Activity log for WordPress

A complete record of who did what and when: user, content, plugin and theme events, filterable, exportable to CSV or JSON, and forwardable to your SIEM.

5
event groups you can filter and export: logins, users, components, files, settings
CSV/JSON
exports with column selection; big ranges run in the background
6
SIEM mirror targets, from syslog to CloudWatch
Retention
you choose how many months of history to keep

What it does

When something breaks (or someone claims they did not touch anything), the activity log settles it. Every tracked action lands in a searchable trail: logins, content edits, plugin installs and deactivations, theme changes, role changes.

It is also the raw material for the rest of the monitoring stack: the incident engine correlates these events into attack timelines, and compliance reports are generated from this same data.

How it works

Event capture is per domain (user, post, plugin and theme events each have their own toggle), and retention defaults to six months, configurable from one to twenty-four, so the log never grows without bound. Exports come out as CSV or JSON with column selection and filters; ranges beyond five thousand events export in the background instead of tying up the admin.

For teams with central logging, the mirror service queues events out to syslog, AWS CloudWatch, Loggly, Papertrail, a custom webhook or an external database.

  • Per-domain event toggles; retention 6 months by default (1 to 24)
  • Filterable dashboard with full event detail
  • CSV and JSON export with column selection
  • WooCommerce order and product events when WooCommerce is active
  • Background export mode for large ranges
  • Log mirroring to 6 destinations

And in the free plugin?

Free ships a lighter event logger and a login-activity snapshot on the dashboard. The full trail (content, plugin and theme events with export and mirroring) is Pro.

Documentation

Activity logs dashboard

Browse, filter and inspect events.

Read the guide →

All logs view

The complete event stream.

Read the guide →

2FA audit log

Enrollments and verifications, tracked.

Read the guide →

Activity log questions

Will the log slow my site down or bloat the database?

Capture is per-domain so you only log what you care about, and retention is capped in months so old events are pruned automatically.

Can I get logs into Splunk or another SIEM?

Yes. Mirror events to syslog, CloudWatch, Loggly, Papertrail, a custom webhook or an external database, whichever your pipeline ingests.

Where does the data live?

In your own WordPress database. Nothing is sent anywhere unless you configure mirroring. There is no vendor cloud.

Related features

Pro

Incident detection

Five attack patterns detected from the activity trail.

Learn more →
Pro

SIEM & webhooks

Forward every event to your central logging.

Learn more →
Pro

Compliance reports

GDPR and audit reports generated from your real data.

Learn more →

All features →

Secure your site today

Install the free plugin from WordPress.org and set up real protection with the guided setup wizard. Upgrade to Pro whenever you need more.