Activity Log Pro – User Activity Log, Audit Log & Security Monitor
Activity Log Pro is a complete WordPress activity log, user activity log, and audit log plugin for user tracking and accountability. Track user logins, content changes, plugin and theme updates, settings changes, and other important site activity – and see who did what, when, and where from one clean activity dashboard. Activity Log Pro gives you a complete audit trail of everything happening on your WordPress site. See who logged in, what content changed, exactly when it happened, which plugins were updated and any suspicious activity – all in one place. Perfect for businesses, e-commerce stores, agencies, WordPress maintenance services, and multi-user sites that need full visibility into user and system changes. Agencies and freelancers managing multiple sites can use Log Channels (Premium) to centralise logs from every client site into a single logging platform like Datadog or Better Stack. Whether you’re troubleshooting issues, staying compliant, or monitoring for security threats, Activity Log Pro is your WordPress activity tracker and activity monitoring tool to keep your site secure and transparent. “This is a super slick plugin guys. Very simple to use, very clean interface. Super excited about it.” – Ryan @ InfluenceWP.com “Perfect! Robust and exemplary neat plugin! All the info that you need is in a clear overview.” – @mixha Why Use a WordPress Activity Log? Understand every action on your site, reduce security risks, and simplify compliance. Security & Compliance: Stay compliant with GDPR, HIPAA, and other regulations while detecting failed logins, role changes, and suspicious behavior. Troubleshooting & Debugging: See exactly what changed before something broke – track plugin updates, theme edits, and content changes. User Accountability & Audit Trails: Know exactly who did what, when, and from which IP address for complete transparency and legal compliance. Performance & Site Health: Monitor plugin installations, theme changes and modifications that impact your site’s speed and stability. Enhanced Backup Strategy: Create detailed change logs that complement your backups – know exactly what to restore and when changes occurred. WordPress Security Monitoring: Track failed logins, suspicious activities, user role changes, and potential security threats in real-time. Key Features of This WordPress Activity Log Plugin 🚀 Complete Core Activity Tracking User login/logout activities with IP tracking Failed login attempt monitoring for security Login Flood Guard (optional) — caps consecutive failed-login log entries during brute-force bursts; configurable threshold (20/50/100/200), on/off toggle, and an inline notice on the Activity Logs screen when suppression is active Post, page, and custom post type changes (create, update, delete) Media library activities (upload, edit, delete) Plugin installations, activations, deactivations, and updates Theme switches, installations, and customizer changes WordPress core updates Widget modifications and placement changes Menu creation, updates, and deletions User registration, profile updates, and role changes Comment activities (approved, spam, trash, delete) Settings and options changes Category and tag management 🔌 Advanced Plugin Integrations WooCommerce Activity Log: Complete e-commerce activity monitoring — track order modifications, product changes, inventory updates, customer data edits, payment gateway settings, and coupon usage for full store audit trails (Premium) Yoast SEO Activity Log: Monitor all SEO changes including meta descriptions, title tags, search engines follow links, Advanced Meta Robots, Breadcrumbs Title updates, focus keyword changes, and readability optimizations to maintain SEO integrity (Premium) Free Professional Features Real-time activity monitoring dashboard Advanced filtering and search capabilities Detailed activity metadata and context IP address tracking for security analysis User role-based activity permissions Customizable data retention policies Export capabilities (CSV, JSON, HTML and TXT formats) Clean, responsive admin interface Database optimization for performance 💎 Premium Features Upgrade to Activity Log Pro Premium for advanced security and privacy controls: Advanced IP Privacy Controls – GDPR-compliant IP anonymization and masking options IP Location Mapping – Geographical insights for visitor analysis and security monitoring Security Alerts – Security Alerts helps you detect important WordPress activity in real time with instant email notifications for security events, content changes, and core/plugin updates. Configure smart alert cooldowns, choose multiple recipients, and reduce noise while still catching high-risk behavior fast. Log Channels – Centralise activity logs from all your WordPress sites into one platform. Stream every log entry in real time to Grafana Loki, Better Stack, Slack, Papertrail, Loggly, Datadog, Syslog/SIEM targets, or your own custom webhook endpoint. Every event is automatically tagged with the site name and URL — so you can filter across all your sites inside your existing logging platform. Delivered asynchronously in background jobs with zero impact on page load times. Ideal for agencies, WordPress maintenance services, and freelancers managing multiple client sites. Enhanced Security Features – Real-time logs and suspicious activity logs (via Live Monitor) JSON Feed Export – SIEM integration with secure token-based access WooCommerce Logger – Comprehensive e-commerce tracking (orders, products, customers) Yoast SEO Logger – Complete SEO audit trails for meta data and schema changes Priority Support – Direct access to expert support with faster response times 👉 Compare Free vs Premium Features → | 👉 Try out the Demo → 🏢 Centralised Logging for Agencies & WordPress Maintenance Services Managing multiple WordPress sites? Log Channels (Premium) lets you stream activity logs from every client site into a single external logging platform — so you can monitor all your sites in one place, without logging into each WordPress admin individually. How it works: Install Activity Log Pro on each WordPress site, configure a Log Channel pointing to your preferred logging platform, and every activity log entry is forwarded in real time. Each event is automatically tagged with the site name and site URL, so you can filter, search, and alert by site inside your chosen platform. Supported platforms — bring your own logging stack: Better Stack — Stream logs to your Better Stack Logs source; filter by site in the Telemetry dashboard Datadog — Forward logs to your Datadog account; filter by site_name or site_url in Logs Search Loggly — Centralise logs in Loggly; tag and query by site across your entire client portfolio Papertrail — Route logs via HTTPS token or classic Syslog to your Papertrail destinations Slack — Push activity events to a Slack channel for real-time awareness across all sites Custom Webhook / Syslog / SIEM — Connect to any endpoint or enterprise SIEM platform Why agencies and maintenance services choose Log Channels: One dashboard, all sites — view and search logs from every client site in your existing logging platform No vendor lock-in — choose the platform you already use; no new SaaS subscription required Tamper-proof audit trail — if a site is compromised and an attacker clears the on-site logs, your external copy is already safely stored and completely out of reach Zero performance impact — log delivery runs asynchronously in background jobs; visitors and admins never wait for external services to respond Multiple simultaneous channels — send logs to Datadog for archiving and Slack for real-time alerts at the same time Per-channel test button — verify each connection is working before you rely on it View full Log Channels details: 👉 activitylog.pro/features → ⚡ Performance & Database Custom database table – Activity Log Pro uses its own dedicated table, keeping your posts and meta tables clean and queries fast. Low-overhead logging – Events are captured in real time using optimised queries designed to have minimal impact on site performance. Configurable retention – Set log retention from 7 to 365 days to keep your database lean and manageable. Automatic cleanup – Scheduled purges run automatically based on your retention settings, with no manual intervention required. 🧹 Clean Uninstall Full data removal – Uninstalling the plugin removes all log data, custom tables, plugin options, and scheduled tasks. No leftover clutter – Your database is restored to its original state with nothing left behind, so you can test the plugin with confidence. 🛡️ Security & Privacy Activity Log Pro takes your privacy and security seriously: IP Address Anonymization by Default – All IP addresses are automatically anonymized (e.g., 192.168.1.xxx) for privacy protection WordPress Standard Security – Database security practices (prepared statements, input sanitization) Configurable Data Retention – Meet your privacy requirements with customizable retention periods Administrator-Only Access – All plugin features require administrator privileges for security 📊 Perfect For Business Websites & Corporate Sites: Maintain GDPR compliance, PCI DSS standards, and audit trail requirements for regulatory inspections and security protocols. WooCommerce & E-commerce Stores: Track order modifications, product changes, inventory adjustments, customer data access, and payment processing for fraud prevention and compliance. Multi-user WordPress Sites: Monitor team member activities, role changes, content approvals, and administrative access for complete user accountability. WordPress Development & Staging Sites: Track plugin installations, removal, theme modifications. Digital Agencies, WordPress Maintenance Services & Freelancers: Centralise activity logs across all your client sites into a single logging platform like Datadog, Better Stack, or Loggly. Each log entry is tagged with the site name and URL, giving you a unified, searchable audit trail across your entire portfolio — without logging into each site individually. Use Log Channels (Premium) to stream logs from all your client sites to your existing stack. No new SaaS dashboard required — bring your own logging platform and stay in control of your data. Membership Sites & Private Communities: Track member activities, subscription changes, content access, and community moderation actions. Educational Institutions & Learning Management: Monitor student submissions, instructor activities, course content changes, and user enrollment modifications. News & Publishing Websites: Monitor editorial workflows, content publication schedules, author activities, and SEO optimization changes. 🔧 Easy Setup & Configuration Get started in minutes: 1. Install and activate the plugin – it works out of the box with default settings 2. Configure which activities to track (optional) 3. Set your data retention preferences (optional) 4. Start monitoring immediately (There are various other Settings for you to explore) No complex setup required — this WordPress activity log works right away with sensible defaults while offering extensive customization options for advanced users. 💡 Use Cases This user activity log helps you answer the questions that matter most: Troubleshooting: “What changed right before the site broke?” Security Monitoring: “Who attempted to login with admin credentials?” Content Management: “When was this post last modified and by whom?” Compliance: “Show me all user activities for the past 6 months” Performance: “What plugins were recently activated that might be slowing the site?” Multi-Site Management: “Which of my client sites had a plugin deactivated, a user role changed, or a new admin added today?” System Requirements WordPress 6.3 or higher PHP 7.4 or higher MySQL 5.6 or higher (or MariaDB 10.0+) Minimum 64MB PHP memory limit (128MB recommended) Database Information Creates custom table: {prefix}actlogpro_activity_log_pro_all_logs Estimated storage: ~1KB per logged event Automatic cleanup: Based on retention settings (7-365 days) Uses WordPress database prefix: Follows WordPress naming conventions Privacy Policy Activity Log Pro logs user activities on your WordPress site. This may include: User login/logout times and IP addresses (anonymized by default) Content creation, modification, and deletion activities Plugin and theme changes Administrative actions Data Storage: Activity logs are stored locally in your WordPress database by default. No log data is sent to external services unless you explicitly enable a Log Channel (Premium), which can forward copies of logs to services like Datadog, Grafana Loki, Better Stack, and others. IP Address Privacy: IP addresses are automatically anonymized by default (e.g., 192.168.1.xxx) for privacy protection. Full IP addresses are only stored if explicitly enabled by administrators in the premium version. Third-Party Services: The plugin uses ipinfo.io for optional IP geolocation lookups when administrators manually request location information, and LemonSqueezy for payment processing when users choose to purchase premium features and for newsletter subscriptions when users voluntarily sign up. The ipinfo.io service is only used when explicitly requested and data is cached locally. LemonSqueezy is only used when users voluntarily initiate premium purchases, subscription management, or newsletter signups. Data Retention: You can configure data retention periods to meet your privacy requirements. You can configure a secure JSON feed, with access via a secure authentication token, available in Premium → activitylog.pro/pricing Support For support, documentation, and feature requests, please visit: Plugin Website → activitylog.pro Get Support → activitylog.pro/support Plugin Docs → activitylog.pro/docs Following on Twitter/X → x.com/ActivityLog Third-Party Services This plugin uses the following third-party services: IP Geolocation Service (ipinfo.io) – Purpose: Provides geographical location data for IP addresses to enhance security monitoring – Data Sent: IP addresses are sent to ipinfo.io for location lookup when administrators manually request IP location information – When Used: Only when administrators manually request IP location information via the admin interface – Privacy Policy: https://ipinfo.io/privacy-policy – Terms of Service: https://ipinfo.io/terms-of-service – Data Storage: Location data is cached locally for 24 hours to minimize API calls – User Control: This feature is optional and only available to administrators who explicitly request IP location data Payment Processing Service (LemonSqueezy) – Purpose: Handles secure payment processing, license validation, and subscription management for premium features – Data Sent: When users choose to purchase premium plans, payment information (credit card details, billing address), email address, and license details are processed by LemonSqueezy – When Used: Only when users voluntarily initiate premium plan purchases, license activation, or subscription management – Privacy Policy: https://www.lemonsqueezy.com/privacy – Terms of Service: https://www.lemonsqueezy.com/terms – Data Storage: Payment and license data is managed entirely by LemonSqueezy – no payment information is stored on your WordPress site – User Control: Users have complete control over whether to purchase premium features and can manage their subscriptions through LemonSqueezy’s customer portal Newsletter Subscription Service (LemonSqueezy) – Purpose: Allows users to voluntarily subscribe to product updates and educational content newsletters – Data Sent: Name and email address only when users explicitly choose to subscribe to the newsletter – When Used: Only when users voluntarily fill out and submit the newsletter subscription form in the plugin settings – Privacy Policy: https://www.lemonsqueezy.com/privacy – Terms of Service: https://www.lemonsqueezy.com/terms – Data Storage: Newsletter subscription data is managed by LemonSqueezy – no subscription information is stored on your WordPress site – User Control: Users have complete control over newsletter subscription and can unsubscribe at any time via email links or LemonSqueezy’s customer portal
Top keywords
- activity36×1.57%
- log34×1.48%
- site27×1.18%
- wordpress27×1.18%
- data25×1.09%
- changes24×1.05%
- logs22×0.96%
- security21×0.92%
- ip19×0.83%
- user19×0.83%
- activity log18×0.79%
- premium17×0.74%
Login Armor
🇫🇷 Fully translated into French. Interface et documentation intégralement disponibles en français. Thirteen security modules. One lightweight plugin. No premium tier. Login Armor protects WordPress login, accounts and administration with thirteen independent modules. It is built for agencies, freelancers and site owners who want practical security, clear evidence and safe defaults without a remote dashboard, bundled telemetry or upsells. Why Login Armor Complete and free: every module is included under the GPL. Lightweight: modules load only when needed and normal login checks add less than 2 ms on a typical setup. Private by default: data stays on your site. Optional external calls are disabled until you enable the related feature. Ready for real sites: multisite support, reverse-proxy controls, WP-CLI commands and production-safe defaults. Thirteen security modules Hide Login: replace wp-login.php with a private slug and return a 404 or redirect blocked visitors to a chosen URL. Brute Force Protection: escalating lockouts, subnet blocking, trusted proxy headers and coverage for login, password recovery, registration, XML-RPC and REST users. Hardening: fifteen controls for XML-RPC, pingbacks, file editing, version exposure, application passwords, author enumeration, reserved usernames, honeypots and new-admin alerts. Two-Factor Authentication: TOTP, email codes, backup codes, trusted devices, per-role enforcement, grace periods and recovery. Detection and Incidents: group raw events into attack patterns with severity, timelines, source IPs, targeted users and one-click actions. Activity Log: tamper-evident admin audit trail with filters, CSV export, retention controls and optional signed SIEM forwarding. Security Headers: CSP, X-Frame-Options, Permissions-Policy, Referrer-Policy and X-Content-Type-Options for login and lockout pages, with optional site-wide baseline headers. Breach Check: privacy-preserving Have I Been Pwned password checks and an optional XposedOrNot email check. Password Policy: length and character rules, username exclusion, breached-password rejection and optional non-locking expiration reminders. Session Management: idle timeout, maximum lifetime, optional single-device access and one-click revocation of other sessions. IP Geolocation: cached country lookup for IPs shown in Incidents and Events, with private ranges excluded. Request Firewall: optional, monitor-first filtering of malicious paths, query strings and HTTP methods, with administrator exclusions and IP/path allowlists. Bot Challenge: an invisible proof-of-work the browser solves before the login form is accepted, an alternative to CAPTCHAs with no external service; monitor-first, then enforce. Additional tools Login Armor also includes guided onboarding, a 0-100 security score, conflict detection, email/Slack/Discord/webhook notifications, a dashboard widget and a complete WP-CLI suite. The optional AI Security Briefing uses your own WordPress AI connector to explain a thirty-day security snapshot or a single incident. It always starts with deterministic facts, works without AI and sends nothing until an administrator explicitly requests an analysis. GPL forever. PHP 8.1+. WordPress 6.8+. Zero dependencies. Treize modules de sécurité. Une seule extension légère. Aucune version premium. Login Armor protège la connexion, les comptes et l’administration de WordPress grâce à treize modules indépendants. L’extension s’adresse aux agences, freelances et propriétaires de sites qui veulent une sécurité concrète, des preuves lisibles et des réglages sûrs, sans tableau de bord distant, télémétrie imposée ni upsell. Pourquoi Login Armor Complet et gratuit : tous les modules sont inclus sous licence GPL. Léger : les modules se chargent uniquement lorsque nécessaire et les contrôles ajoutent moins de 2 ms sur une connexion normale. Privé par défaut : les données restent sur votre site. Les appels externes optionnels sont désactivés tant que vous n’activez pas la fonction concernée. Prêt pour la production : multisite, reverse proxies, commandes WP-CLI et réglages par défaut sécurisés. Treize modules de sécurité Masquer la connexion : remplace wp-login.php par un slug privé et renvoie une 404 ou redirige les visiteurs bloqués vers l’URL choisie. Protection contre la force brute : verrouillages progressifs, blocage de sous-réseaux, proxies de confiance et protection de la connexion, récupération, inscription, XML-RPC et REST users. Renforcement : quinze contrôles pour XML-RPC, les pingbacks, l’éditeur de fichiers, la version, les mots de passe applicatifs, l’énumération d’auteurs, les identifiants réservés, le pot de miel et les alertes nouvel administrateur. Authentification à deux facteurs : TOTP, codes par e-mail, codes de secours, appareils de confiance, application par rôle, période de grâce et récupération. Détection et incidents : regroupe les événements en scénarios d’attaque avec sévérité, chronologie, IP sources, comptes ciblés et actions immédiates. Journal d’activité : piste d’audit admin infalsifiable avec filtres, export CSV, rétention et transfert SIEM signé optionnel. En-têtes de sécurité : CSP, X-Frame-Options, Permissions-Policy, Referrer-Policy et X-Content-Type-Options pour les pages de connexion et de verrouillage, avec en-têtes de base optionnels sur tout le site. Détection de fuites : vérification confidentielle des mots de passe via Have I Been Pwned et contrôle optionnel des e-mails via XposedOrNot. Politique de mot de passe : longueur, classes de caractères, exclusion de l’identifiant, rejet des mots de passe compromis et rappels d’expiration non bloquants. Gestion des sessions : délai d’inactivité, durée maximale, accès limité à un appareil et révocation des autres sessions. Géolocalisation IP : pays des IP affichées dans Incidents et Événements, avec cache et exclusion des plages privées. Pare-feu de requêtes : filtrage optionnel, d’abord en surveillance, des chemins, requêtes et méthodes HTTP malveillants, avec exclusion des administrateurs et listes d’autorisation IP/chemins. Défi anti-bot : une preuve de calcul invisible résolue par le navigateur avant validation du formulaire de connexion, alternative aux CAPTCHA sans service externe ; d’abord en surveillance, puis en blocage. Outils complémentaires Login Armor inclut aussi un assistant de configuration, un score de sécurité de 0 à 100, la détection de conflits, les notifications par e-mail, Slack, Discord ou webhook, un widget de tableau de bord et une suite WP-CLI complète. Le briefing de sécurité IA optionnel utilise votre propre connecteur IA WordPress pour expliquer les trente derniers jours ou un incident précis. Il commence toujours par des faits déterministes, fonctionne sans IA et n’envoie rien tant qu’un administrateur ne demande pas explicitement une analyse. Conçu par Login Armor est conçu et maintenu par Fabrice Ducarme de WPFormation. Nous l’utilisons sur chaque site que nous livrons. Présentation et fonctionnement de Login Armor Guides de sécurité WordPress sur WPFormation Veille des vulnérabilités WordPress sur WPFormation GPL pour toujours. PHP 8.1+. WordPress 6.8+. Zéro dépendance. External Services Login Armor has no telemetry and requires no Login Armor account. The following services are contacted only when WordPress itself or an administrator enables the related feature. WordPress AI connector (optional) The AI Security Briefing sends a security prompt through the administrator’s own WordPress AI connector only after they click an analysis button. Minimised mode sends counts, categories, severities and role buckets without clear IP addresses or usernames. Explicit deep mode also sends IP addresses and event details. Login Armor stores no provider API key. The selected AI provider’s terms and privacy policy apply. Slack, Discord or custom webhook (optional) When an administrator enables an incident notification channel, Login Armor sends the incident type, severity, IP address, target username, event count and site URL to the configured endpoint. The separate signed Activity Log forwarding option sends the event, object, user ID/login/role, IP address, description, integrity hashes, site URL and plugin version to the administrator’s SIEM or custom webhook. Slack: Terms | Privacy Discord: Terms | Privacy Custom webhook: terms and privacy are controlled by the administrator’s chosen endpoint. Gravatar The Activity Log uses WordPress core’s get_avatar(). If avatars are enabled in WordPress, a hashed email address may be sent to Gravatar to retrieve the image. Gravatar: Terms | Privacy Have I Been Pwned (optional) Breach Check and the optional compromised-password policy send only the first 5 characters of a password’s SHA-1 hash to the Pwned Passwords API. The password and full hash never leave the site. Checks fail soft if the service is unavailable. Public registration and password-reset validation do not call the service; authenticated checks remain active. Have I Been Pwned: Privacy | Acceptable Use XposedOrNot (optional) The separate Email check, disabled by default, sends the user’s email address and a plugin-identifying User-Agent to XposedOrNot when a user is created or changes email. XposedOrNot: Service | Privacy ipwho.is (optional) IP Geolocation sends a displayed public IP address to ipwho.is when an administrator opens Incidents or Events. Results are cached for 30 days. Private and reserved ranges are never sent, and developers can replace the lookup through the login_armor_geoip_lookup filter. ipwho.is: Service | Documentation