How to Check if Images on Your Website Are Copyrighted
Find the images on your site you can't prove you're allowed to use: build an inventory, trace sources, match licenses and decide what to fix first.
By Suraj, founder of PixGuard · Published · Updated
Most websites collect images faster than anyone records where they came from. A designer buys stock photos on their own account, writers add pictures to posts, a theme ships demo photos nobody replaces, a page builder hides backgrounds outside the media library, supplier feeds bring product shots, and customers upload review photos. Years later, the receipts are in a former employee's inbox or gone.
Short answer: You usually can't confirm an image's copyright status by looking at it. Instead, list all the images your site publishes, trace where each one came from, and match it to a license, receipt or contract. Use metadata, watermarks and reverse image search to trace the rest, then license, replace or remove what you can't document.
Many images will turn out to be your own, licensed or free. The goal is to find the ones you can't account for.
Can You Tell if an Image Is Copyrighted?
Usually not by looking at it. In the US, the UK and other Berne Convention countries, an original photo or illustration is protected by copyright automatically once it's created. The owner doesn't need to register it, add a © symbol or watermark it first (US Copyright Office, Circular 1; GOV.UK; WIPO). Assume someone owns each image.
Finding an image online doesn't give you permission to use it. Even Google's help page for the Images "Usage rights" filter tells you to confirm the license with the provider and the host site (Google Search Help). More in our guide to using Google Images on your website.
The exceptions are real but narrow:
- Public domain. In the US, works published before 1931 are public domain as of 2026 (Cornell University Library), and works made by federal employees as part of their official duties aren't protected by US copyright (17 U.S.C. 105). Terms differ by country.
- Creative Commons and other free licenses. These are permissions with conditions, such as attribution or no commercial use. See Creative Commons licenses explained for website owners.
- Your own and commissioned work. Check contracts: a photographer may license photos to you rather than transfer copyright.
So the useful question is whether you can show you're allowed to use each image. This guide is general information, US-focused where specific, and not legal advice.
How to Check Images on Your Website for Copyright Issues
Steps 1 to 3 establish what you have and can prove, steps 4 to 7 gather evidence, and steps 8 to 10 turn findings into decisions. Track everything in one spreadsheet:
| Column | What to record |
|---|---|
| Image URL | File URL or CMS media ID |
| Page URLs | Every page showing the image |
| Added | Date and who added it (person, agency, feed, theme) |
| Origin | Own, commissioned, stock, free library, Creative Commons, supplier, user upload, AI or unknown, with a source link |
| License | Type (standard, extended, editorial, CC BY 4.0) and licensee |
| Proof | Order number, invoice or contract, and its location |
| Signals | Metadata credit, watermark, search match, scanner flag |
| Status | Verified, likely OK, unclear, problem |
| Decision | Keep, license, attribute, replace or remove; who and when |
For a full audit checklist, see our step-by-step website image audit guide.
1. Build an inventory of the images you publish
List all the images the public can see, from your CMS, a crawl of the live site and the other sources in the next section.
Shows: how many images you have and where. Doesn't show: anything about rights.
2. Identify where each image came from
Upload dates and authors narrow things down, and filenames often reveal the source: shutterstock_123456789.jpg, GettyImages-123456789.jpg and AdobeStock_123456789.jpeg are default download names. Ask former designers, agencies and writers what they used. Track visitor uploads separately: in the US, the DMCA safe harbor in 17 U.S.C. 512(c) can protect sites that meet its conditions, such as designating an agent and removing material promptly on notice.
Shows: where proof should exist. Doesn't show: whether anyone licensed it.
3. Check your licensing records
Search email and accounting for stock receipts, photographer and agency invoices, and supplier agreements for product photos. Check each contract's scope: web or print, ads, duration, and whether you got a license or the copyright.
Shows: your strongest evidence. Doesn't show: whether the license still fits how you use the image.
4. Inspect metadata where available
Open the original file in a metadata viewer and look for Creator, Copyright Notice and Credit Line (details below).
Shows: often a creator or agency. Doesn't show: anything reliable once stripped or edited.
5. Look for watermarks and attribution
At full size, look for agency names or logos, "preview" or "sample" text, faint tiled marks and signatures. A watermarked preview in production usually means nobody bought the license. Creative Commons images need attribution with title, author, source and license (Creative Commons). PixGuard's free watermark detector checks a single file. Never crop out a watermark: in the US, intentionally removing copyright management information, knowing or having reason to know it will help conceal infringement, can create separate liability (17 U.S.C. 1202).
Shows: strong leads when marks exist. Doesn't show: anything when there's no mark; a credit line isn't a license.
6. Run reverse image searches when appropriate
Search images with an unknown origin, a stock look or no records (details below).
Shows: where else the image appears, often a stock listing. Doesn't show: who owns it or whether you're licensed.
7. Check stock and provider records
Search each provider account's license history for the asset ID; confirm license type and licensee (details below).
Shows: whether you hold a license and its scope. Doesn't show: whether someone else's download covers your site.
8. Flag images where ownership or licensing is unclear
Give every row a status. Verified: documented license, ownership or free license. Likely OK: plausible source, no proof yet. Unclear: no source, no record. Problem: watermarked preview, a license that doesn't fit the use, or an existing claim.
Shows: which images need work. Doesn't show: infringement. Unclear means undocumented.
9. Prioritize images for investigation
Weigh signal strength against page visibility.
| Priority | Typical signals | What to do |
|---|---|---|
| 1. Fix first | Agency watermark; stock filename or metadata with no license; image named in a claim | License it or take it down (with legal advice if there's a claim); check other pages for the file |
| 2. Investigate next | Stock or photographer match with no record; homepage, product or ad images; a former designer's images | Trace the source, search records, contact the provider |
| 3. Verify when you can | Older posts; supplier, theme or user images | Confirm supplier, theme and upload terms in bulk |
| 4. Document and move on | Your own photos, commissioned work with a contract, verified licenses | Record where the proof is stored |
10. Replace, license, attribute or remove
License images worth keeping, and ask whether the license covers past use. Attribute Creative Commons images correctly. Replace with your own or documented images (replacing copyrighted images safely). Remove every copy: resized versions, CDN copies and other pages using the file.
Fixing an image stops future use but doesn't erase past use, which is why the decision record matters.
Checking images one by one takes time
PixGuard flags images with copyright risk signals, so you know which ones to investigate first. Paste a page URL to check its 3 largest images, free and without signup.
How to Find All the Images on Your Website
Page-by-page checks miss a lot: templates repeat images across many URLs, sliders load lazily, themes serve several sizes per file, and some images never appear in the HTML. Combine these sources and de-duplicate by file:
- CMS media library export. In WordPress, use Tools > Export > Media or run
wp post list --post_type=attachment --format=csv. This includes files no page uses. - A site crawler. Screaming Frog SEO Spider, free for up to 500 URLs, exports image URLs with the pages that use them.
- XML sitemaps. Many SEO plugins add image entries: a quick cross-check.
- CDN and storage listings. Images served from S3, Cloudflare R2 or an image CDN may never touch your CMS.
- CSS backgrounds. Search your theme's stylesheets for
background-imageandurl(. - PDFs. Brochures and catalogs carry photos; Acrobat or
pdfimagescan extract them. - Email templates. Newsletter platforms host their own image libraries.
- Old landing pages. Unlinked campaign pages still load. Compare ad and analytics landing-page reports with your crawl.
- Social share images. Each page's
og:imageshows whenever it's shared.
Past a few hundred images, this gets slow. A scanner can take the first pass. PixGuard, for example, crawls up to 50 pages from a URL you enter and scores the images it finds for copyright risk signals, up to your plan's per-scan limit. It reads standard image tags and inline background styles only, so keep the manual sources for stylesheet backgrounds, srcset variants, social share images, PDFs and images loaded by JavaScript.
You can try it on one page without an account; PixGuard checks that page's 3 largest images. Scan Your Website with PixGuard →
How Reverse Image Search Helps
Reverse image search finds other places the same or a similar image appears online, which can surface the stock listing or photographer an image came from.
- Tools. Google Lens, Bing Visual Search and TinEye index different parts of the web, so use more than one.
- Reading matches. A match on Shutterstock, Adobe Stock, Getty Images or iStock means the image is sold under license: find the asset ID and search your accounts for it. A photographer's portfolio tells you who to ask. Dozens of matches on unrelated blogs don't make an image free, since popular stock photos spread the same way; look for the stock or free-library listing among them.
- Earliest appearance. TinEye can sort results by oldest, but its "first found" date is when its crawler first saw the image, not when it was published (TinEye Help). Treat the earliest result as a lead.
A match isn't proof of ownership, because the earliest copy online may itself be a copy. A stock match doesn't mean you're unlicensed; you may have bought it. No match doesn't mean an image is free, since crops and filters often defeat the search. See our reverse image search guide.
How to Check Image Metadata
Image files can carry text fields describing who made them and on what terms.
| Format | What it is | Rights-related fields |
|---|---|---|
| EXIF | Camera data written at capture | Artist, Copyright, camera model, date taken |
| IPTC | Rights data added by photographers and agencies (IPTC standard) | Creator, Copyright Notice, Credit Line, Source, Rights Usage Terms |
| XMP | A container that can hold IPTC fields and more | IPTC fields, plus Web Statement of Rights and Licensor URL |
To view them:
- Windows: right-click the file, choose Properties, open Details and look under Origin for Authors and Copyright.
- macOS: open the file in Preview, choose Tools > Show Inspector, then the More Info tab, which shows EXIF and IPTC sections when present.
- Online: PixGuard's free image metadata viewer shows EXIF, IPTC, XMP and ICC fields for an uploaded image, no signup needed. ExifTool can read a whole folder at once.
Metadata has three limits. It's often stripped by editing tools, CMSs, CDNs and social platforms, so check the original upload where you can. It's easy to edit, so a name in it is a claim, not proof. And missing metadata does not mean an image is copyright-free: copyright doesn't depend on a notice in the file. Still, an agency name in the Credit Line is a strong lead (what EXIF metadata reveals about ownership).
How to Check Stock Images
For stock images, the proof sits in the account that bought them.
- Find the asset ID in the filename, the metadata or the listing you found by reverse search.
- Search the license or download history of every Shutterstock, Adobe Stock, Getty Images or iStock account your business, agencies and past staff used. Export or screenshot the record.
- Match it to a receipt. Invoices, order confirmations and subscription statements show who paid and when.
- Compare the license type with your use. Standard licenses usually cover web use but limit print runs, merchandise and templates for resale, which typically need an extended or enhanced license. Editorial-only images can't promote a product. See what Shutterstock and Adobe Stock licenses allow.
- Check whose name is on it. If an agency or freelancer bought it, ask them to transfer the license where the provider allows, or buy one in your company's name; an IP attorney writing for IPWatchdog recommends keeping stock accounts in the business's name. See agency or client: who's liable.
For each verified image, store the provider, asset ID, license type, licensee, order number, date and a PDF of the terms at purchase. For free libraries such as Unsplash or Pexels, save the image page URL and the license.
How to Audit a WordPress Website
WordPress sites build up images in predictable places:
- Media Library list view. Under Media > Library, list view shows each file's author, the post it was uploaded to and the date, all sortable. The type filter includes Unattached, for uploads not attached to any post (WordPress documentation). Unattached doesn't mean unused: images uploaded to the library and later inserted into posts can still show as unattached.
- The uploads folder. By default, files sit in
wp-content/uploads/YYYY/MM, so you can review the oldest years first. - Page builders. Elementor, Divi and similar builders set backgrounds in their own settings, often output through CSS files many crawlers don't read.
- Theme demo content. Demo imports add sample images that are often licensed for the demo only. Check the theme's documentation.
- Resized copies. WordPress keeps EXIF, IPTC and XMP data in resized images only if your host uses Imagick; GD strips it (WordPress developer reference). Read metadata from the original upload.
PixGuard also has a WordPress plugin, PixGuard Scanner, in the WordPress.org plugin directory. You connect it to your account with an API key from your PixGuard dashboard settings, and each new image it checks uses one image credit.
See how PixGuard works with WordPress sites. Audit Your WordPress Images →
What to Do When You Find an Image With Unclear Licensing
- Find the original source with the filename, metadata and reverse image search (see how to find out who owns an image).
- Check every stock account your business, agencies and former staff used for a license.
- Search internal records: email, shared drives, invoices and original design files, which may keep the stock ID in a layer name.
- Contact the creator or provider when appropriate. If it's worth keeping, ask for a license in writing.
- Replace the image if rights can't be established, and remove every copy.
- Document the decision: what you checked and found, what you decided, who decided and when.
If you've already received a demand letter or takedown notice, get legal advice before you respond, pay or contact the sender. A demand letter is a settlement request, not a court judgment. Removing the image promptly is usually wise, since in the US continued use after notice can support a willfulness claim, but save screenshots first. See responding to a Getty Images demand letter, what to do about a DMCA takedown notice and how damages per image are calculated.
Common Mistakes Website Owners Make
- Assuming Google Images means an image is free to use. Google Images indexes other people's images, so check the license on the source page, as Google advises.
- Assuming an image without a watermark is free. Copyright doesn't depend on a watermark, and most professional photos online don't have one.
- Assuming an image without metadata is public domain. Editing tools, CMSs and CDNs strip metadata routinely, so its absence says nothing about rights.
- Assuming "found online" means licensed. Another site's license covers that site, so your use needs its own permission.
- Forgetting about old blog images. Undocumented images cluster in posts from before you tracked sources, so audit the oldest years first.
- Forgetting images inside PDFs and media libraries. Downloads and unused uploads are still publicly reachable, so inventory them too.
- Relying on a single reverse image search. Engines index different parts of the web and miss edited copies, so an empty result means "unknown", not "clear".
Can PixGuard Check My Website for Copyright Risks?
Yes for finding risk signals, no for legal answers. PixGuard is an auditing and research tool, not a legal authority: it flags images that deserve a closer look and shows why, but it can't see your license records or decide whether a use is authorized, so ownership and licensing still need to be verified. Instead of checking hundreds of images by hand, you can have it crawl your site and rank what it finds by risk.
What it checks in a free or paid account:
- EXIF, IPTC and XMP copyright and creator fields
- visible watermark text and logos from major stock agencies such as Shutterstock, Getty Images and Adobe Stock
- matches against a database of reference image fingerprints
- signs that an image is AI-generated
- on Pro and Business: AI similarity matching, AI vision review of borderline images, and a source lookup showing web pages where a matching image appears (for higher-risk images)
What you get: a 0 to 100 risk score per image, with a severity level and the signals behind it, sorted by risk with High, Medium and Low counts. You see the estimated credit cost first, and rescanning images PixGuard has already analyzed costs no credits. Free accounts see the top 2 signals per image; Pro and Business see all.
Limits to plan around:
- Up to 50 pages per scan, following links on the exact host you enter (use the www or non-www version your site serves).
- New images per scan: 10 on Free, 500 on Pro, 2,000 on Business. Images you've already scanned don't count toward the cap, so a repeat scan moves on to the next new images.
- It reads image tags and inline background styles only; the other sources in the inventory section still need a manual check.
- Results show each image's URL but not the page it appeared on, and there's no CSV export, so keep your crawl for page mapping.
- Bot-protected sites may need to allowlist PixGuardBot.
Free options:
- No account: paste a page URL and PixGuard checks that page's 3 largest images, up to 3 times a day. This quick check looks for watermark patterns and visual risk signals; metadata and fingerprint checks need an account.
- Free account: 30 image scans, no card required, valid for 30 days after signup.
- Free tools, no signup: metadata viewer, watermark detector and image hash calculator.
Pro ($29 a month, about 250 images a month) and Business ($79 a month, about 1,000 images a month) add the deeper checks, plus checks on images inside an uploaded PDF.
To check more than one page, start a website image audit with a free account.
Frequently Asked Questions
How do I check if an image on my website is copyrighted?
Assume it is, then check whether you can prove you're allowed to use it: a license, receipt or contract covering your use. If there isn't one, trace the source with metadata, watermarks and reverse image search, then license, replace or remove it. See how to check if an image is copyrighted for single images.
How can I check all images on my website?
Combine a media library export with a crawl of the live site, then add images from stylesheets, PDFs, email templates and CDN storage, recording each image and its pages in one spreadsheet. A scanner such as PixGuard speeds up the first pass by flagging which images to investigate, but no single tool sees them all.
Is an image from Google Images copyrighted?
Usually, yes. Google Images indexes images published on other websites, and most are protected by copyright. The Usage rights filter narrows results to Creative Commons or commercial licenses, but Google's own help page says to confirm the license with the image's host and license provider before using it.
Does reverse image search prove copyright ownership?
No. Reverse image search shows where the same or a similar image appears online, which can point to a stock listing or photographer. It can't show who owns the copyright, whether you hold a license, or when the image was first published. The earliest copy it finds may itself be a copy.
Does EXIF data prove who owns an image?
No. EXIF, IPTC and XMP fields can name a creator or agency, a useful lead, but anyone can edit them and many platforms strip them. Treat a name in the metadata as a claim to verify against a license or the creator's own listing. Missing metadata doesn't make an image free to use.
Can I use an image if there is no watermark?
Not on that basis alone. Copyright applies automatically, with or without a watermark, a © notice or metadata, and most professional photos online have no visible watermark. You need a license, permission, your own ownership, or a confirmed public domain or Creative Commons status that covers your use.
How do I find the original source of an image?
Start with the filename and metadata, which often include a stock asset ID or creator name. Then run the image through Google Lens, Bing Visual Search and TinEye, looking for a stock listing or photographer's portfolio. Finally, search your email and stock accounts for a matching download or receipt.
How do I audit a WordPress site for copyrighted images?
Export the Media Library with Tools > Export > Media or WP-CLI, review it in list view by date and author, and use the Unattached filter to find forgotten uploads. Then crawl the live site for theme images and old posts, and search page-builder stylesheets for background images. Match each image to a license or source, oldest uploads first.
What should I do if I cannot find the license for an image?
Treat it as undocumented, not automatically infringing. Search every stock account, inbox and contract your business and past contractors used, and trace the source. If you still can't establish rights, license the image from its owner or replace it and remove every copy. Record what you checked and decided.
Can PixGuard scan my entire website?
Not in one pass on most sites. A PixGuard website scan crawls up to 50 pages and analyzes up to 10 new images per scan on Free, 500 on Pro or 2,000 on Business, and it misses stylesheet backgrounds, srcset variants, PDFs and JavaScript-loaded images. It's a first pass that ranks images for investigation, not a complete inventory or a legal verdict.
See which images on your site need a closer look
Paste a page URL and PixGuard checks its 3 largest images for copyright risk signals, free and without signup. A free account adds 30 image scans (valid 30 days); each site scan crawls up to 50 pages and checks up to 10 new images on the free plan.