- PHP 82.2%
- Shell 16.8%
- JavaScript 1%
|
|
||
|---|---|---|
| .forgejo/workflows | ||
| .github | ||
| assets/js | ||
| build | ||
| docs | ||
| includes | ||
| tests | ||
| wordpress-org-assets | ||
| .gitattributes | ||
| .gitignore | ||
| AGENTS-TESTING.md | ||
| AGENTS.md | ||
| ARCHITECTURE.md | ||
| argentwolf-video-processor.php | ||
| CHANGELOG.md | ||
| LICENSE | ||
| README.md | ||
| readme.txt | ||
| TODO.md | ||
| uninstall.php | ||
| wordpress-development.md | ||
ArgentWolf Video Processor
ArgentWolf Video Processor is a self-hosted WordPress plugin that queues video attachments and creates privacy-cleaned, streaming-friendly derivatives with the server's FFmpeg and FFprobe binaries.
The original attachment remains untouched. Generated outputs can:
- strip GPS, device, chapter, and other embedded metadata;
- normalize display rotation into encoded pixels;
- reduce resolution and bitrate for practical web playback;
- produce an H.264/AAC adaptive HLS ladder;
- produce VP9/Opus WebM and H.264/AAC MP4 progressive fallbacks;
- place MP4 indexing data at the front of compatibility files;
- replace Video block and shortcode sources only at render time.
Processing model
The plugin stores jobs in a WordPress database queue and runs one worker per site. Its recurring WordPress event only starts a detached WP-CLI worker and returns; FFmpeg does not run inside the WP-Cron callback or settings-page request.
Backlog actions queue work but do not perform encoding synchronously.
Default output
Where the source dimensions permit, the default configuration creates:
- 360p, 480p, and 720p H.264/AAC fragmented-MP4 HLS renditions;
- a 720p-bounded VP9/Opus WebM progressive fallback;
- a 720p-bounded H.264/AAC MP4 progressive fallback.
Native browser HLS is used when available. Other compatible browsers use the locally bundled and pinned hls.js runtime.
Managed generated-media storage
Plugin-created media is stored below the active WordPress uploads directory at:
wp_upload_dir()['basedir']/argentwolf-video-processor/<attachment-id>/
Temporary and final outputs stay inside that plugin-owned boundary so validated promotion can remain same-filesystem and atomic. The original Media Library attachment remains in its normal WordPress-managed location and is not moved or rewritten.
Version 0.3.1 introduces this storage model for generated derivatives. Legacy installations may require a separately reviewed one-time operator migration; that migration utility is not part of the public plugin runtime or release ZIP.
Requirements
- WordPress 6.4 or newer.
- PHP 8.1 or newer.
- WP-CLI.
- A current, security-maintained FFmpeg and FFprobe installation.
libx264andaac.libvpx-vp9andlibopuswhen WebM output is enabled.- The FFmpeg HLS muxer with fragmented-MP4 support when adaptive HLS is enabled.
- PHP
proc_open()for encoding. - PHP
exec()for automatic detached dispatch.
When exec() is disabled, an operator may run
wp argent-video worker --once from a system scheduler.
This plugin is intended for operators who can install and maintain server-side media software. It does not bundle FFmpeg and may not be suitable for restricted shared hosting.
Administration
Settings > ArgentWolf Video provides:
- queue and worker status;
- smart, adaptive-only, and force-reprocess backlog operations;
- diagnostics for binaries, codecs, HLS, and the browser player;
- output, path, and process-priority settings;
- manual worker launch;
- WP-CLI examples;
- a link to the GitHub project for support and development;
- bounded database-backed worker diagnostic history and retention controls.
WP-CLI
wp argent-video diagnose
wp argent-video jobs
wp argent-video jobs --status=failed
wp argent-video enqueue 123 --force
wp argent-video scan --mode=smart
wp argent-video scan --mode=adaptive
wp argent-video scan --mode=all --after=2026-01-01 --through=2026-07-31
wp argent-video worker --once
wp argent-video worker --limit=3
The argent-video command name is retained for compatibility.
Privacy
Metadata removal applies to generated derivatives and adaptive renditions. The original uploaded attachment is preserved and may retain its original metadata.
The plugin does not upload videos or usage information to an external service
and contains no telemetry. hls.js is fetched only during controlled release
builds, verified, and served locally from the installed plugin. Build-time
hls.VERSION and hls.SHA256 integrity records are not shipped in the runtime
package.
Worker diagnostic history is stored locally in the WordPress database with bounded retention; detached-process capture files are temporary and removed after import.
Development and releases
Repository-only documentation and tests are excluded from the installable ZIP.
The release package has one top-level argentwolf-video-processor/ directory.
Use the ZIP attached to a tagged GitHub release or the WordPress.org package, not GitHub's automatically generated source archive.
Support development
Project source, issues, and funding links are available at:
https://github.com/thystra/wp-argentwolf-video-processor
License
The plugin is GPL-2.0-or-later. The distributed hls.js runtime is provided under
the Apache-2.0 license included as assets/vendor/hls.LICENSE.
FFmpeg security advisory gate
ArgentWolf Video Processor inspects the administrator-configured system FFmpeg binary before starting new transcoding. Security checks are capability-aware: a build can be unaffected by an advisory when the vulnerable decoder or encoder is not compiled in, even when its version is otherwise old enough to be affected. Known-vulnerable or unverifiable builds are blocked from starting new transcodes; existing originals and generated media are left untouched.
The initial enforced advisory is
CVE-2026-8461, an out-of-bounds
write in the MagicYUV decoder that can permit remote code execution. The plugin
checks whether the magicyuv decoder is enabled, recognizes fixed upstream or
backported release lines, reports the CVE explicitly in Diagnostics and WordPress
Site Health, and links to the NVD record. Future FFmpeg CVEs should be added to
the same advisory registry with their own capability and NVD link.
Current stable release
Current stable release: 1.0.0, published through WordPress.org.
Install from WordPress.org or use the exact ZIP attached to the tagged Forgejo release. Automatically generated source archives are not the canonical installable release artifact.