pha4wp and PHA concept statement 0.1.3 Conceived: 1 June 2026 Published: 1 August 2026 pha4wp is an independent package verification system for WordPress, designed by Charles Lecklider. pha4wp checks a plugin or theme package before WordPress unpacks the ZIP. It verifies that the package is the one its publisher released, independently of the system that supplied it. The package can come from WordPress.org, a vendor, or another distributor. If it has been substituted or changed, verification fails before its contents are installed. pha4wp is based on PHA (Plugin Hash Authority). PHA separates package identity from package distribution. A publisher identifies the exact package it released through a publisher-controlled DNS record containing the package size and cryptographic digest. Publishing hashes in DNS is not new. PHA provides the glue and trust that make this useful for software distribution: a neutral, consistent way to discover which publisher-controlled record applies to a package and check it before installation. The design is deliberately small, vendor-neutral, and open. Canonical URL: https://pha4wp.org/