No description
  • PHP 82.2%
  • Shell 16.8%
  • JavaScript 1%
Find a file
Alan Johnson 06c41627fc
Some checks failed
CI / validate (push) Has been cancelled
update workflow
2026-09-16 17:42:58 -04:00
.forgejo/workflows update workflow 2026-09-16 17:42:58 -04:00
.github Add native Forgejo release workflow 2026-08-13 21:43:41 -04:00
assets/js Prepare ArgentWolf Video Processor 0.3.0 2026-07-29 17:45:30 -04:00
build Add FFmpeg security gate and harden CI 2026-08-13 21:13:38 -04:00
docs Document 1.0 release closure and shared lessons 2026-08-22 22:47:37 -04:00
includes Fix worker capture persistence and release validation 2026-08-17 14:02:20 -04:00
tests Pin r5 0.3.2 validation artifact 2026-08-17 14:12:07 -04:00
wordpress-org-assets Prepare Video Processor for WordPress.org submission 2026-08-05 19:07:20 -04:00
.gitattributes Prepare ArgentWolf Video Processor 0.3.0 2026-07-29 17:45:30 -04:00
.gitignore Prepare ArgentWolf Video Processor 0.3.0 2026-07-29 17:45:30 -04:00
AGENTS-TESTING.md Document 1.0 release closure and shared lessons 2026-08-22 22:47:37 -04:00
AGENTS.md Document 1.0 release closure and shared lessons 2026-08-22 22:47:37 -04:00
ARCHITECTURE.md Prepare 0.3.2 worker diagnostics and temp-file handling 2026-08-17 09:30:17 -04:00
argentwolf-video-processor.php Promote ArgentWolf Video Processor to 1.0.0 2026-08-22 20:16:52 -04:00
CHANGELOG.md Promote ArgentWolf Video Processor to 1.0.0 2026-08-22 20:16:52 -04:00
LICENSE Add Argent Video Processor v0.1.0 2026-07-27 13:06:15 -04:00
README.md Document 1.0 release closure and shared lessons 2026-08-22 22:47:37 -04:00
readme.txt Promote ArgentWolf Video Processor to 1.0.0 2026-08-22 20:16:52 -04:00
TODO.md Record 2.0 stable-baseline forward-port 2026-08-22 23:31:02 -04:00
uninstall.php Fix worker capture persistence and release validation 2026-08-17 14:02:20 -04:00
wordpress-development.md Document 1.0 release closure and shared lessons 2026-08-22 22:47:37 -04:00

ArgentWolf Video Processor

ArgentWolf Video Processor is a self-hosted WordPress plugin that queues video attachments and creates privacy-cleaned, streaming-friendly derivatives with the server's FFmpeg and FFprobe binaries.

The original attachment remains untouched. Generated outputs can:

  • strip GPS, device, chapter, and other embedded metadata;
  • normalize display rotation into encoded pixels;
  • reduce resolution and bitrate for practical web playback;
  • produce an H.264/AAC adaptive HLS ladder;
  • produce VP9/Opus WebM and H.264/AAC MP4 progressive fallbacks;
  • place MP4 indexing data at the front of compatibility files;
  • replace Video block and shortcode sources only at render time.

Processing model

The plugin stores jobs in a WordPress database queue and runs one worker per site. Its recurring WordPress event only starts a detached WP-CLI worker and returns; FFmpeg does not run inside the WP-Cron callback or settings-page request.

Backlog actions queue work but do not perform encoding synchronously.

Default output

Where the source dimensions permit, the default configuration creates:

  1. 360p, 480p, and 720p H.264/AAC fragmented-MP4 HLS renditions;
  2. a 720p-bounded VP9/Opus WebM progressive fallback;
  3. a 720p-bounded H.264/AAC MP4 progressive fallback.

Native browser HLS is used when available. Other compatible browsers use the locally bundled and pinned hls.js runtime.

Managed generated-media storage

Plugin-created media is stored below the active WordPress uploads directory at:

wp_upload_dir()['basedir']/argentwolf-video-processor/<attachment-id>/

Temporary and final outputs stay inside that plugin-owned boundary so validated promotion can remain same-filesystem and atomic. The original Media Library attachment remains in its normal WordPress-managed location and is not moved or rewritten.

Version 0.3.1 introduces this storage model for generated derivatives. Legacy installations may require a separately reviewed one-time operator migration; that migration utility is not part of the public plugin runtime or release ZIP.

Requirements

  • WordPress 6.4 or newer.
  • PHP 8.1 or newer.
  • WP-CLI.
  • A current, security-maintained FFmpeg and FFprobe installation.
  • libx264 and aac.
  • libvpx-vp9 and libopus when WebM output is enabled.
  • The FFmpeg HLS muxer with fragmented-MP4 support when adaptive HLS is enabled.
  • PHP proc_open() for encoding.
  • PHP exec() for automatic detached dispatch.

When exec() is disabled, an operator may run wp argent-video worker --once from a system scheduler.

This plugin is intended for operators who can install and maintain server-side media software. It does not bundle FFmpeg and may not be suitable for restricted shared hosting.

Administration

Settings > ArgentWolf Video provides:

  • queue and worker status;
  • smart, adaptive-only, and force-reprocess backlog operations;
  • diagnostics for binaries, codecs, HLS, and the browser player;
  • output, path, and process-priority settings;
  • manual worker launch;
  • WP-CLI examples;
  • a link to the GitHub project for support and development;
  • bounded database-backed worker diagnostic history and retention controls.

WP-CLI

wp argent-video diagnose
wp argent-video jobs
wp argent-video jobs --status=failed
wp argent-video enqueue 123 --force
wp argent-video scan --mode=smart
wp argent-video scan --mode=adaptive
wp argent-video scan --mode=all --after=2026-01-01 --through=2026-07-31
wp argent-video worker --once
wp argent-video worker --limit=3

The argent-video command name is retained for compatibility.

Privacy

Metadata removal applies to generated derivatives and adaptive renditions. The original uploaded attachment is preserved and may retain its original metadata.

The plugin does not upload videos or usage information to an external service and contains no telemetry. hls.js is fetched only during controlled release builds, verified, and served locally from the installed plugin. Build-time hls.VERSION and hls.SHA256 integrity records are not shipped in the runtime package.

Worker diagnostic history is stored locally in the WordPress database with bounded retention; detached-process capture files are temporary and removed after import.

Development and releases

Repository-only documentation and tests are excluded from the installable ZIP. The release package has one top-level argentwolf-video-processor/ directory.

Use the ZIP attached to a tagged GitHub release or the WordPress.org package, not GitHub's automatically generated source archive.

Support development

Project source, issues, and funding links are available at:

https://github.com/thystra/wp-argentwolf-video-processor

License

The plugin is GPL-2.0-or-later. The distributed hls.js runtime is provided under the Apache-2.0 license included as assets/vendor/hls.LICENSE.

FFmpeg security advisory gate

ArgentWolf Video Processor inspects the administrator-configured system FFmpeg binary before starting new transcoding. Security checks are capability-aware: a build can be unaffected by an advisory when the vulnerable decoder or encoder is not compiled in, even when its version is otherwise old enough to be affected. Known-vulnerable or unverifiable builds are blocked from starting new transcodes; existing originals and generated media are left untouched.

The initial enforced advisory is CVE-2026-8461, an out-of-bounds write in the MagicYUV decoder that can permit remote code execution. The plugin checks whether the magicyuv decoder is enabled, recognizes fixed upstream or backported release lines, reports the CVE explicitly in Diagnostics and WordPress Site Health, and links to the NVD record. Future FFmpeg CVEs should be added to the same advisory registry with their own capability and NVD link.

Current stable release

Current stable release: 1.0.0, published through WordPress.org.

Install from WordPress.org or use the exact ZIP attached to the tagged Forgejo release. Automatically generated source archives are not the canonical installable release artifact.