BeziWorld Activity Log
BeziWorld Activity Log records what users do on your WordPress site: who logged in, who failed to log in, who changed a role, who edited their profile, who created or edited content, and more. The focus is user activity, and the goal is to make the capabilities competing plugins reserve for paid upgrades available for free. Designed for performance. Events are stored in a dedicated, indexed custom table (never in wp_posts), written in batches to keep request overhead low, while security-relevant events are persisted immediately. Retention pruning keeps the table lean automatically. Designed for trust. Each event is signed with a per-site HMAC and sealed into a hash-chained sequence of checkpoints, making after-the-fact tampering — including row insertion or deletion — detectable. Because an attacker with full server access could recompute local signatures, the latest checkpoint signature can be anchored off-host (emailed or sent to a webhook) so the integrity proof leaves the machine. Designed for privacy. IP logging is optional and can be anonymised at capture time. The plugin never phones home and never loads code from external servers. Highlights Authentication and account activity: logins, logouts, failed logins (rate-limited to prevent log flooding), registration, role changes, profile and user-metadata changes, password resets, application passwords, user deletion. Content activity: posts, pages and custom post types created, updated (with a field-level diff), status changes, trashing, restoring and permanent deletion; comments, media and taxonomy terms. Clean, readable event viewer with severity badges, expandable detail rows, sorting, filtering and full-text search. Granular configuration: enable or disable whole event groups or individual events. Exclusion rules by IP/CIDR, user login, user ID, role and request path. Plugin/theme and settings changes, navigation menus, and the GDPR personal-data request lifecycle. Optional integrations: WooCommerce (orders, status changes, stock) and Yoast SEO (metadata and settings). Real-time notifications — Slack, Discord, Telegram, email and generic webhook — by urgency or chosen event codes, delivered immediately or as an hourly digest. Free. Optional login geolocation (via a provider you wire) with an automatic alert on a login from a new country. Scheduled HTML summary reports emailed to the administrator (daily or weekly). Statistics screen with daily-volume chart and category, user and event breakdowns. Active session management: see who is logged in and terminate sessions. Free. Tamper-evident integrity: per-row HMAC plus a hash-chained checkpoint sequence with optional off-host anchoring (email/webhook), verifiable with WP-CLI (wp bzal verify-integrity). Real-time notifications also fire on a chosen set of event codes, regardless of urgency. Configurable severity per event code, driving notifications and the security badge. Optional anomaly detection: flags a rapid bulk-delete burst by one user and off-hours admin logins as high-severity alerts. Admin-bar quick view: the latest events and a 24-hour security badge on every screen. “Users online” view: who currently holds a session, with their most recent action, time and IP. CSV and JSON export of the filtered log, with spreadsheet-formula-injection protection. Read access via the REST API (offset and cursor pagination, plus an integrity-anchor endpoint) and optionally GraphQL, gated by capability. Granular configuration: enable/disable whole event groups or individual events; exclusion rules by IP/CIDR, user, role and path. Configurable retention with on-demand cleanup; UTC storage with display in your chosen timezone. Fully translatable, with bundled Polish, German and Czech translations. External services This plugin works fully offline. It does not connect to any external service on its own. The following optional integrations are disabled by default and only ever contact a destination that you enter in the settings; each transmits a short summary of a logged event (such as the event description, the acting user’s login, the time, and — when IP logging is enabled — the IP address) at the moment the event occurs or, in digest mode, once per hour. Slack — when you enter a Slack Incoming Webhook URL, matching events are POSTed to that webhook. See the Slack Terms of Service (https://slack.com/terms-of-service) and Privacy Policy (https://slack.com/trust/privacy/privacy-policy). Discord — when you enter a Discord webhook URL, matching events are POSTed to that webhook. See the Discord Terms (https://discord.com/terms) and Privacy Policy (https://discord.com/privacy). Telegram — when you enter a Telegram bot token and chat ID, matching events are sent through the Telegram Bot API at api.telegram.org. See the Telegram Terms (https://telegram.org/tos) and Privacy Policy (https://telegram.org/privacy). Generic webhook — when you enter a custom webhook URL (for notifications or for off-host integrity anchoring), the corresponding payload is POSTed to that URL. The destination is yours; review its provider’s terms and privacy policy. Login geolocation — disabled unless you both enable it and wire a provider through the bzal_geolocate_country filter. The plugin bundles no geolocation provider and makes no geolocation request by itself; any lookup is performed by the provider you supply, under that provider’s terms. Summary reports and notification emails are delivered through your site’s own WordPress mail system to the recipients you configure; they are not sent to any third party by this plugin.
Top keywords
- event11×1.32%
- webhook9×1.08%
- events8×0.96%
- privacy8×0.96%
- telegram8×0.96%
- user8×0.96%
- terms7×0.84%
- discord6×0.72%
- https6×0.72%
- ip6×0.72%
- optional6×0.72%
- provider6×0.72%
ShieldUp – Bad Bots, Scrapers, Attackers
Tired of bad bots, scrapers, attackers and sluggish website performance? By providing real-time monitoring of accessing IPs, HTTP codes, URLs, and user agents, organized analytics, customizable timeline and visualizations, ShieldUp will help you indentify and combat threats like bad bots, scrapers, malicous attackers. Which will improve website security and performance by reducing the load on your server resources for a snappy website and great user experience. Key Features 🛡️ Advanced Security: ShieldUp protects your site from malicious bots, scrapers, attackers and hackers, shielding your website from potential threats. 🚀 Optimized Performance: Improve website speed and user experience by eliminating unnecessary requests from scrapers, bad bots and brute force attackers 🗃️ Comprehensive Data Collection: ShieldUp logs and archive accessing IPs, HTTP response codes, URLs, user agents, timestamps, etc. 📊 Detailed Data Insights: ShieldUp will analyze, organize and displays IP data based on IP ranges, request counts, details, offering a comprehensive view of your traffic within user-friendly tables. 📅 Custom Time Period: Select specific time ranges through an intuitive calendar feature for in-depth data analysis. 📈 Visualize Data: Easily visualize traffic trends and patterns with our user-friendly graphs. 🛠️ IP Tools: Helps you with actions like retrieving detailed IP information from DB or third-party tools. 🌐 Cloudflare Integration (Pro): Seamlessly connect your website to Cloudflare, enhancing security and performance even further by leverage Cloudflare’s powerful features. ⚙️ Advanced IP Management (Pro): Take control with a click. Manage IPs and IP ranges effortlessly, with actions like blocking, JavaScript challenges, whitelisting, or remove rules using Cloudflare’s firewall through the plugin. 💼 Centralized IP Database (Pro): Keep all IPs controlled by your WP plugin and Cloudflare in a centralized database for efficient management and tracking. 📝 User Activity Logging (Pro): Maintain detailed logs of all IP controls by users, ensuring accountability and providing a historical record of security actions. 🏆 Priority Support (Pro): Pro members get priority support, so you can expect quick help with any questions or issues. Please Note: Yes, the Pro version is undeniably impressive. However, the free version is really what you need and will get the job done. How it works 1. Installation and Activation Start by downloading and installing the ShieldUp plugin. Once activated, it seamlessly integrates with your WordPress, ready to work its magic. 2. Data Collection ShieldUp starts by collecting crucial data about the traffic to your website. It keeps a record of accessing IPs, including HTTP response codes, URLs, user agents, and timestamps. This data is organized into user-friendly tables and presented through interactive graphs, allowing you to gain valuable insights into your website’s traffic patterns. 3. Select, Organize and Display Data You can choose a specific time frame, making it easy to identify which IPs are accessing your site the most. It also groups IPs into /16 and /24 ranges and along with graphical representation helps you visualize trends, spot unusual activity and potential security threats. 4. Cloudflare Integration (Pro) ShieldUp seamlessly integrates with Cloudflare in PRO version, enhancing your website’s security even further. Using the Cloudflare API, you can manage IPs and IP ranges right from your WordPress dashboard. Implement blocks, JavaScript challenges, whitelist entries, or remove rules with just a few clicks. 5. IP Tools & IP Management Each IP listed in the user-friendly interface comes with action buttons, enabling you to ban IPs in your website’s firewall or CloudFlare, retrieve detailed IP information from third-party tools, and perform other custom actions. 6. Enhanced Security ShieldUp employs advanced security measures to protect your website from a wide range of threats. It identifies and blocks malicious bots, scrapers, attackers, and hackers, ensuring that your website remains secure. 7. Optimized Website Performance In addition to security, ShieldUp optimizes your website’s performance. It achieves this by filtering out unnecessary requests from bad bots, scrapers and other unwanted traffic. This optimization reduces the load on your server resources, resulting in a snappy and responsive website and great user experience. Firewalls, What we recommend? One of the best options would be a hardware-type firewall, but we wouldn’t be in this situation if we had one. The next best option for managing HTTP and HTTPS traffic is a cloud-based firewall, such as CloudFlare, especially when it is available for free and offers a wide range of excellent features. In addition to that, we also use CSF for other security solutions and to manage traffic and ports related to services like mail and SSH. So, why do we think CloudFlare is a better solution for HTTP and HTTPS trafic, than “Traditional” Server/Software-Based Firewall (CSF) especially Plugin-Like Firewalls (WordPress Plugins)? Traditional firewalls, while valuable, have limitations when compared to Cloudflare’s robust security and performance capabilities. These firewalls primarily protect your server or website by consuming server resources, leaving them vulnerable to large-scale attacks, among other things. In contrast, Cloudflare operates a global network that defends against threats at the network edge, providing superior DDoS protection and accelerated content delivery. By choosing Cloudflare, you gain a comprehensive, cloud-based solution that strengthens your website’s resilience and speed, effectively surpassing the capabilities of traditional local firewalls when it comes to HTTP and HTTPS trafic. Here are some of the main features of CloudFlare: Global Network Security: Cloudflare operates a vast global network that acts as a protective shield for your website, filtering out malicious traffic and threats before they even reach your server. This distributed approach ensures that attacks are mitigated at the network edge, preserving your server resources. Content Caching: Cloudflare’s caching infrastructure stores copies of your website’s content at data centers around the world. This means visitors experience faster load times as they access cached content from a server nearest to them, reducing server load and improving website responsiveness. Web Application Firewall (WAF): Cloudflare offers a comprehensive Web Application Firewall that can be finely tuned to your specific needs. It provides a robust defense against common web application attacks, such as SQL injection and cross-site scripting (XSS), without the need for additional on-site firewall plugins. IP Control and Access Management: Cloudflare’s firewall allows you to control and manage IP access with precision. You can easily set rules to block or allow specific IPs, IP ranges, or countries, giving you granular control over who can access your website. DDoS Protection: Cloudflare’s network is designed to withstand large-scale DDoS attacks, providing a shield against volumetric threats that would overwhelm on-site firewalls. This ensures uninterrupted website availability. Performance Optimization: Cloudflare’s content delivery network (CDN) optimizes the delivery of your website’s assets, including images, scripts, and stylesheets, resulting in reduced latency and faster load times for your visitors. Scalability and Reliability: Cloudflare’s infrastructure is highly scalable and redundant, ensuring that your website remains available even during traffic spikes or server failures. By integrating Cloudflare with your WordPress site, you not only enhance security but also optimize performance, reduce server load, and simplify IP access control, all while benefiting from Cloudflare’s global network and advanced security features. It’s a comprehensive solution that takes your website’s protection and performance to the next level. This is why we use it on all our websites, including the Pro version of this plugin as well. Therefore, we strongly recommend that you use it for your website if you haven’t already, whether you intend to use this plugin or not. Please note that we still use and recommend that you use a ‘Traditional’ server/software-based firewall like CSF, in conjunction with CloudFlare, to cover various security aspects such as traffic/ports for mail, FTP, SSH, etc.