{"id":343431,"date":"2026-08-05T08:23:19","date_gmt":"2026-08-05T08:23:19","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/bitsplit-media-delivery\/"},"modified":"2026-08-31T09:49:05","modified_gmt":"2026-08-31T09:49:05","slug":"bitsplit-media-delivery","status":"publish","type":"plugin","link":"https:\/\/tir.wordpress.org\/plugins\/bitsplit-media-delivery\/","author":23535988,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.3.0","stable_tag":"1.3.0","tested":"7.1","requires":"5.6","requires_php":"7.4","requires_plugins":null,"header_name":"BitSplit Media Delivery","header_author":"frolpaxa","header_description":"Stop serving ready-to-download media files. Add friction to direct downloads, hotlinking, and generic scraping.","assets_banners_color":"232f49","last_updated":"2026-08-31 09:49:05","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/github.com\/frolpaxa","rating":0,"author_block_rating":0,"active_installs":0,"downloads":144,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.2.4":{"tag":"1.2.4","author":"frolpaxa","date":"2026-08-14 19:11:39","revision":3647848},"1.3.0":{"tag":"1.3.0","author":"frolpaxa","date":"2026-08-31 09:49:05","revision":3673815}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3644855,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3644855,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256},"icon.svg":{"filename":"icon.svg","revision":3644855,"resolution":false,"location":"assets","locale":false}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3673856,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3673856,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.2.4","1.3.0"],"block_files":[],"assets_screenshots":{"screenshot-1.jpg":{"filename":"screenshot-1.jpg","revision":3647848,"resolution":"1","location":"assets","locale":"","width":1280,"height":720},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3673856,"resolution":"2","location":"assets","locale":"","width":1200,"height":675}},"screenshots":{"1":"Enable split media delivery and choose whether public or logged-in visitors may reconstruct media.","2":"See how BitSplit replaces a stable media file URL with incomplete storage and on-demand browser reconstruction."}},"plugin_section":[],"plugin_tags":[15346,163,267775,188691,222],"plugin_category":[50],"plugin_contributors":[274498],"plugin_business_model":[],"class_list":["post-343431","plugin","type-plugin","status-publish","hentry","plugin_tags-hotlinking","plugin_tags-images","plugin_tags-media-protection","plugin_tags-scraping","plugin_tags-video","plugin_category-media","plugin_contributors-frolpaxa","plugin_committers-frolpaxa"],"banners":{"banner":"https:\/\/ps.w.org\/bitsplit-media-delivery\/assets\/banner-772x250.png?rev=3673856","banner_2x":"https:\/\/ps.w.org\/bitsplit-media-delivery\/assets\/banner-1544x500.png?rev=3673856","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":"https:\/\/ps.w.org\/bitsplit-media-delivery\/assets\/icon.svg?rev=3644855","icon":"https:\/\/ps.w.org\/bitsplit-media-delivery\/assets\/icon.svg?rev=3644855","icon_2x":false,"generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/bitsplit-media-delivery\/assets\/screenshot-1.jpg?rev=3647848","caption":"Enable split media delivery and choose whether public or logged-in visitors may reconstruct media."},{"src":"https:\/\/ps.w.org\/bitsplit-media-delivery\/assets\/screenshot-2.png?rev=3673856","caption":"See how BitSplit replaces a stable media file URL with incomplete storage and on-demand browser reconstruction."}],"raw_content":"<!--section=description-->\n<p>BitSplit changes how WordPress delivers public media. Instead of keeping a\ncomplete file at a stable public URL, it stores the original and generated sizes\nas incomplete blocks and reconstructs each file in the visitor's browser through\na short-lived session.<\/p>\n\n<p>It is a media-protection layer for photography portfolios, publishers, member\nsites, and other WordPress sites where making direct downloads and bulk collection\nharder is valuable.<\/p>\n\n<h4>Why use BitSplit?<\/h4>\n\n<ul>\n<li><strong>No stable ready-to-download media URL<\/strong> - public paths serve incomplete\nblocks rather than finished files.<\/li>\n<li><strong>Images, video, and audio<\/strong> - every supported media type is handled by the\nsame delivery flow.<\/li>\n<li><strong>Normal WordPress workflow<\/strong> - use the Media Library, Gutenberg Image, Gallery,\nVideo and Audio blocks, featured images, and responsive <code>srcset<\/code> markup as usual.<\/li>\n<li><strong>Two access modes<\/strong> - keep media public while adding download friction, or\nrequire visitors to sign in before reconstruction.<\/li>\n<li><strong>No external service<\/strong> - reconstruction runs on your WordPress site and in the\nvisitor's browser, with no SaaS account, license key, quota, or payment.<\/li>\n<li><strong>Backup and recovery tools<\/strong> - export a recovery manifest before site changes\nand restore attachment mappings when needed.<\/li>\n<\/ul>\n\n<p>BitSplit is <strong>not encryption, DRM, or a promise that downloading is impossible<\/strong>.\nA determined viewer can inspect the browser flow, automate reconstruction, or\ncapture rendered content. Use it when raising the cost of casual downloading is\nvaluable; use established encryption and access control when confidentiality is\nrequired.<\/p>\n\n<h4>Included functionality<\/h4>\n\n<p>The plugin protects any number of image, video, and audio attachments.\nEvery feature is free: there is no paid tier, license key, trial, add-on, or\nusage quota, and the plugin contacts no external service.<\/p>\n\n<p>It includes public or logged-in-only access, Gutenberg image, gallery, video and\naudio support, featured-image and <code>srcset<\/code> handling, and backup\/recovery tools.<\/p>\n\n<h4>Delivery flow<\/h4>\n\n<ol>\n<li>WordPress stores each file as an incomplete BitSplit block, with reconstruction\ndata stored separately in attachment metadata.<\/li>\n<li>Front-end markup receives a placeholder instead of the original media URL.<\/li>\n<li>The browser establishes an ephemeral P-256 ECDH session.<\/li>\n<li>Reconstruction data is transported with HKDF and AES-256-GCM.<\/li>\n<li>Block bytes require a short-lived, session-bound signed token.<\/li>\n<li>The browser reconstructs the file into a temporary Blob URL. Video and audio\nare streamed through a Service Worker so playback can seek.<\/li>\n<\/ol>\n\n<p>The transport encryption protects reconstruction data in transit; the BitSplit\nblock itself is not encrypted and contains most source bytes.<\/p>\n\n<h4>Access modes<\/h4>\n\n<ul>\n<li><strong>Public visitors<\/strong> - public media remains viewable; BitSplit adds download and\nscraping friction.<\/li>\n<li><strong>Logged-in users only<\/strong> - anonymous visitors cannot obtain reconstruction data\nor block bytes.<\/li>\n<\/ul>\n\n<h4>WordPress coverage<\/h4>\n\n<p>BitSplit handles normal attachment images, Gutenberg Image, Gallery, Video and\nAudio blocks, featured images, <code>srcset<\/code>, classic content containing <code>wp-image-ID<\/code>,\nand the <code>[bitsplit id=\"123\"]<\/code> shortcode.<\/p>\n\n<h4>Storage<\/h4>\n\n<p>Incomplete blocks are stored in a plugin-owned directory resolved through\n    wp_upload_dir(), while reconstruction data stays in WordPress post metadata.\nThe plugin does not write web-server configuration files or require users to edit\nserver configuration.<\/p>\n\n<h4>Requirements<\/h4>\n\n<ul>\n<li>PHP 7.4 or newer<\/li>\n<li>GMP extension<\/li>\n<li>OpenSSL with ECDH support<\/li>\n<\/ul>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>bitsplit-media-delivery<\/code> folder to <code>\/wp-content\/plugins\/<\/code>.<\/li>\n<li>Activate <strong>BitSplit Media Delivery<\/strong>.<\/li>\n<li>Open <strong>Tools -&gt; BitSplit<\/strong>.<\/li>\n<li>Choose an access mode.<\/li>\n<li>Enable split media delivery.<\/li>\n<li>Export the recovery manifest and store it safely.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20bitsplit%20make%20downloading%20impossible%3F\"><h3>Does BitSplit make downloading impossible?<\/h3><\/dt>\n<dd><p>No. Public content must reach the viewer's browser. BitSplit removes the simple\nready-file URL and makes downloaders reproduce the reconstruction protocol.<\/p><\/dd>\n<dt id=\"is%20bitsplit%20encryption%3F\"><h3>Is BitSplit encryption?<\/h3><\/dt>\n<dd><p>No. The reconstruction-data transport uses standard cryptography, but the stored\nBitSplit block is an incomplete, unencrypted representation of the source.<\/p><\/dd>\n<dt id=\"is%20any%20functionality%20locked%20behind%20payment%3F\"><h3>Is any functionality locked behind payment?<\/h3><\/dt>\n<dd><p>No. The plugin is entirely free: every feature and all executable code ship in this\npackage, with no paid tier, license, trial, or quota.<\/p><\/dd>\n<dt id=\"what%20happens%20when%20i%20deactivate%20or%20delete%20the%20plugin%3F\"><h3>What happens when I deactivate or delete the plugin?<\/h3><\/dt>\n<dd><p>The plugin attempts to restore protected attachments to their normal public\npaths before removing its metadata. Keep a current exported manifest and filesystem\nbackup before bulk operations.<\/p><\/dd>\n<dt id=\"does%20it%20need%20python%3F\"><h3>Does it need Python?<\/h3><\/dt>\n<dd><p>No. The codec is implemented in PHP with GMP and in browser JavaScript.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.3.0<\/h4>\n\n<ul>\n<li>Make the plugin fully free: image, video, and audio delivery ship in one package.<\/li>\n<li>Remove the licensing runtime and the separate paid package.<\/li>\n<\/ul>\n\n<h4>1.2.4<\/h4>\n\n<ul>\n<li>Make the directory package a self-contained image plugin with no locked functionality.<\/li>\n<li>Move separately distributed media-type integrations out of the directory package.<\/li>\n<li>Store images only as keyless blocks and do not write web-server configuration.<\/li>\n<\/ul>\n\n<h4>1.2.3<\/h4>\n\n<ul>\n<li>Store images as keyless blocks and migrate records created by earlier versions.<\/li>\n<\/ul>\n\n<h4>1.2.2<\/h4>\n\n<ul>\n<li>Improve activation and deactivation recovery.<\/li>\n<\/ul>\n\n<h4>1.2.1<\/h4>\n\n<ul>\n<li>Preserve protected image settings during updates.<\/li>\n<\/ul>\n\n<h4>1.2.0<\/h4>\n\n<ul>\n<li>Add unlimited image attachment protection.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>Add public and logged-in-only access policies.<\/li>\n<li>Add short-lived session-bound tokens and same-origin checks.<\/li>\n<li>Add Gutenberg Image\/Gallery, featured-image, classic-content, and srcset coverage.<\/li>\n<li>Stream block creation for large image files.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial image delivery prototype with ECDH key transport, browser reconstruction,\nand recovery manifests.<\/li>\n<\/ul>","raw_excerpt":"Replace ready-to-download media URLs with on-demand browser reconstruction to deter hotlinking and generic scraping.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/tir.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/343431","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/tir.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/tir.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/tir.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=343431"}],"author":[{"embeddable":true,"href":"https:\/\/tir.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/frolpaxa"}],"wp:attachment":[{"href":"https:\/\/tir.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=343431"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/tir.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=343431"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/tir.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=343431"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/tir.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=343431"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/tir.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=343431"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/tir.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=343431"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}