Activity Log – Monitor & Record User Changes
An easy to use, fully supported WordPress activity log plugin. Want to know exactly who does what on your WordPress site? Activity Log works like an airplane’s black box: it quietly records every action in the WordPress admin — and now every request made through the REST API, WP-CLI, WP-Cron, and more — so you always know: If someone is trying to hack your site When a post was published, and who published it If a plugin/theme was activated/deactivated Suspicious admin activity The plugin doesn’t require any setup; it works right out of the box, runs on its own database table so it doesn’t slow down your site, and stays out of your way until you need it. What’s New Request Source Tracking – See exactly where each change came from: the WP Admin, the REST API, WP-CLI, WP-Cron, XML-RPC, or the WP Abilities API, including which Application Password was used. Filter the log by source to quickly spot automated or API-driven changes alongside manual admin activity. Email Logging – Capture all emails sent from your WordPress site for streamlined debugging and compliance. Especially useful for WooCommerce stores tracking order emails alongside other site events. Export to CSV – Export your Activity Log data to CSV, or build support for your own format with our dedicated Export API. Data Privacy and GDPR Compliance – Export or erase log data directly through the WordPress Privacy Tools. If you have more than a handful of users, keeping track of who did what by hand is virtually impossible. Activity Log solves that by tying every action back to the user who triggered it, in an easy-to-filter view right on your WordPress dashboard. With the Activity Log you can record: WordPress – Core updates Posts – Created, updated, deleted Pages – Created, updated, deleted Custom Post Type – Created, updated, deleted Tags – Created, updated, deleted Categories – Created, updated, deleted Taxonomies – Created, updated, deleted Menus – Created, updated, deleted Media – Created, updated, deleted Comments – Created, approved, unapproved, trashed, untrashed, spammed, unspammed, deleted Users – Login, logout, login failed, update profile, registered, deleted Plugins – Installed, updated, activated, deactivated, changed Themes – Installed, updated, deleted, activated, changed (Editor and Customizer) Widgets – Added to sidebar, deleted from sidebar, order widgets Setting – General, writing, reading, discussion, media, permalinks Options – Extended custom settings for 3rd party plugins Export – Exported activity log file Request Source – WP Admin, REST API, WP-CLI, WP-Cron, XML-RPC, WP Abilities, and Application Password name when used WooCommerce – Track products, orders, customers, and more bbPress – Forums, topics, replies, taxonomies, and other actions Emails sent from WordPress site – Sending successful, sending failed There’s more, of course, but you get the point… For each event recorded by the activity log, the following details are also logged: Date and time of occurrence User and user role responsible for the change Source IP address from which the change originated Request source — WP Admin, REST API, WP-CLI, WP-Cron, XML-RPC, or WP Abilities Affected object where the change occurred Data Storage and Performance All events are stored in a dedicated custom database table, keeping the impact on your site’s performance to a minimum — even under heavy traffic. Uninstall Clean-up Uninstalling the plugin removes all of its data from your database automatically, leaving nothing behind. What users have to say “Its tools, particularly for data privacy and GDPR compliance, make it indispensable for websites operating within European Union boundaries or dealing with EU citizens’ data” – HubSpot.com “If you’re after a competent WP security audit log plugin with all the basic features you need, Activity Log is it!” – WPAstra.com “Activity Log features a remarkably straightforward dashboard interface, providing administrators with an at-a-glance understanding of site interactions” – Malcare.com “Thanks to this step, we’ve discovered that our site was undergoing a brute force attack” – Artdriver.com “Activity Log lets you track a huge range of activities. Overall, very easy to use and setup” – ElegantThemes.com Contributions: Would you like to contribute to this plugin? You’re more than welcome to submit your pull requests on the GitHub repo. And, if you have any notes about the code, please open a ticket on the issue tracker.
Top keywords
- log13×1.89%
- activity12×1.75%
- deleted12×1.75%
- activity log10×1.46%
- updated10×1.46%
- created9×1.31%
- site9×1.31%
- updated deleted9×1.31%
- created updated8×1.16%
- created updated deleted8×1.16%
- wordpress8×1.16%
- data7×1.02%
Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File Scanning
Most security plugins hand you a dashboard full of alerts and expect you to know what to do next. Shield works differently. It blocks threats automatically, repairs what it can on its own, and then shows you exactly what still needs your attention — ranked by impact, not volume. Less noise. More action. 🤖 Security That Runs Itself The most powerful thing Shield does is what it handles without you: Automatic IP Blocking — every visitor is quietly scored as they interact with your site. Failed logins, firewall blocks, silentCAPTCHA failures, and other signals accumulate into a reputation score. When a visitor’s score crosses the threshold, Shield blocks them — automatically, without you lifting a finger Automatic File Repair — when a file integrity scan finds a changed WordPress core file, Shield pulls the original from WordPress.org and restores it. Detected and fixed, without waiting for you to act Automatic Bot Recognition — Shield identifies legitimate crawlers (Google, Bing, DuckDuckGo, Yandex, Apple) and known services (ManageWP, Pingdom, Stripe, CloudFlare) and never blocks them. Your SEO and monitoring tools keep working 🧭 Guided Security, Not Just a Dashboard Shield organises your security into four focused areas so you always know where to look: Queue — things that need your attention, ranked by priority. Not everything at once — just what matters right now Investigate — dig into blocked IPs, security events, and the specific signals that triggered each one Configure — guided setup for each protection area, with clear recommendations matched to your site Reports — a clear view of what Shield has blocked, detected, and repaired over time The goal: guide you quickly towards action, not bury you in data. 🛡️ Free Protection Bot Blocking & Firewall silentCAPTCHA — blocks bad bots on login, registration, lost password, and comment forms using passive signals invisible to real visitors. No CAPTCHA keys. No external requests. No JavaScript that breaks your forms. Everything runs on your server (GDPR friendly). Firewall rules blocking common WordPress attack patterns — SQL injection probes, known exploit signatures, suspicious request parameters XML-RPC protection — disable or restrict entirely, including pingbacks and trackbacks REST API firewall — block unauthenticated requests Fake crawler detection — identifies bots spoofing legitimate search engines Login & Account Security Two-factor authentication (2FA) — email codes, Google Authenticator, or YubiKey OTP for all users Brute force protection with configurable login attempt limits and cooldown Session locking — tie sessions to a browser or IP to stop account theft after a successful login User enumeration blocking — closes off ?author= probes used to harvest usernames before an attack Scanning & Integrity Core file scanning — compares WordPress core against official checksums and repairs changed files automatically Suspicious PHP detection — flags PHP files in locations where they have no business being Abandoned plugin detection — identifies unmaintained plugins most likely to carry unpatched vulnerabilities Visibility & Control Security Admin PIN — lock Shield’s own settings so other administrators cannot quietly weaken your configuration Security activity log — logins, user changes, plugin and theme events, post edits, and suspicious requests: Everything in one clear view IP Rules — automatic & manual block and bypass rules, CIDR range support, full per-IP request history 🤝 CrowdSec Integration Shield is the only WordPress security plugin with a native CrowdSec integration. CrowdSec aggregates threat signals from millions of sites into a shared IP reputation network — your site blocks known attackers before they ever probe you, using intelligence far beyond your own traffic history. ✨ ShieldPRO Passkeys — phishing-resistant, passwordless login for users Backup login codes — emergency 2FA access when a device is lost AI-based malware scanner — detects known and unknown PHP malware Plugin & theme file scanning — compares installed files against WordPress.org originals, flagging unauthorised changes Vulnerability scanning — active checks across all installed plugins and themes Broader spam protection — WooCommerce, EDD, Contact Form 7, Ninja Forms, Elementor, and more Traffic rate limiting — cap request rates per IP to absorb high-volume bot floods User suspension — manual or automatic suspension of idle accounts MainWP integration White Label — rename and rebrand Shield for client sites Who It’s For Shield suits site owners, agencies, and MSPs who want protection that runs itself — not a plugin that demands constant attention to be useful. If you have been burned by security plugins that generate more noise than protection, or dashboards that tell you everything is wrong without telling you what to fix, Shield was built to be the alternative.