Activity Log – Monitor & Record User Changes
An easy to use, fully supported WordPress activity log plugin. Want to know exactly who does what on your WordPress site? Activity Log works like an airplane’s black box: it quietly records every action in the WordPress admin — and now every request made through the REST API, WP-CLI, WP-Cron, and more — so you always know: If someone is trying to hack your site When a post was published, and who published it If a plugin/theme was activated/deactivated Suspicious admin activity The plugin doesn’t require any setup; it works right out of the box, runs on its own database table so it doesn’t slow down your site, and stays out of your way until you need it. What’s New Request Source Tracking – See exactly where each change came from: the WP Admin, the REST API, WP-CLI, WP-Cron, XML-RPC, or the WP Abilities API, including which Application Password was used. Filter the log by source to quickly spot automated or API-driven changes alongside manual admin activity. Email Logging – Capture all emails sent from your WordPress site for streamlined debugging and compliance. Especially useful for WooCommerce stores tracking order emails alongside other site events. Export to CSV – Export your Activity Log data to CSV, or build support for your own format with our dedicated Export API. Data Privacy and GDPR Compliance – Export or erase log data directly through the WordPress Privacy Tools. If you have more than a handful of users, keeping track of who did what by hand is virtually impossible. Activity Log solves that by tying every action back to the user who triggered it, in an easy-to-filter view right on your WordPress dashboard. With the Activity Log you can record: WordPress – Core updates Posts – Created, updated, deleted Pages – Created, updated, deleted Custom Post Type – Created, updated, deleted Tags – Created, updated, deleted Categories – Created, updated, deleted Taxonomies – Created, updated, deleted Menus – Created, updated, deleted Media – Created, updated, deleted Comments – Created, approved, unapproved, trashed, untrashed, spammed, unspammed, deleted Users – Login, logout, login failed, update profile, registered, deleted Plugins – Installed, updated, activated, deactivated, changed Themes – Installed, updated, deleted, activated, changed (Editor and Customizer) Widgets – Added to sidebar, deleted from sidebar, order widgets Setting – General, writing, reading, discussion, media, permalinks Options – Extended custom settings for 3rd party plugins Export – Exported activity log file Request Source – WP Admin, REST API, WP-CLI, WP-Cron, XML-RPC, WP Abilities, and Application Password name when used WooCommerce – Track products, orders, customers, and more bbPress – Forums, topics, replies, taxonomies, and other actions Emails sent from WordPress site – Sending successful, sending failed There’s more, of course, but you get the point… For each event recorded by the activity log, the following details are also logged: Date and time of occurrence User and user role responsible for the change Source IP address from which the change originated Request source — WP Admin, REST API, WP-CLI, WP-Cron, XML-RPC, or WP Abilities Affected object where the change occurred Data Storage and Performance All events are stored in a dedicated custom database table, keeping the impact on your site’s performance to a minimum — even under heavy traffic. Uninstall Clean-up Uninstalling the plugin removes all of its data from your database automatically, leaving nothing behind. What users have to say “Its tools, particularly for data privacy and GDPR compliance, make it indispensable for websites operating within European Union boundaries or dealing with EU citizens’ data” – HubSpot.com “If you’re after a competent WP security audit log plugin with all the basic features you need, Activity Log is it!” – WPAstra.com “Activity Log features a remarkably straightforward dashboard interface, providing administrators with an at-a-glance understanding of site interactions” – Malcare.com “Thanks to this step, we’ve discovered that our site was undergoing a brute force attack” – Artdriver.com “Activity Log lets you track a huge range of activities. Overall, very easy to use and setup” – ElegantThemes.com Contributions: Would you like to contribute to this plugin? You’re more than welcome to submit your pull requests on the GitHub repo. And, if you have any notes about the code, please open a ticket on the issue tracker.
Top keywords
- log13×1.89%
- activity12×1.75%
- deleted12×1.75%
- activity log10×1.46%
- updated10×1.46%
- created9×1.31%
- site9×1.31%
- updated deleted9×1.31%
- created updated8×1.16%
- created updated deleted8×1.16%
- wordpress8×1.16%
- data7×1.02%
Quantely Activity
Lightweight, privacy-conscious pageview and event logging plugin that runs inside your own website. Quantely Activity is built to capture activity reliably under imperfect conditions through server-side recording and optional client-side signals, while supporting filtering for bots, unwanted pages, IP sources and selectable WordPress logged-in roles. Quantely Activity can be used for: Monitoring site behavior Reviewing traffic patterns Security and bot analysis Feeding downstream analytics layers Quantely Activity is turn-key: install it, and pageviews and events should begin appearing shortly after. Raw activity data is retained for a configurable short period, helping keep the plugin lightweight and privacy-conscious. What Quantely Activity is Quantely Activity is a capture and monitoring layer. It is designed to record activity on your site in a structured and reliable way, with a strong focus on signal capture and data integrity. Unlike many analytics tools, it does not focus on marketing analytics, attribution modelling, or behavioral profiling. It also does not rely solely on browser JavaScript. A server-side baseline helps ensure pageviews are still captured when scripts or beacons fail. Hybrid capture engine The plugin combines server-side pageview capture with optional browser-side signals. Typical flow: Browser request ↓ Server pageview baseline ↓ Browser attach (Beacon) – engagement pings – interaction events ↓ Correlation via pageview identifiers ↓ Bot classification and exclusions ↓ Deduplication and storage This architecture helps keep capture reliable under real-world conditions where browser-only tracking can miss signals. Event correlation and deduplication Quantely Activity links browser-side signals back to the pageview where they occurred. Engagement pings, clicks, form submissions, and similar events can be correlated to their originating pageview. Built-in deduplication helps avoid duplicate records when similar signals are captured from both browser and server-side sources. This keeps the activity stream more accurate and easier to interpret. Fully on-site All captured activity is stored in your own WordPress database. Quantely Activity does not send captured activity data to external services. IP addresses are never stored in plain form, and the plugin does not perform cross-site tracking. Privacy-aware design The plugin is designed with privacy-conscious principles in mind: No plain IP addresses stored Short configurable retention window Optional honoring of GPC / DNT signals No external tracking services Data remains on your own site This gives site owners visibility into activity while keeping capture local and controlled. Hooks Quantely Activity exposes a small developer API for integrations and downstream processing. qmon_hit_before_insert — Filter a normalized hit array before it is stored. qmon_hit_recorded — Action fired after a hit has been stored. This is the main integration point for forwarding or persisting captured records. qmon_event_normalize — Filter a normalized event payload before it is finalized. qmon_event_db_dedupe_window_sec — Filter the database deduplication window for events. qmon_bot_verdict — Filter the bot-classification verdict before it is finalized.