{"id":354221,"date":"2026-09-03T00:52:47","date_gmt":"2026-09-03T00:52:47","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/sigilet\/"},"modified":"2026-09-03T01:17:48","modified_gmt":"2026-09-03T01:17:48","slug":"sigilet","status":"publish","type":"plugin","link":"https:\/\/brx.wordpress.org\/plugins\/sigilet\/","author":23547034,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.6.5","stable_tag":"1.6.5","tested":"7.1","requires":"6.4","requires_php":"8.0","requires_plugins":null,"header_name":"Sigilet","header_author":"Sigilet","header_description":"Mint and issue Open Badges 2.0 using hosted verification. Create badge types, award them to recipients by email (hashed + salted), and publish standards-compliant Issuer, BadgeClass, and Assertion JSON with a human-friendly verification page.","assets_banners_color":"694832","last_updated":"2026-09-03 01:17:48","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/sigilet.com\/wordpress-plugin\/","header_author_uri":"","rating":0,"author_block_rating":0,"active_installs":0,"downloads":47,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.6.4":{"tag":"1.6.4","author":"sigilet","date":"2026-09-03 00:52:32","revision":3678830},"1.6.5":{"tag":"1.6.5","author":"sigilet","date":"2026-09-03 01:17:48","revision":3678838}},"upgrade_notice":{"1.6.2":"<p>Pro licensing moves to Sigilet&#039;s own service. Pro installations need a Sigilet license key, entered on the License screen, after updating. The WordPress.org build is unaffected.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3678826,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3678826,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500-rtl.png":{"filename":"banner-1544x500-rtl.png","revision":3678826,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3678826,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250-rtl.png":{"filename":"banner-772x250-rtl.png","revision":3678826,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3678826,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.6.4","1.6.5"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3678826,"resolution":"1","location":"assets","locale":"","width":1400,"height":700},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3678826,"resolution":"2","location":"assets","locale":"","width":1400,"height":860},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3678826,"resolution":"3","location":"assets","locale":"","width":1100,"height":760},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3678826,"resolution":"4","location":"assets","locale":"","width":1100,"height":1100},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3678826,"resolution":"5","location":"assets","locale":"","width":1400,"height":876}},"screenshots":{"1":"Award History with revoke controls.","2":"The Award a Badge workflow.","3":"A hosted verification page.","4":"The recipient sharing hub (LinkedIn, download, copy link\/embed).","5":"Issuer settings."}},"plugin_section":[],"plugin_tags":[2306,44546,18342,192752,712],"plugin_category":[],"plugin_contributors":[278939],"plugin_business_model":[],"class_list":["post-354221","plugin","type-plugin","status-publish","hentry","plugin_tags-badges","plugin_tags-certificates","plugin_tags-elearning","plugin_tags-open-badges","plugin_tags-verification","plugin_contributors-sigilet","plugin_committers-sigilet"],"banners":{"banner":"https:\/\/ps.w.org\/sigilet\/assets\/banner-772x250.png?rev=3678826","banner_2x":"https:\/\/ps.w.org\/sigilet\/assets\/banner-1544x500.png?rev=3678826","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/sigilet\/assets\/icon-128x128.png?rev=3678826","icon_2x":"https:\/\/ps.w.org\/sigilet\/assets\/icon-256x256.png?rev=3678826","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/sigilet\/assets\/screenshot-1.png?rev=3678826","caption":"Award History with revoke controls."},{"src":"https:\/\/ps.w.org\/sigilet\/assets\/screenshot-2.png?rev=3678826","caption":"The Award a Badge workflow."},{"src":"https:\/\/ps.w.org\/sigilet\/assets\/screenshot-3.png?rev=3678826","caption":"A hosted verification page."},{"src":"https:\/\/ps.w.org\/sigilet\/assets\/screenshot-4.png?rev=3678826","caption":"The recipient sharing hub (LinkedIn, download, copy link\/embed)."},{"src":"https:\/\/ps.w.org\/sigilet\/assets\/screenshot-5.png?rev=3678826","caption":"Issuer settings."}],"raw_content":"<!--section=description-->\n<p>Issue real, verifiable digital badges from the site you already run.<\/p>\n\n<p>Sigilet turns WordPress into a badge issuer. Design a badge, award it by email, and your recipient gets a credential they can share on LinkedIn, download, and point any employer at - hosted on your domain, under your organization's name.<\/p>\n\n<p>No badge platform. No per-badge fees. No account for your recipients to create.<\/p>\n\n<h4>How it works<\/h4>\n\n<ol>\n<li><strong>Create a badge type.<\/strong> Title, description, criteria, image - it's just a WordPress post type.<\/li>\n<li><strong>Award it.<\/strong> Enter a recipient's email and issue it live, email the recipient, or hold it as a draft until launch day.<\/li>\n<li><strong>They share it.<\/strong> Every award gets a clean public verification page, a LinkedIn share button, and a downloadable badge file that carries its own proof.<\/li>\n<\/ol>\n\n<h4>Why issuers pick Sigilet<\/h4>\n\n<ul>\n<li><strong>It's your credential, on your domain.<\/strong> Verification pages live on your site and carry your organization's name - recipients and employers never leave your domain to check a badge.<\/li>\n<li><strong>Recipients never sign up for anything.<\/strong> They click a link and see their badge. That's the whole experience.<\/li>\n<li><strong>Built on an open standard, not a walled garden.<\/strong> Badges are <a href=\"https:\/\/www.imsglobal.org\/spec\/ob\/v2p0\/\">Open Badges 2.0<\/a> credentials, readable by any conformant wallet, backpack, or verifier.<\/li>\n<li><strong>Recipient privacy is the default.<\/strong> Email addresses are never stored - only a salted, per-award hash. More on that below.<\/li>\n<li><strong>Right-sized for small teams.<\/strong> A handful of issuers, sensible volume, delivered over your site's existing <code>wp_mail<\/code>.<\/li>\n<\/ul>\n\n<h4>What you get<\/h4>\n\n<ul>\n<li><strong>Badge types<\/strong> as a custom post type - title, description, criteria, tags, featured image.<\/li>\n<li><strong>Award workflow<\/strong> with three modes: draft\/embargoed, live, or live + email the recipient.<\/li>\n<li><strong>Hosted verification<\/strong> - every assertion resolves at a stable public URL, on your domain, with a <code>\"verification\": { \"type\": \"hosted\" }<\/code> block.<\/li>\n<li><strong>Revocation<\/strong> - one-click revoke\/un-revoke from the award history; revoked assertions report <code>\"revoked\": true<\/code> and show a watermark on the verification page.<\/li>\n<li><strong>Expiry<\/strong> - optional per-award expiry date, surfaced in JSON and on the verification page.<\/li>\n<li><strong>Dedicated roles &amp; capabilities<\/strong> - grant <code>Badge Issuer<\/code> or <code>Badge Viewer<\/code> access without handing over WordPress post-editing rights.<\/li>\n<li><strong>Recipient sharing hub<\/strong> - a private-to-the-recipient panel on the verification page with a \"Share to LinkedIn feed\" button, badge download, copy-link and copy-embed buttons, plus Open Graph \/ Twitter Card tags so shared links unfurl with the badge image. An optional \"Add to LinkedIn\" (certifications) button can be enabled in settings.<\/li>\n<li><strong>Badge baking<\/strong> - the download button serves a <em>baked<\/em> PNG that carries its own assertion URL inside the file, so the badge is a self-describing, wallet-importable credential rather than just a picture.<\/li>\n<\/ul>\n\n<h4>Recipient privacy, in detail<\/h4>\n\n<p>Recipient email addresses are never stored. Each award saves only a per-assertion <strong>salted SHA-256<\/strong> identity hash (<code>sha256$\u2026<\/code>), exactly as the Open Badges hashed <code>IdentityObject<\/code> allows. Identical emails produce different hashes across awards, so two badges held by the same person cannot be correlated from the public JSON. The plaintext address is used only to send the optional award notification, then discarded.<\/p>\n\n<h4>Under the hood<\/h4>\n\n<p>Sigilet publishes standards-compliant Issuer, BadgeClass, and Assertion JSON alongside a friendly, theme-independent verification page - no third-party badge service sits between you and your recipients. Baking follows the Open Badges PNG <code>iTXt<\/code> convention; PNG uploads are baked directly, and GIF\/WebP\/AVIF are converted first where the server's GD extension supports the source format.<\/p>\n\n<h4>Pro<\/h4>\n\n<p>The <strong>CSV bulk award<\/strong> feature - import a spreadsheet of recipients and dispatch awards through a paced background email queue - is a separate Sigilet Pro package and is <strong>not part of this download<\/strong>. Its code is not included here in any form: there is no locked screen, no disabled control, and no trial. Everything this plugin does - issuance, hosted verification, baking, roles, revocation, expiry, and sharing - is free, complete, and never expires.<\/p>\n\n<h3>External services<\/h3>\n\n<p>The free WordPress.org build makes no licensing, analytics, or update request to a third party. Its updates come only from WordPress.org.<\/p>\n\n<p>The <strong>Pro build<\/strong> connects to the <strong>Sigilet licensing service<\/strong> (licence.sigilet.com) for license activation, daily license validation, and authenticated Pro updates.<\/p>\n\n<ul>\n<li><strong>Data sent:<\/strong> the Pro license key, a one-way SHA-256 hash of this site's address, this site's URL (on activation only), and the installed plugin version (on update checks only).<\/li>\n<li><strong>When it is sent:<\/strong> when an administrator activates or deactivates a license; once a day when WordPress checks the license is still current; and when WordPress checks for Pro updates.<\/li>\n<li><strong>No analytics:<\/strong> no site diagnostics, administrator details, installed themes or plugins, and no badge-recipient data are sent, at any time.<\/li>\n<li><strong>Local storage:<\/strong> the license key and a signed entitlement token are stored in the site's WordPress options table. The token is verified on this site, offline, so Pro features keep working through a service outage.<\/li>\n<\/ul>\n\n<p>Pro checkout is provided by <strong>Polar<\/strong>, the merchant of record, through Sigilet's external pricing page. The plugin does not embed Polar, receive payment details, or call Polar's API. Polar processes the customer's account, payment, tax, invoice, refund, and subscription data during checkout and billing management.<\/p>\n\n<p>Badge recipients' personal data is never sent to the licensing service, Polar, or any other external service. Review <a href=\"https:\/\/sigilet.com\/privacy\/\">Sigilet's Privacy Policy<\/a> and <a href=\"https:\/\/polar.sh\/legal\/privacy\">Polar's Privacy Policy<\/a>.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin to <code>wp-content\/plugins\/<\/code>, or install it from the Plugins screen, and activate <strong>Sigilet<\/strong>.<\/li>\n<li>Go to <em>Sigilet \u2192 Settings<\/em> and fill in your organization name, URL, and contact email.<\/li>\n<li>If verification URLs return 404, visit <em>Settings \u2192 Permalinks<\/em> and click <strong>Save Changes<\/strong> once to flush rewrite rules.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"where%20are%20recipient%20email%20addresses%20stored%3F\"><h3>Where are recipient email addresses stored?<\/h3><\/dt>\n<dd><p>They are not. Sigilet stores only a per-assertion salted SHA-256 hash of the recipient's email, per the Open Badges hashed <code>IdentityObject<\/code>. The plaintext address is used only to send the optional award notification and is then discarded.<\/p><\/dd>\n<dt id=\"do%20i%20need%20a%20third-party%20badge%20platform%3F\"><h3>Do I need a third-party badge platform?<\/h3><\/dt>\n<dd><p>No. Badges are issued and verified entirely on your own WordPress domain. The Pro build contacts Sigilet's licensing service only to check the license and fetch Pro updates; purchases occur through Polar outside WordPress. Neither service hosts badges or receives recipient data.<\/p><\/dd>\n<dt id=\"is%20sigilet%20free%3F\"><h3>Is Sigilet free?<\/h3><\/dt>\n<dd><p>Yes. Everything in this download is free and never expires: issuance, hosted verification, baking, roles, revocation, expiry, and recipient sharing. Nothing is time-limited, quota-limited, or locked behind an upgrade. CSV bulk award is a separate Pro package that is not included in this plugin at all.<\/p><\/dd>\n<dt id=\"what%20image%20formats%20can%20be%20baked%3F\"><h3>What image formats can be baked?<\/h3><\/dt>\n<dd><p>The Open Badges spec defines baking for PNG. PNG uploads are baked directly. GIF\/WebP\/AVIF uploads are converted to PNG first when the server's GD extension supports the source format; otherwise the original image is served unbaked.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.6.5<\/h4>\n\n<ul>\n<li>Removed the one-time migrations that retired the licensing providers Sigilet no longer uses. Freemius (retired at 1.6.0) and Appsero (removed at 1.6.2) both left records behind on installs that ran them, and a premium-only migration cleaned those up on upgrade. No install that can still be reached needs it: Appsero was never configured in any shipped build, so no site could hold its records, and the remaining Freemius installs are being moved onto Sigilet's own licensing service directly rather than migrated. Sites installed from WordPress.org never carried either migration and are unaffected.<\/li>\n<\/ul>\n\n<h4>1.6.4<\/h4>\n\n<ul>\n<li>Internal clarity only, no functional change: the base64 @font-face rule embedded in preset badge SVGs now lives in the SVG asset file assets\/presets\/inter-font-face.svg instead of a PHP string. It is SVG-document markup handed to the image rasterizer, never web-page output, so it has no enqueue path; keeping it in an asset file makes that visible at a glance.<\/li>\n<\/ul>\n\n<p>Earlier releases are listed in <code>changelog.txt<\/code>, bundled with the plugin.<\/p>","raw_excerpt":"Mint and issue Open Badges 2.0 from your own WordPress site: hosted verification, salted-hash recipient privacy, and baked PNG downloads.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/brx.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/354221","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/brx.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/brx.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/brx.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=354221"}],"author":[{"embeddable":true,"href":"https:\/\/brx.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/sigilet"}],"wp:attachment":[{"href":"https:\/\/brx.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=354221"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/brx.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=354221"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/brx.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=354221"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/brx.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=354221"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/brx.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=354221"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/brx.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=354221"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}