Article 50 is in force since 2 August 2026. Get the free plugin
Resources · Changelog

Changelog

The release history of the AIM Transparency WordPress plugin, in plain words. The same history ships inside the plugin readme.

01The current series32 releases

What changed, version by version.

Newest first. Pro entries are marked, everything else is in the free plugin.

2.2.0

  • New: every image format is marked without a server tool. Writing the mark into WebP, GIF, TIFF, AVIF, HEIC and HEIF used to need exiftool, which most shared hosts do not have. On those servers the plugin said so rather than pretending, but it still meant a WebP library carried the visible badge and nothing inside the files. All of them are now written by the plugin’s own PHP writer, so a plain shared host covers the whole library. HEIC matters more than it looks: it is what an iPhone produces by default.
  • New: the plugin can tell when something between your server and your visitors is destroying the mark. Some CDN features and image optimisers re-compress images after the mark is written, which strips it on the way to the reader. From the server those images still look marked, so the old report called them fine. The plugin now fetches one of your own images the way a visitor would and reads what actually arrives, and it names the culprit where it recognises one, such as Cloudflare Polish.
  • Improved: images re-compressed by ShortPixel, Imagify, Smush or EWWW are marked again automatically. Those plugins optimise on their own schedule, often minutes after an upload, and the mark was lost until the next library scan noticed. The plugin now listens for each of them finishing and rewrites it straight away.
  • Improved: images marked before this update are re-checked on their own. Where a format could not be written on your server, that was recorded against each image at the time and those records do not revisit themselves. They are now re-checked, so a library marked before 2.2.0 fills itself in rather than staying wrong.
  • Fixed: a settings update naming only some badge types could reset the rest. An update sent to the plugin’s API mentioning only some source types was read as the whole picture, so every type it left out was recorded as hidden and any wording set on it was cleared. Each type is now merged into what is already stored. Badge Studio has always sent every type, so a site changed through the dashboard was never affected.
  • Fixed: an incomplete request to the readiness API could clear your Article 4 record. A request naming only some items, or none at all, was read as the whole record, so everything it left out was recorded as unticked and its note cleared. Items are now merged into what is stored, and a request carrying no items is refused outright. The Readiness screen has always sent all nine.
  • Improved: the dashboard tabs follow the order of the work. Media comes straight after Overview, so the part that runs on its own comes first, and Readiness, which is a record you fill in by hand, sits with the settings rather than second in the list.

2.1.8

  • Fixed: on some hosts the plugin could not mark an image at all, and stopped the page instead. Since 2.1.5 each temporary file has been named partly after the process writing it, which is what keeps two uploads arriving at the same moment from overwriting each other. A host is free to switch that off and some do, Kinsta among them, and there the plugin reached for something that was not there: a fatal error, a failed upload, and no disclosure written. The name no longer depends on it. Nothing needs repairing afterwards, because on an affected site nothing was ever written in the first place. Reported by @comankey.
  • Note: Pro sites met this sooner. Automatic flagging marks an image the moment it arrives, so on an affected host the failure met every upload rather than waiting for someone to flag one by hand. The add-on itself needs no update.

2.1.7

  • Fixed: the official EU icon could be drawn with a border around it. A border width set for the custom badge was applied to the EU icon as well, painting a rectangle around artwork whose appearance is fixed by the disclosure standard. It showed up on every badge at once on shop grids and galleries. Your custom badge’s own border is unchanged.

2.1.6

  • New: the small dot before the badge label can be switched off. The custom badge style draws a dot before its words. Badge Studio now has a switch for it under Design, for sites that want a plainer mark. The AIM and official EU styles never drew one, so nothing changes there.
  • Improved: setting your own logo hides that dot for you. A logo is already a mark, and two side by side read as clutter rather than as a label, so the badge now carries one mark instead of two.
  • Fixed: the badge preview showed something your site would not. The preview in the Media viewer and in Badge Studio always drew the small dot and never drew your logo, whatever your settings said. Every preview now renders what visitors actually get.

Pro 1.2.7

  • Fixed: AI-written text disclosures were missing from every Pro report format. The JSON, Markdown, plain-text and print-ready reports all left out the Article 50(4) section, so a site disclosing AI-written text handed an auditor a record that evidenced none of it. The free CSV had carried it since 2.1.0. Three of the four printed a post count and then showed no posts, which is worse than omitting the count.
  • Fixed: the JSON report gained posts and report.post_count, and its schema moves to aim-transparency/report/3. Anything reading the old shape should pin to the schema string rather than assume it.
  • Changed: the "Codes used in this record" heading sat a level deeper than its neighbours in the Markdown and print reports, which skipped a heading level and made the document harder to navigate by structure. It is now a peer of the sections around it.
  • Changed: the plain-text report explained that addresses may run past the right margin only after sixteen lines had already done so. The note now appears where the convention is first used.

Pro 1.2.6

  • Fixed: after updating, the add-on kept saying an update was available. The version it compared against was the one loaded at the start of the request, which PHP cannot change mid-run, so a freshly updated site still saw the notice.
  • Fixed: a stale update notice left by an older version now clears itself. The notice was written before this release existed, so it could not be fixed from inside the version that wrote it.
  • Fixed: "Check again" on the Updates screen now checks again. The add-on answered from a cache of up to six hours, so pressing the button did nothing visible and looked broken.

2.1.5

  • Fixed: writing the mark no longer erases other metadata already in the file. On a server without exiftool, marking an image replaced any existing XMP block outright, losing the creator, copyright, credit line and licence terms the photographer had written into it. The mark is now merged into what is already there. Licence terms were the worst of it: unlike a credit line they exist nowhere else in the file, so nothing survived. EXIF and the older IPTC block were never affected, which is why this went unnoticed for so long.
  • New: the full-size original is marked too. Upload a large photo and WordPress serves a scaled-down copy while keeping your original beside it, reachable by removing -scaled from the address. Only the served copy carried the disclosure, so the largest and most shareable version was the bare one. The filter aicl_mark_original_image turns this off.
  • Improved: marking is safer and lighter. It no longer loads the whole file into memory, so a 40 MB photo costs about what a small one costs and no longer fails outright on a host with a tight memory limit. It also keeps the file’s permissions, follows a symbolic link to the real image, leaves nothing behind when the disk is full, and two things marking the same image at once can no longer overwrite each other.
  • Improved: photos containing more than one image — iPhone gain maps, and the multi-picture files from Samsung, Fujifilm and GoPro cameras — are skipped and reported as skipped rather than written into and quietly damaged.
  • New: the Media screen opens a picture properly. Click a thumbnail and the image opens at full size with its details beside it, instead of judging a photo from a sixty-pixel square. Arrow keys step through the library, including across pages.
  • Fixed: awkward files no longer look broken. No browser can display a TIFF or a HEIC, so on a server that cannot make JPEG copies the library, the viewer and the recently-flagged list all showed a torn-image icon. Each now names the format and says the file is on the server and its record is intact. An image whose file has gone missing says that too.
  • Improved: the Media screen also gained a stable order for images uploaded in the same second, page numbers matching the rest of WordPress, a viewer that no longer blinks shut at a page boundary, and a visible edge on the With AI / Without AI filter in the Classic theme.
  • Fixed: on a multilingual site, a translated post could disclose nothing. A translation with no record of its own now inherits the one from the post it was translated from, as images have done since 2.1.0.

Pro 1.2.5

  • This release also delivers 1.2.1 to 1.2.4, which were built but never published to the update channel. Licensed sites move straight from 1.2.0 to 1.2.5.
  • Security: updates are accepted only from the update service itself. The download address in an update response is checked against the service it came from before WordPress is allowed to install it.
  • Fixed: the add-on could not be translated at all. Its header declared a translations folder that was never created, so all eighteen of its phrases stayed in English whatever language the site was set to.
  • Licence records stored on a site are now signed. The signature covers the fields that decide entitlement plus the site address, so a record edited by hand or copied to a second site no longer validates there.
  • Fixed: the licence text and the changelog were missing from the download, and the “Visit plugin site” link led to a 404.
  • WordPress 7.1 ready: automatic flagging still recognises a file that arrives carrying its own provenance.

2.1.4

  • Fixed: cropping or rotating an image used to take the AI disclosure off it. WordPress has two image editors and both lost it differently. Editing from a post produced a new picture that was never marked at all, so no badge, no record and nothing inside the file. Editing from the Media screen rewrote the files without the mark, then went on reporting it as written, which is the worse of the two: you were told a disclosure was in a file that no longer held one. Both now carry the disclosure through the edit, and the file status is recorded honestly afterwards.
  • Improvement: the plugin’s own description was rewritten, and translated into all 21 languages. It had been describing an image-only plugin since before AI-written text and the chatbot notice existed.

2.1.3

  • Improvement: ready for WordPress 7.1. 7.1 can hand image resizing to your visitor’s browser instead of your server, which changes when WordPress announces that an image is finished: it says so twice, once when the upload arrives and again once the resized copies have landed. Tested against the release candidate before it shipped: the mark reaches the original and every resized copy, and nothing had to change for that to be true.
  • Pro: automatic flagging was tested against 7.1 too. A file that arrives already carrying its own provenance is still recognised and labelled when the browser does the resizing, and the second announcement does not cause it to be flagged twice.
  • Fixed: the AI image source panel appeared where there is no image to describe. It showed in the editor sidebar on Pages and on any other post type without a featured image. It now appears only where a featured image is actually supported.
  • New: a aicl_featured_post_types filter, for sites that want to decide which post types offer that panel. It matches the aicl_text_post_types filter already there for written text.
  • Fixed: the admin menu icon lost the cut between its two plates when WordPress recoloured it for the current admin scheme, leaving one solid shape. It keeps its form in every scheme now.
  • Improvement: the options in the AI text disclosure panel no longer sit flush against one another.

2.1.2

  • Improvement: the dashboard reads shorter. Every screen was trimmed, 10,700 words down to 7,500, with nothing left over 31 words. Where a description simply restated the label beside it, it is gone. Where it explained a standard rather than a setting, that explanation now lives in the documentation, which is what it is for.
  • Improvement: the Media list no longer moves when you record a source type. Saving used to add a line to the row you had just changed, growing it and pushing everything below it down under your cursor. The confirmation now floats above the page and clears itself, so nothing shifts.
  • Improvement: a description no longer strands its last word on a line of its own.
  • Fixed: on a multisite network, uninstalling could leave WordPress pointing at the wrong site for the rest of that request. Each site is now cleaned without disturbing which one WordPress thinks it is on.
  • Security: the wording you set for the click-to-disclose box is filtered again as the page is built, not only when you save it. A value that reached the database by some other route can no longer place raw markup on your pages.

2.1.1

  • Fixed: the featured-image control was English in every language. Ten strings across the block and classic editors were hardcoded, and the script carried no translation handle at all, so wrapping them alone would have changed nothing. They now resolve from the same catalogues as the rest of the plugin.
  • Improvement: that panel is now called AI image source, so it is no longer mistaken for the AI content disclosure panel sitting beside it in the editor.

2.1.0

  • New: disclose AI-written text, not just AI images. Article 50(4) asks a publisher to say when text was generated or manipulated by AI, but only for text published to inform the public on matters of public interest. So the plugin asks that question once, in Settings, and most sites are told plainly that the duty does not apply to them and are never asked again. Sites it does apply to get a control in the post editor, in both the block and classic editors, recording whether the text was AI Generated, AI Modified or marked simply as AI.
  • New: the Article 50(4) exemption is worked out, not claimed. Where text has had human review and a named person or organisation holds editorial responsibility, no disclosure is required and both facts are recorded with the date. Review on its own is half the test, so a post with nobody named still discloses.
  • New: a disclosed post carries schema.org JSON-LD describing the article, alongside the existing ImageObject data for pictures.
  • New: [aicl_text_disclosure] places that line by hand instead of automatically, for anyone who wants it under a byline rather than above the post.
  • Note: text and images are judged separately, because the law judges them separately. Human review of an article does not exempt an AI-generated image inside it, and the badge stays.

2.0.3

  • Security: Pro entitlement is no longer decided in this plugin. The rules that grant Pro used to live here, and this plugin is published source, so the way past them was published with it. They now live in the Pro add-on, and the record it stores is signed and tied to the site it was activated on. Nothing changes for anyone running the free plugin.

2.0.2

  • Fix: Algorithmic can now be set in bulk. Six of the seven source types were in the Media Library bulk menu. Algorithmic, for procedural work like fractal or formula art, was left out, so the only way to set it was one image at a time. It sits with the others now, translated in all 21 languages.

2.0.1

  • Improvement: the Media screen leads with your library. The eight source-type explanations used to sit above it, so the actual work started below the fold. They now sit under the list and fold away, and whether you leave them open or closed is remembered. A link at the top jumps to them when you want them.
  • New: filter your library by With AI or Without AI. The filter offered only “everything recorded” before, which could not answer the obvious question of which images are the AI ones.
  • Improvement: the screen you were on survives a reload. Refreshing used to drop you back on Overview. The tab is now part of the address, so a reload keeps your place and you can link someone straight to a screen.
  • Fix: AVIF and TIFF now appear on the Metadata screen. The plugin has always written them wherever your host has exiftool, but the screen only knew four formats, so those images were missing from it entirely. On a server without exiftool they now say so plainly instead of showing an unexplained zero.
  • Fix: AI (basic) had the same icon as AI Generated, so the two were indistinguishable in a list until you read the label. It has its own now.
  • Improvement: clearer wording on the Shortcodes screen, and the picture beside a disclosure is now called a symbol throughout, so it is no longer confused with the mark written inside your image files.

2.0.0

  • New: the plugin speaks 22 languages, every official EU language WordPress supports. Not just the settings screens: the badge on the image, the disclosure box, the chatbot notice and the whole dashboard. Each language takes its legal wording from that country’s own official text of Regulation (EU) 2024/1689 rather than a translation of ours. Irish and Maltese are the two official EU languages WordPress itself does not ship.
  • New: the dashboard now looks like WordPress. A compliance tool should read as part of your admin rather than as a guest that brought its own furniture, so the default is a new WordPress-native layout built from the same container, heading and tab strip every core settings screen uses. It picks up your admin colour scheme on its own. The Neo and Classic themes are still there, and if you have already picked one, updating does not change it under you.
  • New: the Overview screen fixes things instead of only reporting them. Every finding now carries the action that resolves it, so an image missing its mark, a chat widget nobody has disclosed, or an unrecorded Article 4 statement is one click from done rather than a trip to another tab. Findings split into what needs attention, what is already working and what is genuinely optional, so a clear site reads as clear. Every change is dated in a Recent changes list with an undo beside it.
  • Fix: the plugin no longer assumes every chat tool is an AI. It treated all 304 chat systems it knows about as AI assistants, including Tawk.to, Olark, Intercom and Crisp, which are live chat answered by people. Following that advice would have told your visitors they were talking to an AI while a colleague was typing. Every chat tool is now classified by who actually replies, and the plugin says one of three things: this one replies with AI, this one can be either depending on your setup, or this one is answered by your team and Article 50(1) does not apply.
  • Improvement: detection reads your shop and product pages as well as the home page, posts and pages, and keeps only the part of each page it needs, so it covers more ground while storing about a tenth as much.
  • New: multilingual sites are handled properly. Tested with Polylang: a source type set on an image carries to that image’s translated copies, so the badge no longer vanishes on a translated page when media translation is on. A wpml-config.xml ships for both Polylang and WPML. WPML is built for but not yet tested, and we say so rather than claim otherwise.
  • New: the dashboard asks for corrections in any language other than English. The translations were made with AI help and checked against the Regulation’s own text in each language, but not by a native speaker of every one, so the plugin says so and gives you somewhere to report anything that reads wrong.
  • Improvement: a new aicl_scan_urls filter points detection at any page a widget only appears on, such as a checkout or a members area.

1.3.1

  • Fix: “We could not check your pages” appeared on sites that were working perfectly well. A server cannot always reach itself at its public web address: local installs publish on a different port than the web server listens on, an origin behind a proxy often cannot resolve its own hostname, and some firewalls block a site from requesting itself. The scan now falls back to asking the server directly, on its own address. Sites that were already fine are unaffected and make no extra requests.

1.3.0

  • New: German, French and Spanish translations, covering every visitor-facing disclosure.
  • New: detection finds AI chat widgets that were not installed as WordPress plugins, by recognising the JavaScript a widget leaves in the browser and the cookies it sets. A chat tool pasted into your theme, added through a tag manager or served from your own CDN is now found.
  • New: detection reads three pages instead of one, so a widget that only loads on posts is no longer missed.
  • Improvement: the dashboard admits when it could not check. If your pages cannot be read, you get a plain explanation and what was still checked, instead of a confident “You’re all clear”. A scan that could not run is no longer reported as a scan that found nothing.
  • Security: the CSV compliance export now neutralises spreadsheet formula injection, and carries a UTF-8 marker so accented filenames stop mangling.

1.2.9

  • Fix: on a WooCommerce variable product, choosing a variation swapped the picture but left the previous image’s disclosure on it. A photograph could end up wearing an “AI Generated” badge, and an AI variation could end up with none. The badge now follows the image.
  • Fix: the dashboard under-reported large libraries. Figures came from a bounded page of attachments, so a big site saw a smaller flagged count than it really had. Totals are now aggregated in the database and are correct at any size.

1.2.8

  • Fix: the official EU mark on a disclosure notice rendered squashed. The Commission’s set has one square mark plus two wider lockups that already spell out their own label; a notice now always uses the square one, undistorted, since the sentence beside it is already saying the same thing.

1.2.7

  • New: a Shortcodes panel in the dashboard, under Disclosure. Pick the type, the style, your own wording, colours and mark, watch it render, and copy the finished shortcode. The shortcodes were documented but invisible in the plugin until now.
  • New: [aicl_disclosure] takes bg and color, so a notice can match your theme rather than always being the default near-black pill. A pair below the WCAG AA minimum of 4.5:1 is rejected and the default renders instead, because a disclosure nobody can read is not a disclosure.
  • New: mark chooses the glyph, aim, eu (the official European Commission AI-content icon for the matching source type) or none. A logo attribute puts your own image beside the mark, never instead of it. See the shortcode docs.
  • Each source type now has its own icon in the dashboard lists (camera, pen, layers, shapes) rather than one cog standing in for everything that is not AI.
  • Fix: the toggle control centres its knob correctly on both themes.

1.2.6

  • New: the dashboard has been redesigned. Every screen is one sheet divided by hairlines rather than a grid of separate cards, so Overview reads top to bottom: your readiness score, the figures behind it, what is running on your site, then your library. Readiness gained a numbered Article 4 checklist with proper evidence fields, Media shows each image’s disclosure state at a glance, and Upgrade sets out plainly what is free and what Pro adds.
  • New: Detection now recognises 671 AI systems, up from a short list of image tools. It separates chatbots and assistants (Article 50(1)) from image and content generators (Article 50(2)), so you can see which duty applies to what.
  • New: reusable disclosure shortcodes. [aicl_disclosure] places an AI notice anywhere shortcodes run, with a type (generated, edited, assisted or chatbot) and a style (inline, badge or banner). [aicl_ai_notice] covers the chatbot case. See the chatbot disclosure guide.
  • Detection also reads your own front page, so AI widgets that load in the browser are found, not just plugins on disk. It stays on your server; nothing is sent to a third party.
  • Uploading an image refreshes the Detection result straight away instead of waiting for the cache to expire.
  • Clearer wording throughout the dashboard, and a refreshed getting-started screen in both the Neo and Classic themes.

1.2.5

  • The getting-started screen has fresh artwork that matches your Neo or Classic dashboard theme, in a cleaner layout.
  • The “AI on your site” detection card is more reliable: re-scanning clears resolved warnings right away, it respects images you have marked as human-made instead of re-flagging them, and it lists AI-capable plugins by their real names.
  • Clearer, more natural wording across the dashboard and the getting-started screen.
  • Fix: the dashboard now keeps your chosen theme (Neo or Classic) consistent everywhere, including the getting-started screen.

1.2.4

  • New: an “AI on your site” card on the dashboard. It finds images in your library whose files read as AI-generated (a declared source type, or a known generator name like Midjourney, DALL·E or Firefly) but aren’t flagged, and lists active plugins that can generate AI images. Everything is computed on your own server, with no external requests.

1.2.3

  • A friendly one‑screen welcome after activation walks you to your first labelled image: pick an image, choose how it was made, and see it disclosed straight away. Reopen it any time from Transparency › Getting started.
  • Minor internal hardening and housekeeping.

1.2.2

  • The Pro library scan now runs to completion from one click: the dashboard processes the library in batches with a live progress bar (inspected / adopted / remaining) and a cancel button.
  • The scan result reports what discovery found (images adopted from provenance already declared inside the files) alongside the strip-guard counts.
  • The disclosure modal footer, its close button and the badge screen-reader fallback are now translatable.

Pro 1.2.0

  • Discovery scan: the library scanner now works in both directions. Alongside the strip-guard (re-embedding tags an optimizer removed), it reads your unflagged library for a declared DigitalSourceType (PIM-stamped masters, C2PA-signed camera files, AI-tool output) and adopts the declared value as the flag. Existing libraries heal retroactively: one click, or automatically each day.
  • Strip-guard now also covers AVIF on hosts with exiftool.
  • Auto-flagging validates tokens against the running free plugin, so a newer Pro against an older free plugin skips cleanly instead of writing unknown values.
  • Scans are batched, resumable and safe to run any time: a lock prevents overlapping runs, a time budget protects slow hosts, and a flag you clear by hand is never re-applied by the scanner.

1.2.1

  • Human-provenance source types: flag images as Camera Photo (digitalCapture), Human Created (digitalCreation: 3D renders and digital art made without generative AI) or Composite (composite: a non-AI mix such as photos + renders). Each embeds the current IPTC Digital Source Type into the file and the page JSON-LD, with no badge by default. Honest provenance for human-made work, not just AI labels. An optional visible badge for these types is available with the Custom badge style.
  • Embedding is now idempotent: files that already carry the exact Digital Source Type value (for example C2PA-signed camera captures or PIM-stamped masters) are left byte-for-byte untouched.
  • Pro auto-flagging adopts the human-provenance types too, so files stamped upstream arrive labelled.
  • Fixed: images whose badge is hidden now correctly emit their machine-readable JSON-LD, as the settings always described.
  • Source-type names and the visitor-facing disclosure texts are now translatable.

1.2.0

  • A fresh default dashboard style (“Neo”), with a one-click toggle back to the original monochrome look, in Settings > Appearance or the palette button in the top bar. Both styles support light and dark mode. Fonts are bundled locally (Inter + Bricolage Grotesque, SIL OFL); the plugin still makes no external requests.
  • The badge live preview demonstrates the badge on bundled sample images (our own AI-generated artwork, labelled as such), with a small slider to switch scenes. Docs and Support links added to the dashboard sidebar.

02Earlier releases2 releases

Where it started.

1.1.0

  • AI-assistant (chatbot) disclosure for EU AI Act Article 50(1): tell visitors when they are interacting with an AI rather than a human. Drop the [aicl_ai_notice] shortcode into any page with a chat UI, or enable the optional floating notice that appears when a known chat widget is detected. Configurable disclosure text and position.

1.0.0

  • Initial release: media flag with bulk actions, a visible badge across standard and block themes, optional universal badge coverage, IPTC/XMP embedding (exiftool + pure-PHP JPEG/PNG), schema.org JSON-LD, a free CSV compliance export, the React dashboard, and the opt-in transparency directory.

§ 11 Status

Images first, then the rest of the Act.

We started with images, where AI is easiest to pass off as real. What follows is indicative, not a commitment.

StageCapability
ShippedAI image labelling with badge, IPTC/XMP and JSON-LD · human provenance types · detection of undisclosed AI images and active AI plugins · Badge Studio · WooCommerce across every surface · chatbot and assistant disclosure under Article 50(1) · disclosure shortcodes · 22 EU languages · readiness and Article 4 checklist · CSV export
NextAI video and audio disclosure · automatic detection of AI-written text
ExploringC2PA Content Credentials signing with invisible watermark · team and multisite management

Article 50 is in force.

Install the free plugin, label what is AI, and have the record to show for it.

Get the free plugin