption. It reveals when two committed snapshots are equal, and low-entropy content may be guessable by testing candidate text.<\/p>\n\n<p>Public disclosure:\n* If you enable meta injection or public verify links, your public pages may expose a hash\/canonicalization identifier and a verification link.<\/p>\n\n<p>See the included docs (for operators):\n* <code>assets\/docs\/privacy.md<\/code>\n* <code>assets\/docs\/third_party_services.md<\/code>\n* <code>assets\/docs\/data_deletion_uninstall.md<\/code><\/p>\n\n<h3>Third Party Services<\/h3>\n\n<p>This plugin connects to the following external services:<\/p>\n\n<ol>\n<li><p><strong>Clockdo Timestamping API<\/strong> (<code>ots-api.clockdo.com<\/code>)<\/p>\n\n<ul>\n<li>Used to register sites, submit timestamp requests, and check proof status.<\/li>\n<li>Endpoints called: <code>\/api\/v1\/public\/sites<\/code>, <code>\/api\/v1\/public\/site-stamps<\/code>, <code>\/api\/v1\/site\/me<\/code>, <code>\/api\/v1\/proofs\/{proof_id}<\/code>, and authenticated manifest\/OTS artifact paths.<\/li>\n<li>Data sent for registration: site domain.<\/li>\n<li>Data sent for public proofs: post URL, SHA-256 hash, and manifest\/export JSON according to settings.<\/li>\n<li>Data sent for private\/draft proofs: Site ID, SHA-256 content commitment, event\/visibility\/source-status fields, canonicalization version, and idempotency key. The per-site secret authenticates the request.<\/li>\n<li>Service homepage: <a href=\"https:\/\/ots.clockdo.com\">https:\/\/ots.clockdo.com<\/a><\/li>\n<li>Privacy policy: <a href=\"https:\/\/ots.clockdo.com\/privacy\">https:\/\/ots.clockdo.com\/privacy<\/a><\/li>\n<li>Terms of service: <a href=\"https:\/\/ots.clockdo.com\/terms\">https:\/\/ots.clockdo.com\/terms<\/a><\/li>\n<\/ul><\/li>\n<li><p><strong>Clockdo Verification Page<\/strong> (<code>ots-verify.clockdo.com<\/code>)<\/p>\n\n<ul>\n<li>If public verify links are enabled, post pages may link to this domain for independent proof verification.<\/li>\n<\/ul><\/li>\n<\/ol>\n\n<p>All outbound connections are made via the WordPress HTTP API (<code>wp_remote_post<\/code> \/ <code>wp_remote_get<\/code>).\nThe API Base URL is configurable; the above domains are defaults.<\/p>\n\n<p>See also: <code>assets\/docs\/third_party_services.md<\/code><\/p>\n\n<h3>Uninstall<\/h3>\n\n<p>Ordinary uninstall removes plugin settings, transient queue state, legacy batch tables, and mutable display metadata. It deliberately retains the immutable <code>ots_post_snapshots<\/code> and <code>ots_post_proofs<\/code> audit tables, including any full-text snapshots, and it may leave proof files under <code>wp-content\/uploads\/clockdo-ots-private\/<\/code>.<\/p>\n\n<p>For irreversible full deletion, first make and verify a backup, then follow <code>assets\/docs\/data_deletion_uninstall.md<\/code> to remove the two retained tables and the private uploads directory explicitly.<\/p>\n\n<h3>Disclaimer<\/h3>\n\n<p>This plugin provides timestamping and verification tooling. It is not legal advice, not a certification service, and does not determine ownership.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin folder to <code>\/wp-content\/plugins\/<\/code> or upload the ZIP via Plugins -&gt; Add New -&gt; Upload Plugin.<\/li>\n<li>Activate the plugin.<\/li>\n<li>Go to the plugin Settings page and set your API Base URL and fetch\/save your Site ID.<\/li>\n<li>Ask your Clockdo operator to provision the Site Secret if you plan to enable draft or private-post proofs. Merely entering a domain never issues this credential, and the Settings page reports only whether it is configured.<\/li>\n<li>Review the archive\/submission settings. In legacy mode, public publish\/update automation is enabled by default and draft\/private automation is opt-in. Enabling export + full content + local storage activates full-text archive mode, in which every meaningful eligible save is retained and queued for its matching public\/private proof.<\/li>\n<li>Publish or save a post, then inspect article coverage and proof history on the dashboard.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"is%20this%20a%20copyright%20registration%3F\"><h3>Is this a copyright registration?<\/h3><\/dt>\n<dd><p>No. This plugin creates a verifiable timestamp record. It does not register copyright or determine legal ownership.<\/p><\/dd>\n<dt id=\"can%20this%20help%20in%20disputes%3F\"><h3>Can this help in disputes?<\/h3><\/dt>\n<dd><p>It provides independent timestamp evidence that may support your documentation process. Legal outcomes depend on jurisdiction and additional evidence.<\/p><\/dd>\n<dt id=\"does%20this%20prove%20ownership%2Fcopyright%3F\"><h3>Does this prove ownership\/copyright?<\/h3><\/dt>\n<dd><p>No. It proves that a specific fingerprint existed by a certain time (via an OTS proof). Ownership depends on broader evidence and jurisdiction.<\/p><\/dd>\n<dt id=\"what%20data%20is%20timestamped%3F\"><h3>What data is timestamped?<\/h3><\/dt>\n<dd><p>A SHA-256 fingerprint of a canonical representation of content and\/or a manifest that references it.<\/p><\/dd>\n<dt id=\"what%20happens%20with%20drafts%20and%20private%20posts%3F\"><h3>What happens with drafts and private posts?<\/h3><\/dt>\n<dd><p>Draft submissions and opted-in private-post submissions use a private protocol. The remote service receives a content hash plus protocol fields, but not the title, author, URL, WordPress post ID, or body. Private proof status and artifacts require the site's secret. Publishing the post later creates a separate public proof.<\/p><\/dd>\n<dt id=\"which%20wordpress%20states%20are%20archived%20automatically%3F\"><h3>Which WordPress states are archived automatically?<\/h3><\/dt>\n<dd><p>In full-text archive mode, meaningful saves of draft, pending, scheduled, private, and published posts create immutable local versions and queue their corresponding hash proof. Actual publication of a scheduled or previously private post creates a separate public version. Autosaves, revisions, auto-drafts, trash changes, and no-change saves do not create versions. Sites outside full-text archive mode retain the legacy opt-in draft\/private submission behavior.<\/p><\/dd>\n<dt id=\"where%20are%20snapshots%20and%20proof%20files%20stored%3F\"><h3>Where are snapshots and proof files stored?<\/h3><\/dt>\n<dd><p>Exact full-text snapshot bytes are stored in the WordPress database. Frozen manifest and <code>.ots<\/code> artifacts are stored locally under the uploads directory. Authorized users can download the snapshot, manifest, and finalized OTS from the WordPress dashboard. If you purchase a separate hosted plan, proofs may also be hosted by the Clockdo service (manifest + <code>.ots<\/code> only; never the local full-text snapshot).<\/p>\n\n<p>The plugin applies restrictive directory\/file permissions and writes Apache deny rules. nginx does not read <code>.htaccess<\/code>; nginx operators must explicitly deny <code>\/wp-content\/uploads\/clockdo-ots-private\/<\/code> (or move that directory outside the web root).<\/p><\/dd>\n<dt id=\"will%20this%20affect%20seo%3F\"><h3>Will this affect SEO?<\/h3><\/dt>\n<dd><p>Meta tags do not duplicate content. If you enable a public footer link, consider <code>rel=\"nofollow\"<\/code> by default.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>0.1.3<\/h4>\n\n<ul>\n<li>First public release after 0.1.1; it consolidates the unpublished 0.1.2 development line and internal 0.1.3 release candidates.<\/li>\n<li>Archive every meaningful draft, pending, scheduled, private, and public save as exact immutable snapshot bytes in full-text mode.<\/li>\n<li>Bind frozen single-snapshot-v3 and bulk-v3 manifests to snapshot and content hashes without uploading private article metadata or full text.<\/li>\n<li>Add authenticated per-version snapshot, manifest, and finalized OTS downloads while retaining immutable proof history independently from current article visibility.<\/li>\n<li>Add a unified public\/private submission state machine, generation-aware ownership, durable outboxes, leases, watchdogs, idempotent retries, and accepted-Proof-ID recovery.<\/li>\n<li>Keep accepted recovery pending until the exact Proof ID and idempotency key are present in durable local history; conflicting audit identities fail closed.<\/li>\n<li>Freeze the additive v1 API contract, capability negotiation, wire statuses, request limits, canonicalization identifiers, and artifact digest bindings.<\/li>\n<li>Make historical legacy aggregate proofs read-only, preserve their exact body-only hash semantics, and require bulk-v3 for new auditable full-text batches.<\/li>\n<li>Verify local and downloaded manifests, exports, snapshots, and OTS targets against the durable proof commitment, failing closed on mismatches.<\/li>\n<li>Harden database upgrades, private status\/artifact access, file migration, network handling, logs, cleanup, and long-running proof status recovery.<\/li>\n<\/ul>\n\n<h4>0.1.1<\/h4>\n\n<ul>\n<li>Harden the initial public proof workflow, local storage, request validation, and admin display before the private protocol release.<\/li>\n<\/ul>\n\n<h4>0.1.0<\/h4>\n\n<ul>\n<li>Internal pre-directory MVP: record generation, proof requests, dashboard UI, local storage, optional public meta\/link. This version was not a WordPress.org release.<\/li>\n<\/ul>","raw_excerpt":"Create verifiable OpenTimestamps records for WordPress posts, with durable proof history and independently checkable evidence.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/sw.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/280906","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sw.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/sw.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/sw.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=280906"}],"author":[{"embeddable":true,"href":"https:\/\/sw.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/ray5051"}],"wp:attachment":[{"href":"https:\/\/sw.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=280906"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/sw.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=280906"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/sw.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=280906"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/sw.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=280906"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/sw.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=280906"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/sw.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=280906"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}