=== Sigelith Timestamp ===
Contributors: sigelith
Tags: timestamp, proof of existence, media library, integrity, badge
Requires at least: 6.0
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 1.0.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Stamp files from your Media Library in the public Sigelith log and show a timestamp badge under them. Only the file's fingerprint leaves your server.

== Description ==

Sigelith Timestamp records that a file existed at a point in time — without sending the file anywhere.

When you stamp a file, the plugin computes its SHA-256 fingerprint on your server and records those 64 characters in the public, append-only Sigelith log. Anyone can later check, with standard tools and without trusting you or Sigelith, that a file with exactly these bytes existed no later than the stamped time and has not changed since.

* **Stamp with one click** — "Stamp with Sigelith" next to each file in the Media Library, as a bulk action, or in the attachment details. Optionally, every new upload in the background.
* **A badge under the file** — under File blocks (and, if you want, Image blocks), on attachment pages, or anywhere with `[sigelith_stamp id="123"]`. The badge is plain HTML with one small stylesheet served from your own site: no script, no tracking, no request to Sigelith while your page is viewed. It cannot break your theme and your theme cannot break it.
* **Honest by design** — the badge disappears when the file is replaced, until the new version is stamped. It says what a timestamp proves: that the file existed no later than a given time. It does not claim who made the file or that its content is true.
* **Gets stronger with time** — once a week Sigelith seals all its entries, signs the seal and anchors it in Bitcoin. The plugin checks this once a day and adds "Weekly seal" and "Bitcoin: block" to the badge.

Free, no account, no API key.

How the log and the proofs work, precisely enough to check them yourself: [sigelith.org/spec](https://sigelith.org/spec/). A court-appointed expert can follow the step-by-step check in [section 11](https://sigelith.org/spec/#expert).

== External services ==

This plugin connects to the Sigelith service at https://sigelith.org to record and check timestamps. It sends nothing until you stamp a file.

* **When you stamp a file** (by clicking "Stamp with Sigelith", by the bulk action, or — only if you switched it on — automatically after an upload), the plugin sends the file's SHA-256 fingerprint (64 hexadecimal characters) to `https://sigelith.org/api/proof/stamp`. The file itself, its name and the address of your site are never sent.
* **Once a day**, for stamped files whose weekly seal or Bitcoin anchor is not yet complete, the plugin sends the same fingerprint to `https://sigelith.org/api/proof/verify` to read their status.
* **Visitors** of your site never contact Sigelith unless they click "Verify independently" on a badge, which opens the public verification page.

Fingerprints in the Sigelith log are public and permanent: an entry cannot be withdrawn. Nobody can read a file from its fingerprint, but the fact that a file with that fingerprint existed becomes public.

Terms of use: https://sigelith.org/terms/ — Privacy policy: https://sigelith.org/privacy/

== Installation ==

1. Upload the `sigelith-timestamp` folder to `/wp-content/plugins/`, or install the plugin from the Plugins screen.
2. Activate it.
3. In Media → Library (list view), choose "Stamp with Sigelith" under a file.
4. Optional: Settings → Sigelith Timestamp.

== Frequently Asked Questions ==

= Does my file leave my server? =

No. Only its SHA-256 fingerprint does.

= Which file is stamped? =

The file behind the attachment's URL — the one your readers download. For large images WordPress serves a scaled copy; that copy is what gets stamped.

= What happens if I replace the file? =

The badge disappears and the Media Library shows that the file changed. Stamp the new version to get a new badge. Earlier stamps stay in the public log and in the attachment's history.

= Is this a qualified electronic timestamp under eIDAS? =

No. It is evidence anyone can check, not a qualified trust service, so it carries no legal presumption. See https://sigelith.org/spec/#attest

= What if the Sigelith service is unavailable? =

Stamping is retried automatically. The service pauses new stamps on purpose when it cannot confirm its clock against the reference time; the plugin waits and tries again.

= Does the plugin keep anything when I delete it? =

Your settings are deleted. The stamp records stay in your attachments' metadata on purpose: they are your copy of public, permanent proofs.

== Screenshots ==

1. The badge under a File block.
2. "Stamp with Sigelith" and the status column in the Media Library.
3. Settings → Sigelith Timestamp.

== Changelog ==

= 1.0.0 =
* First release.
