pha4wp

Independent package verification for WordPress

What pha4wp achieves

pha4wp checks a plugin or theme package before WordPress unpacks the ZIP. It verifies that the package is the one its publisher released, independently of the system that supplied it.

The package can come from WordPress.org, a vendor, or another distributor. If it has been substituted or changed, verification fails before its contents are installed.

PHA

PHA separates package identity from package distribution. A publisher identifies the exact package it released through a publisher-controlled DNS record containing the package size and cryptographic digest.

Publishing hashes in DNS is not new. PHA provides the glue and trust that make it useful for software distribution: a neutral, consistent way to discover which publisher-controlled record applies to a package and check it before installation.

The design is deliberately small, vendor-neutral, and open.

PHA and pha4wp are under development. The protocol and implementation have not yet been published.

Provenance

PHA was conceived by Charles Lecklider on 1 June 2026. This initial public statement was published and independently timestamped on 1 August 2026.

An immutable copy of the statement is accompanied by independent timestamp proofs: