User Login History
The plugin helps you to track any visitor’s login details with the following attributes: Login – Login Date-Time Logout – Logout Date-Time Last Seen – Last Seen Date-Time Login Status – Logged in/Logged out/Failed Online Status – Online/Offline/Idle Session Duration – How long the user stayed on your website per session. User ID Username Current Role Old Role – The role while user gets logged in into your website. Browser Operating System IP Address Country Name and Country Code (Based on IP Address) Timezone (Based on IP Address) Mobile (Pro Feature) – Whether the user loggedin with a mobile (e.g. tablet and mobile phone) device. Proxy IP (Pro Feature) – Whether the user loggedin from a proxy IP. Features The User Login History Free Version plugin has all the basic features that will help you to know your website visitors. The User Login History Pro Version plugin has some more premium and useful features along with all the basic features. AUTO LOGOUT (Pro Feature) – Automatically logout idle users every ‘X’ minute. You can also specify roles. This feature is built on WordPress Cron Job. IP ADDRESS CONTROL (Pro Feature) – Allows you to control of masking and hiding of user’s IP address. EMAIL ALERT (Pro Feature) – Allows you to get notified via email for success/failed login. You can also specify roles and modify email templates. AUTO DELETE OLD RECORDS (Pro Feature) – Automatically delete the records older than ‘X’ days. You can also specify the roles. This feature is built on WordPress Cron Job. TRACK SPECIFIC ROLES (Pro Feature) – Allows you to track specific roles only. CSV SEPARATOR (Pro Feature) – Allows you to enter a CSV separator for CSV export. REPORT – TIMESHEET (Pro Feature) – Generate a timesheet report REPORT – NO LOGIN LIST (Pro Feature) – Generate a report of users who have not login for a given date range REPORT – LOGIN DEVICE (Pro Feature) – Generate report of login count based on IP address LOGIN TIME TRACKER – Tracks the date and time of user’s login, logout, last seen, etc. LOGIN STATUS TRACKER – Tracks user’s login status to check if the user is logged in, logged out, failed, etc. ONLINE STATUS TRACKER – Tracks user’s online status to check if the user is online, idle or offline. USER INFORMATION TRACKER – Tracks user’s old role, current role, username, etc. DEVICE INFORMATION TRACKER – Tracks user’s operating system and browser. GEO LOCATION TRACKER – Tracks user’s timezone and country based on IP address. ADVANCED SEARCH FILTER – Filters the records. CSV EXPORTER – Exports the records in csv format. CUSTOMIZABLE SHORTCODE – Renders the records on front-end. PREFERABLE TIMEZONE (DEPRECATED! Will be removed in 3.0) – You can select your preferred timezone to be used for the listing table. MULTISITE NETWORK – On the network admin area, you can see the listing table which shows all the records fetched from all the blogs of the current network. Translations You can download the language files from here. Do you want to translate this plugin to another language? I recommend using POEdit or if you prefer to do it straight from the WordPress admin interface use Loco Translate. When you’re done, post your file on this issue. . You can also translate the plugin online. How to use the plugin? To see all the tracked records in admin, click on the plugin menu shown in the left sidebar. To see all the tracked records of current logged in users in frontend, use the following shortcode: Basic Usage of Shortcode: In your template file: In your content: [user_login_history] Advanced Usage of Shortcode: In your template file: In your content: [user_login_history limit='20' reset_link='custom-uri' columns='ip_address,time_login' date_format='Y-m-d' time_format='H:i:s'] Shortcode Parameters You can use the shortcode to display the login list of the current user. It does not display the login list of other users. Here is the list of all the parameters that you can use in the shortcode. All the parameters are optional. title – Title of the listing table. Default is: empty string limit – Number of records per page. Default is: 20 reset_link – Custom URI of the listing page. For the input “my-login-history”, it will render a reset link with the following URL: www.example.com/my-login-history Default is the full permalink of the current post or page. date_format – A valid date format. Default is: Y-m-d time_format – A valid time format. Default is: H:i:s show_timezone_selector – Whether you want to show timezone selector or not. Any value other than “true” will be treated as “false”. Default is: true roles (Pro Feature): It allows you to set role(s) in the shortcode parameter so that you can see the login list of other users who belong to the role(s). [user_login_history roles=’administrator, editor’] columns – List of column keys used to render columns on the listing table. Default keys are: operating_system, browser, time_login, time_logout Available Column Keys: user_id, username, role, old_role, ip_address, country_name, browser, operating_system, timezone, user_agent, duration, time_last_seen, time_login, time_logout, login_status Geo Tracking The plugin uses a free third party service to detect country and timezone based on IP address. Many projects are using this free service due to which sometimes the server of the service provider becomes slow. This may affect the login functionality of your website. Hence it is recommended that you do not enable this functionality unless you have paid service or reliable service. If you have a paid service, you can contact us to integrate it. Login Statuses Logged in – If the user gets logged in successfully. Logged out – If the user clicks on logout button and gets logged out successfully. Failed – If the user enters invalid credentials. Blocked (DEPRECATED! Will be removed in 3.0) – This is used for the multisite network. By default, a user can login to any blog and then WordPress redirects to the blog on which the user is associated. The plugin saves login info at the blog on which the user logged in but cannot not save the information of the blog on which WordPress redirects the user. You can prevent this behavior by using the plugin setting. Please note that we already removed this status from the pro version plugin but not from the free version yet. Unknown (DEPRECATED! Will be removed in 3.0) – Since we have added a new column “Login Status” in the version 1.7.0, its value will be empty in the database table after upgrading to 1.7.0. To filter such records, you can use this status. Note – In case, a user log in with “Remember Me” and then closes his browser without doing logout, it will show the login status as “Logged in”. Bug Fixes If you find any bug, please create a topic with a step by step description to reproduce the bug. Please search the forum before creating a new topic. Keywords user log, log, logger, detector, tracker, membership, register, sign up, admin, subscriber, editor, contributor, geo location, profile, front end registration, manager, report, statistics, activity, user role editor
Top keywords
- user33×2.76%
- login30×2.51%
- pro14×1.17%
- logged12×1.00%
- ip11×0.92%
- status11×0.92%
- time11×0.92%
- address10×0.84%
- records10×0.84%
- role10×0.84%
- ip address9×0.75%
- logout9×0.75%
Login Armor
🇫🇷 Fully translated into French. Interface et documentation intégralement disponibles en français. Thirteen security modules. One lightweight plugin. No premium tier. Login Armor protects WordPress login, accounts and administration with thirteen independent modules. It is built for agencies, freelancers and site owners who want practical security, clear evidence and safe defaults without a remote dashboard, bundled telemetry or upsells. Why Login Armor Complete and free: every module is included under the GPL. Lightweight: modules load only when needed and normal login checks add less than 2 ms on a typical setup. Private by default: data stays on your site. Optional external calls are disabled until you enable the related feature. Ready for real sites: multisite support, reverse-proxy controls, WP-CLI commands and production-safe defaults. Thirteen security modules Hide Login: replace wp-login.php with a private slug and return a 404 or redirect blocked visitors to a chosen URL. Brute Force Protection: escalating lockouts, subnet blocking, trusted proxy headers and coverage for login, password recovery, registration, XML-RPC and REST users. Hardening: fifteen controls for XML-RPC, pingbacks, file editing, version exposure, application passwords, author enumeration, reserved usernames, honeypots and new-admin alerts. Two-Factor Authentication: TOTP, email codes, backup codes, trusted devices, per-role enforcement, grace periods and recovery. Detection and Incidents: group raw events into attack patterns with severity, timelines, source IPs, targeted users and one-click actions. Activity Log: tamper-evident admin audit trail with filters, CSV export, retention controls and optional signed SIEM forwarding. Security Headers: CSP, X-Frame-Options, Permissions-Policy, Referrer-Policy and X-Content-Type-Options for login and lockout pages, with optional site-wide baseline headers. Breach Check: privacy-preserving Have I Been Pwned password checks and an optional XposedOrNot email check. Password Policy: length and character rules, username exclusion, breached-password rejection and optional non-locking expiration reminders. Session Management: idle timeout, maximum lifetime, optional single-device access and one-click revocation of other sessions. IP Geolocation: cached country lookup for IPs shown in Incidents and Events, with private ranges excluded. Request Firewall: optional, monitor-first filtering of malicious paths, query strings and HTTP methods, with administrator exclusions and IP/path allowlists. Bot Challenge: an invisible proof-of-work the browser solves before the login form is accepted, an alternative to CAPTCHAs with no external service; monitor-first, then enforce. Additional tools Login Armor also includes guided onboarding, a 0-100 security score, conflict detection, email/Slack/Discord/webhook notifications, a dashboard widget and a complete WP-CLI suite. The optional AI Security Briefing uses your own WordPress AI connector to explain a thirty-day security snapshot or a single incident. It always starts with deterministic facts, works without AI and sends nothing until an administrator explicitly requests an analysis. GPL forever. PHP 8.1+. WordPress 6.8+. Zero dependencies. Treize modules de sécurité. Une seule extension légère. Aucune version premium. Login Armor protège la connexion, les comptes et l’administration de WordPress grâce à treize modules indépendants. L’extension s’adresse aux agences, freelances et propriétaires de sites qui veulent une sécurité concrète, des preuves lisibles et des réglages sûrs, sans tableau de bord distant, télémétrie imposée ni upsell. Pourquoi Login Armor Complet et gratuit : tous les modules sont inclus sous licence GPL. Léger : les modules se chargent uniquement lorsque nécessaire et les contrôles ajoutent moins de 2 ms sur une connexion normale. Privé par défaut : les données restent sur votre site. Les appels externes optionnels sont désactivés tant que vous n’activez pas la fonction concernée. Prêt pour la production : multisite, reverse proxies, commandes WP-CLI et réglages par défaut sécurisés. Treize modules de sécurité Masquer la connexion : remplace wp-login.php par un slug privé et renvoie une 404 ou redirige les visiteurs bloqués vers l’URL choisie. Protection contre la force brute : verrouillages progressifs, blocage de sous-réseaux, proxies de confiance et protection de la connexion, récupération, inscription, XML-RPC et REST users. Renforcement : quinze contrôles pour XML-RPC, les pingbacks, l’éditeur de fichiers, la version, les mots de passe applicatifs, l’énumération d’auteurs, les identifiants réservés, le pot de miel et les alertes nouvel administrateur. Authentification à deux facteurs : TOTP, codes par e-mail, codes de secours, appareils de confiance, application par rôle, période de grâce et récupération. Détection et incidents : regroupe les événements en scénarios d’attaque avec sévérité, chronologie, IP sources, comptes ciblés et actions immédiates. Journal d’activité : piste d’audit admin infalsifiable avec filtres, export CSV, rétention et transfert SIEM signé optionnel. En-têtes de sécurité : CSP, X-Frame-Options, Permissions-Policy, Referrer-Policy et X-Content-Type-Options pour les pages de connexion et de verrouillage, avec en-têtes de base optionnels sur tout le site. Détection de fuites : vérification confidentielle des mots de passe via Have I Been Pwned et contrôle optionnel des e-mails via XposedOrNot. Politique de mot de passe : longueur, classes de caractères, exclusion de l’identifiant, rejet des mots de passe compromis et rappels d’expiration non bloquants. Gestion des sessions : délai d’inactivité, durée maximale, accès limité à un appareil et révocation des autres sessions. Géolocalisation IP : pays des IP affichées dans Incidents et Événements, avec cache et exclusion des plages privées. Pare-feu de requêtes : filtrage optionnel, d’abord en surveillance, des chemins, requêtes et méthodes HTTP malveillants, avec exclusion des administrateurs et listes d’autorisation IP/chemins. Défi anti-bot : une preuve de calcul invisible résolue par le navigateur avant validation du formulaire de connexion, alternative aux CAPTCHA sans service externe ; d’abord en surveillance, puis en blocage. Outils complémentaires Login Armor inclut aussi un assistant de configuration, un score de sécurité de 0 à 100, la détection de conflits, les notifications par e-mail, Slack, Discord ou webhook, un widget de tableau de bord et une suite WP-CLI complète. Le briefing de sécurité IA optionnel utilise votre propre connecteur IA WordPress pour expliquer les trente derniers jours ou un incident précis. Il commence toujours par des faits déterministes, fonctionne sans IA et n’envoie rien tant qu’un administrateur ne demande pas explicitement une analyse. Conçu par Login Armor est conçu et maintenu par Fabrice Ducarme de WPFormation. Nous l’utilisons sur chaque site que nous livrons. Présentation et fonctionnement de Login Armor Guides de sécurité WordPress sur WPFormation Veille des vulnérabilités WordPress sur WPFormation GPL pour toujours. PHP 8.1+. WordPress 6.8+. Zéro dépendance. External Services Login Armor has no telemetry and requires no Login Armor account. The following services are contacted only when WordPress itself or an administrator enables the related feature. WordPress AI connector (optional) The AI Security Briefing sends a security prompt through the administrator’s own WordPress AI connector only after they click an analysis button. Minimised mode sends counts, categories, severities and role buckets without clear IP addresses or usernames. Explicit deep mode also sends IP addresses and event details. Login Armor stores no provider API key. The selected AI provider’s terms and privacy policy apply. Slack, Discord or custom webhook (optional) When an administrator enables an incident notification channel, Login Armor sends the incident type, severity, IP address, target username, event count and site URL to the configured endpoint. The separate signed Activity Log forwarding option sends the event, object, user ID/login/role, IP address, description, integrity hashes, site URL and plugin version to the administrator’s SIEM or custom webhook. Slack: Terms | Privacy Discord: Terms | Privacy Custom webhook: terms and privacy are controlled by the administrator’s chosen endpoint. Gravatar The Activity Log uses WordPress core’s get_avatar(). If avatars are enabled in WordPress, a hashed email address may be sent to Gravatar to retrieve the image. Gravatar: Terms | Privacy Have I Been Pwned (optional) Breach Check and the optional compromised-password policy send only the first 5 characters of a password’s SHA-1 hash to the Pwned Passwords API. The password and full hash never leave the site. Checks fail soft if the service is unavailable. Public registration and password-reset validation do not call the service; authenticated checks remain active. Have I Been Pwned: Privacy | Acceptable Use XposedOrNot (optional) The separate Email check, disabled by default, sends the user’s email address and a plugin-identifying User-Agent to XposedOrNot when a user is created or changes email. XposedOrNot: Service | Privacy ipwho.is (optional) IP Geolocation sends a displayed public IP address to ipwho.is when an administrator opens Incidents or Events. Results are cached for 30 days. Private and reserved ranges are never sent, and developers can replace the lookup through the login_armor_geoip_lookup filter. ipwho.is: Service | Documentation