Logify WP – Activity Log & User Audit Log
Logify WP provides real-time, detailed logs of activities happening across your WordPress website. Whether you’re an agency, freelancer, IT team, developer, or website administrator, Logify WP gives you full visibility into your website’s activity with a comprehensive activity log and audit log. From tracking post edits to user login attempts and plugin updates, Logify WP helps you monitor and secure your site with clear and easy-to-understand logs. Take your activity logs to the next level with activity Notes! This feature allows you to attach searchable notes linked to logged events, providing valuable context. Need to document why a plugin was installed, who approved an update, or where a license is stored? Now you can, with simple markup support for clarity. Built to be simple yet powerful, Logify WP features a clean layout of activity information, easy filtering and search options, and customizable role-based access controls. The user-friendly dashboard widget makes it easy to review recent critical activities at a glance. Key Features: Activity Log Overview: Get a complete chronological view of all logged activities across your WordPress site. Ideal for tracking patterns, diagnosing issues, and maintaining a transparent record of site events. User Audit Log: Drill down into individual user activity with dedicated audit trails. See exactly what each user did, when, and from where, perfect for accountability and compliance. Track Core WordPress Activities: Record actions on posts, pages, custom post types, taxonomies, plugins, themes, users, and more. Real-time Monitoring: Get instant insights into who made changes, when, and where, via a secure event log. Action Notes (New!): Add and search notes linked to actions for improved tracking and accountability. User Login Monitoring: Track user logins, logouts, and failed attempts with IP addresses. Media Management: Know who is uploading, editing, or deleting media files and when. Role-Based Access Control: Limit who can access the activity logs based on their WordPress role. Advanced Search & Filters: Filter logs by user, date, post type, and more to quickly find specific actions. User-Friendly Dashboard Widget: View the most recent critical activities in a quick summary. IP Address Information Integration: One-click access to IP information via WhatIsMyIpAddress.com. Who is Logify WP for? Logify WP is perfect for: – Agencies managing multiple client sites. – Freelancers who need a detailed audit trail for their client work. – IT Teams maintaining the security of large WordPress environments. – Website Administrators responsible for monitoring site activity and detecting unauthorized changes. – Developers looking for a simple yet powerful logging tool. – Everyday Website Users who want a simple way to monitor and track activity on their site. Logify WP is actively being developed, with new features in the pipeline. If you’d like to suggest features, submit them via https://logifywp.com/suggest/. Links Plugin Website Suggest Features Credits This plugin bundles DataTables, which is released under the MIT License. DataTables ©2007-2024 SpryMedia Ltd. Third-Party Services This plugin utilizes third-party services under certain circumstances: 1. WordPress Documentation Links When viewing logs, this plugin provides links to the official WordPress documentation corresponding to the version of WordPress that has been installed on your site. These links direct users to: Service URL: https://wordpress.org/documentation/wordpress-version/version- / Purpose: To offer quick access to documentation for the specific WordPress version installed. Data Sent: The WordPress version number is included in the URL. Privacy Policy: https://wordpress.org/about/privacy/ 2. IP Address Lookup This plugin allows users to click on logged IP addresses to view their origin information. When a user clicks an IP address in the log, it opens a link to an external service: Service Name: WhatIsMyIPAddress.com Service URL: https://whatismyipaddress.com/ip/ Purpose: To provide detailed information about the IP address’s geographical location and other related data. Data Sent: The IP address clicked in the log is included in the URL. Privacy Policy: https://whatismyipaddress.com/privacy-policy Terms of Use: https://whatismyipaddress.com/terms-of-use 3. IP Geolocation Service This plugin retrieves the geographical location of users based on their IP addresses to enhance log information. When a user’s IP address is logged, the plugin sends a request to an external service to obtain location details: Service Name: ip-api.com Service URL: http://ip-api.com/json/ Purpose: To obtain geographical location data (city, region, country) associated with the IP address for display in logs. Data Sent: The user’s IP address is included in the API request URL. Data Received: The service returns location information such as city, region, and country. Privacy Policy: https://ip-api.com/docs/legal Terms of Service: https://ip-api.com/docs/legal Please Note: By using these features, data (such as your WordPress version, or your users’ IP addresses) is sent to external services. We recommend reviewing your privacy policies and terms of use to ensure compliance with local laws and regulations.
Top keywords
- ip15×1.88%
- wordpress13×1.63%
- activity10×1.25%
- com10×1.25%
- service10×1.25%
- user10×1.25%
- address8×1.00%
- https8×1.00%
- ip address8×1.00%
- log8×1.00%
- data7×0.88%
- information7×0.88%
Login Security with Telegram Alerts
Login Security with Telegram Alerts is your comprehensive solution for fortifying WordPress login security and staying informed about critical site activities. It actively combats brute-force attacks, enhances user authentication with multi-factor options, and provides real-time alerts directly to your Telegram. Scalable for any site size, from personal blogs to large enterprises, it ensures your WordPress site remains secure and you’re always in the loop. Key Features: Login Security with Telegram Alerts is packed with powerful features designed to give you peace of mind and full control over your site’s access. Brute-Force Protection: Automatically blocks suspicious IP addresses after a configurable number of failed login attempts, effectively preventing dictionary attacks and credential stuffing. Real-time Telegram Notifications: Receive instant alerts for failed login attempts and successful logins, delivered directly to your chosen Telegram channel, group, or private chat. This provides immediate awareness of critical site events, enabling prompt action. Cloudflare Turnstile (Anti-Bot): Protect your login form from bots and automated brute-force attacks using a privacy-friendly, invisible alternative to reCAPTCHA. New Device Login Alerts: Get instant email and Telegram notifications when a user logs in from an unrecognized device or browser. API Protection: Easily disable XML-RPC and restrict the WordPress REST API to logged-in users only, closing common vulnerabilities. Comprehensive Activity Logging: Maintains detailed records of both failed and successful login events, capturing critical information such as IP addresses, usernames, login times, and user agents. This log is invaluable for auditing and identifying suspicious patterns. IP Management: Block or unblock IP addresses directly from the Activity Log with one-click actions. Administrators can manually manage IP blacklists and whitelists from the plugin’s settings page. WordPress Core Files Integrity Check: Verify that WordPress core files haven’t been tampered with by comparing them against official checksums from WordPress.org. File Permissions Management: Automatically check and fix file permissions to match WordPress security standards, ensuring your installation follows best practices. Custom Admin URL: Hide your wp-admin login URL by creating a custom access point, adding an extra layer of security by obscurity. Geolocation Integration: Includes location data in Telegram notifications, adding crucial context to security alerts and aiding in the investigation of suspicious activities. Optional Email Two-Factor Authentication: Site administrators can enable an opt-in extra login step; users who choose to turn it on for their own account will be emailed a one-time verification code (delivered as a polished HTML email) each time they log in. User-Friendly Admin Interface: An intuitive, tabbed settings page contributes to a clean and easy-to-use experience. Why Choose Login Security with Telegram Alerts? Comprehensive Security: Provides advanced features that actively defend your site against common and persistent threats. Instant Awareness: Critical updates are delivered directly to Telegram, facilitating immediate action and providing peace of mind to site administrators. User-Friendly: Engineered for quick setup, often achievable in minutes, with an intuitive interface that makes configuration accessible to users of all technical levels. Performance Optimized: Built with efficiency in mind, ensuring that robust security measures do not compromise site speed. Dedicated Support: A passionate team is committed to providing prompt and helpful support, aiming to ensure users maximize the plugin’s potential. Compatibility & Requirements: WordPress Version: 5.0 or higher (Tested up to 7.1) PHP Version: 7.2 or higher (PHP 7.4+ recommended for optimal performance and security) Performance Considerations: Login Security with Telegram Alerts is designed with performance in mind: Efficient API Calls: When interacting with external services like Telegram’s API, the plugin uses WordPress’s built-in HTTP API for reliable and performant requests, minimizing impact on page load times. Optimized Database Interactions: Designed to minimize database queries and employs best practices for data storage and retrieval, ensuring your site’s database remains lean and responsive. Lightweight Codebase: Development emphasizes avoiding bloated scripts and unnecessary assets, ensuring the plugin adds minimal overhead to site resources. Security Best Practices: Beyond merely claiming to be “secure,” Login Security with Telegram Alerts implements rigorous security measures: Nonces: All critical actions and forms within the plugin utilize WordPress Nonces to protect against Cross-Site Request Forgery (CSRF) attacks. Input Sanitization: All user input is rigorously sanitized before processing or storage to prevent malicious code injection, such as Cross-Site Scripting (XSS) attacks. Output Escaping: Data displayed on both the frontend and backend is properly escaped to prevent XSS vulnerabilities. Capability Checks: Access to plugin functionalities is strictly controlled by checking user capabilities using current_user_can(), preventing unauthorized users from performing actions they are not permitted to. Regular Audits: The plugin’s codebase undergoes regular scanning and updates to address emerging security vulnerabilities. Internationalization (i18n): Login Security with Telegram Alerts is fully internationalized, allowing for seamless translation into any language. All strings are meticulously wrapped in gettext functions, and a dedicated text domain (login-security-with-telegram-alerts) ensures compatibility with WordPress’s robust translation system. Third-Party Services This plugin may connect to external services to provide certain features: Telegram API (api.telegram.org) – Used for: Sending security notifications to your configured Telegram bot – Triggered when: You enable Telegram notifications and configure a bot token and chat ID – Privacy Policy: https://telegram.org/privacy – Terms: https://telegram.org/tos IP Geolocation (ip-api.com) – Used for: Looking up geographical location of login attempts – Triggered when: Geolocation is enabled in settings (optional feature) – Privacy Policy: https://ip-api.com/docs/legal – Data sent: IP addresses only Cloudflare Turnstile (challenges.cloudflare.com) – Used for: Protecting the login form from bots – Triggered when: You enable Cloudflare Turnstile in settings and provide site keys – Privacy Policy: https://www.cloudflare.com/privacypolicy/ – Terms: https://www.cloudflare.com/website-terms/ All external service connections are optional and only occur when explicitly enabled by the administrator. No data is sent without your configuration and consent.