BeziWorld Activity Log
BeziWorld Activity Log records what users do on your WordPress site: who logged in, who failed to log in, who changed a role, who edited their profile, who created or edited content, and more. The focus is user activity, and the goal is to make the capabilities competing plugins reserve for paid upgrades available for free. Designed for performance. Events are stored in a dedicated, indexed custom table (never in wp_posts), written in batches to keep request overhead low, while security-relevant events are persisted immediately. Retention pruning keeps the table lean automatically. Designed for trust. Each event is signed with a per-site HMAC and sealed into a hash-chained sequence of checkpoints, making after-the-fact tampering — including row insertion or deletion — detectable. Because an attacker with full server access could recompute local signatures, the latest checkpoint signature can be anchored off-host (emailed or sent to a webhook) so the integrity proof leaves the machine. Designed for privacy. IP logging is optional and can be anonymised at capture time. The plugin never phones home and never loads code from external servers. Highlights Authentication and account activity: logins, logouts, failed logins (rate-limited to prevent log flooding), registration, role changes, profile and user-metadata changes, password resets, application passwords, user deletion. Content activity: posts, pages and custom post types created, updated (with a field-level diff), status changes, trashing, restoring and permanent deletion; comments, media and taxonomy terms. Clean, readable event viewer with severity badges, expandable detail rows, sorting, filtering and full-text search. Granular configuration: enable or disable whole event groups or individual events. Exclusion rules by IP/CIDR, user login, user ID, role and request path. Plugin/theme and settings changes, navigation menus, and the GDPR personal-data request lifecycle. Optional integrations: WooCommerce (orders, status changes, stock) and Yoast SEO (metadata and settings). Real-time notifications — Slack, Discord, Telegram, email and generic webhook — by urgency or chosen event codes, delivered immediately or as an hourly digest. Free. Optional login geolocation (via a provider you wire) with an automatic alert on a login from a new country. Scheduled HTML summary reports emailed to the administrator (daily or weekly). Statistics screen with daily-volume chart and category, user and event breakdowns. Active session management: see who is logged in and terminate sessions. Free. Tamper-evident integrity: per-row HMAC plus a hash-chained checkpoint sequence with optional off-host anchoring (email/webhook), verifiable with WP-CLI (wp bzal verify-integrity). Real-time notifications also fire on a chosen set of event codes, regardless of urgency. Configurable severity per event code, driving notifications and the security badge. Optional anomaly detection: flags a rapid bulk-delete burst by one user and off-hours admin logins as high-severity alerts. Admin-bar quick view: the latest events and a 24-hour security badge on every screen. “Users online” view: who currently holds a session, with their most recent action, time and IP. CSV and JSON export of the filtered log, with spreadsheet-formula-injection protection. Read access via the REST API (offset and cursor pagination, plus an integrity-anchor endpoint) and optionally GraphQL, gated by capability. Granular configuration: enable/disable whole event groups or individual events; exclusion rules by IP/CIDR, user, role and path. Configurable retention with on-demand cleanup; UTC storage with display in your chosen timezone. Fully translatable, with bundled Polish, German and Czech translations. External services This plugin works fully offline. It does not connect to any external service on its own. The following optional integrations are disabled by default and only ever contact a destination that you enter in the settings; each transmits a short summary of a logged event (such as the event description, the acting user’s login, the time, and — when IP logging is enabled — the IP address) at the moment the event occurs or, in digest mode, once per hour. Slack — when you enter a Slack Incoming Webhook URL, matching events are POSTed to that webhook. See the Slack Terms of Service (https://slack.com/terms-of-service) and Privacy Policy (https://slack.com/trust/privacy/privacy-policy). Discord — when you enter a Discord webhook URL, matching events are POSTed to that webhook. See the Discord Terms (https://discord.com/terms) and Privacy Policy (https://discord.com/privacy). Telegram — when you enter a Telegram bot token and chat ID, matching events are sent through the Telegram Bot API at api.telegram.org. See the Telegram Terms (https://telegram.org/tos) and Privacy Policy (https://telegram.org/privacy). Generic webhook — when you enter a custom webhook URL (for notifications or for off-host integrity anchoring), the corresponding payload is POSTed to that URL. The destination is yours; review its provider’s terms and privacy policy. Login geolocation — disabled unless you both enable it and wire a provider through the bzal_geolocate_country filter. The plugin bundles no geolocation provider and makes no geolocation request by itself; any lookup is performed by the provider you supply, under that provider’s terms. Summary reports and notification emails are delivered through your site’s own WordPress mail system to the recipients you configure; they are not sent to any third party by this plugin.
Top keywords
- event11×1.32%
- webhook9×1.08%
- events8×0.96%
- privacy8×0.96%
- telegram8×0.96%
- user8×0.96%
- terms7×0.84%
- discord6×0.72%
- https6×0.72%
- ip6×0.72%
- optional6×0.72%
- provider6×0.72%
Logify WP – Activity Log & User Audit Log
Logify WP provides real-time, detailed logs of activities happening across your WordPress website. Whether you’re an agency, freelancer, IT team, developer, or website administrator, Logify WP gives you full visibility into your website’s activity with a comprehensive activity log and audit log. From tracking post edits to user login attempts and plugin updates, Logify WP helps you monitor and secure your site with clear and easy-to-understand logs. Take your activity logs to the next level with activity Notes! This feature allows you to attach searchable notes linked to logged events, providing valuable context. Need to document why a plugin was installed, who approved an update, or where a license is stored? Now you can, with simple markup support for clarity. Built to be simple yet powerful, Logify WP features a clean layout of activity information, easy filtering and search options, and customizable role-based access controls. The user-friendly dashboard widget makes it easy to review recent critical activities at a glance. Key Features: Activity Log Overview: Get a complete chronological view of all logged activities across your WordPress site. Ideal for tracking patterns, diagnosing issues, and maintaining a transparent record of site events. User Audit Log: Drill down into individual user activity with dedicated audit trails. See exactly what each user did, when, and from where, perfect for accountability and compliance. Track Core WordPress Activities: Record actions on posts, pages, custom post types, taxonomies, plugins, themes, users, and more. Real-time Monitoring: Get instant insights into who made changes, when, and where, via a secure event log. Action Notes (New!): Add and search notes linked to actions for improved tracking and accountability. User Login Monitoring: Track user logins, logouts, and failed attempts with IP addresses. Media Management: Know who is uploading, editing, or deleting media files and when. Role-Based Access Control: Limit who can access the activity logs based on their WordPress role. Advanced Search & Filters: Filter logs by user, date, post type, and more to quickly find specific actions. User-Friendly Dashboard Widget: View the most recent critical activities in a quick summary. IP Address Information Integration: One-click access to IP information via WhatIsMyIpAddress.com. Who is Logify WP for? Logify WP is perfect for: – Agencies managing multiple client sites. – Freelancers who need a detailed audit trail for their client work. – IT Teams maintaining the security of large WordPress environments. – Website Administrators responsible for monitoring site activity and detecting unauthorized changes. – Developers looking for a simple yet powerful logging tool. – Everyday Website Users who want a simple way to monitor and track activity on their site. Logify WP is actively being developed, with new features in the pipeline. If you’d like to suggest features, submit them via https://logifywp.com/suggest/. Links Plugin Website Suggest Features Credits This plugin bundles DataTables, which is released under the MIT License. DataTables ©2007-2024 SpryMedia Ltd. Third-Party Services This plugin utilizes third-party services under certain circumstances: 1. WordPress Documentation Links When viewing logs, this plugin provides links to the official WordPress documentation corresponding to the version of WordPress that has been installed on your site. These links direct users to: Service URL: https://wordpress.org/documentation/wordpress-version/version- / Purpose: To offer quick access to documentation for the specific WordPress version installed. Data Sent: The WordPress version number is included in the URL. Privacy Policy: https://wordpress.org/about/privacy/ 2. IP Address Lookup This plugin allows users to click on logged IP addresses to view their origin information. When a user clicks an IP address in the log, it opens a link to an external service: Service Name: WhatIsMyIPAddress.com Service URL: https://whatismyipaddress.com/ip/ Purpose: To provide detailed information about the IP address’s geographical location and other related data. Data Sent: The IP address clicked in the log is included in the URL. Privacy Policy: https://whatismyipaddress.com/privacy-policy Terms of Use: https://whatismyipaddress.com/terms-of-use 3. IP Geolocation Service This plugin retrieves the geographical location of users based on their IP addresses to enhance log information. When a user’s IP address is logged, the plugin sends a request to an external service to obtain location details: Service Name: ip-api.com Service URL: http://ip-api.com/json/ Purpose: To obtain geographical location data (city, region, country) associated with the IP address for display in logs. Data Sent: The user’s IP address is included in the API request URL. Data Received: The service returns location information such as city, region, and country. Privacy Policy: https://ip-api.com/docs/legal Terms of Service: https://ip-api.com/docs/legal Please Note: By using these features, data (such as your WordPress version, or your users’ IP addresses) is sent to external services. We recommend reviewing your privacy policies and terms of use to ensure compliance with local laws and regulations.