Type something to search...
How to monitor WordPress activity logs?

How to monitor WordPress activity logs?

To monitor WordPress activity logs, install an activity log plugin such as WP Activity Log, Simple History, or Stream, since WordPress doesn't keep a user activity log by default. Configure it to record logins, user and role changes, plugin and theme changes, and content edits, then set up alerts for high-risk events and review the log on a regular schedule. For deeper visibility, combine the WordPress log with your server's access and error logs.

An activity log answers the question "who did what, and when?" on your site. It helps you spot suspicious behavior early, investigate problems after they happen, and keep a record of changes when several people manage the same site. This guide covers why logging matters, which plugins to use, what to track, how to set up alerts, and how to review and store logs sensibly.

Why Activity Logs Matter for Security

Most WordPress compromises leave traces. An attacker who logs in with a stolen password, creates a new administrator, installs a malicious plugin, or edits a theme file generates events that a good log records.

Activity logs help you:

  • Detect intrusions early: A login from an unfamiliar country or a new admin account at 3 a.m. is easy to spot in a log.
  • Investigate incidents: When something goes wrong, the log shows the sequence of events leading up to it.
  • Hold users accountable: On multi-author and client sites, you can see who changed a setting or deleted a page.
  • Troubleshoot non-security problems: A broken layout after a plugin update is easier to trace when you know exactly what changed.
  • Support compliance: Some regulations and client contracts expect a record of who accessed and changed data.

What WordPress Logs by Default

Out of the box, WordPress records very little. Post revisions show content changes, and the Users screen shows registration dates, but there's no built-in record of logins, failed login attempts, settings changes, or plugin activations.

That's why an activity log plugin is essential if you want real visibility.

The Best Activity Log Plugins

WP Activity Log

WP Activity Log, developed by Melapress, is one of the most comprehensive logging plugins. The free version logs hundreds of event types across core WordPress and popular plugins such as WooCommerce, Yoast SEO, and form builders.

Highlights:

  • Detailed event IDs and severity levels.
  • Logs logins, failed logins, user changes, content changes, plugin and theme changes, settings changes, and more.
  • Premium adds email and SMS notifications, reports, real-time user sessions management, log search and filters, and external log storage options.

Best for: Business sites, stores, and multi-user sites that need detailed, searchable logs.

Simple History

Simple History is a lightweight, free plugin with a clean interface. It shows a readable feed of recent activity on your dashboard.

Highlights:

  • Logs logins, failed logins, post and page changes, media uploads, plugin updates, and user profile changes.
  • Readable, timeline-style display.
  • RSS feed and WP-CLI support for viewing history.
  • Add-ons and a premium version for extra features.

Best for: Small sites and blogs that want easy visibility without complexity.

Stream

Stream logs user activity and system changes with a straightforward, filterable interface.

Highlights:

  • Records activity from core and supported plugins.
  • Filters by user, role, context, and action.
  • Basic alerts and webhook integrations.

Best for: Developers and site owners who like a simple, filterable list.

Security Suites With Logging

Some security plugins include logging features, such as Wordfence's Live Traffic and login security records, Solid Security's logs, and Sucuri Security's audit log. These are useful, but a dedicated activity log plugin usually records more detail about content and settings changes.

How to Set Up WP Activity Log

Here's a typical setup using WP Activity Log as an example. Other plugins follow similar steps.

  1. Install the plugin: Go to Plugins > Add New Plugin, search for WP Activity Log, then install and activate it.

  2. Run the setup wizard: The wizard asks how much you want to log. Choose a comprehensive level for security monitoring. You can refine it later.

  3. Set the retention period: Decide how long to keep logs. Several months is common for small sites, while stores and regulated businesses may need longer. Consider database size when choosing.

  4. Choose who can view logs: Restrict access to administrators or specific trusted users. Logs contain sensitive information like IP addresses and usernames.

  5. Review enabled events: Go to the plugin's Enable/Disable Events screen and confirm that key events are enabled, especially logins, user changes, and plugin changes.

  6. Exclude noise: Exclude specific users, roles, or IP addresses (such as your own monitoring service) if they generate lots of routine entries.

  7. Open the log viewer: Go to WP Activity Log > Log Viewer to see events as they happen.

What Events Should You Monitor?

Not every event is equally important. Focus your attention on these categories.

Authentication Events

  • Successful logins, especially from new IPs or unusual times.
  • Failed login attempts, particularly repeated ones.
  • Logins by administrator accounts.
  • Password resets and password changes.
  • Two-factor authentication changes.

User and Role Changes

  • New user registrations.
  • New administrator accounts.
  • Role changes, especially promotions to Administrator or Editor.
  • Changes to user email addresses (attackers often do this to take over accounts).
  • Deleted users.

Plugin, Theme, and Core Changes

  • Plugins or themes installed, activated, deactivated, or deleted.
  • Plugin and theme updates.
  • Files edited through the dashboard's theme or plugin editor.
  • WordPress core updates.

Settings Changes

  • Changes to Settings > General, especially the site address, admin email, "Anyone can register", and the default role.
  • Permalink changes.
  • Changes to security plugin settings.

Content Changes

  • Posts and pages published, updated, or deleted.
  • Changes to menus, widgets, and templates in the Site Editor.
  • Media uploads, especially unusual file types.

WooCommerce and Ecommerce Events

  • Changes to product prices and stock.
  • Changes to order status and refunds.
  • Payment gateway settings changes.

Setting Up Alerts

Logs are only helpful if someone notices important events. Rather than reading every entry, configure alerts for high-risk actions.

Good candidates for immediate alerts include:

  • A new administrator account is created.
  • An existing user is promoted to Administrator.
  • A plugin or theme is installed or a file is edited from the dashboard.
  • An administrator logs in from a new IP address.
  • The admin email address or site URL changes.
  • Many failed logins occur in a short period.

WP Activity Log's premium notifications, Wordfence's email alerts, and Stream's alerts can all handle some or all of these. Send alerts to an email address or chat channel that someone actually watches, and avoid turning on so many alerts that people start ignoring them.

Adding Custom Logging With Code

If you want to log something specific without a full plugin, you can hook into WordPress actions yourself. The example below records successful and failed logins to a custom log file. Add it to a small custom plugin (for example wp-content/plugins/sajjad-login-log/sajjad-login-log.php) rather than a theme, so it keeps working if you change themes.

<?php
/**
 * Plugin Name: Sajjad Login Log
 * Description: Logs successful and failed WordPress logins to a file.
 */

defined( 'ABSPATH' ) || exit;

function sajjad_login_log_write( $message ) {
    $upload_dir = wp_upload_dir();
    $log_dir    = trailingslashit( $upload_dir['basedir'] ) . 'sajjad-logs';

    if ( ! file_exists( $log_dir ) ) {
        wp_mkdir_p( $log_dir );
        // Prevent direct web access to the log directory on Apache.
        file_put_contents( $log_dir . '/.htaccess', "Require all denied\n" );
        file_put_contents( $log_dir . '/index.php', "<?php // Silence is golden.\n" );
    }

    $ip   = isset( $_SERVER['REMOTE_ADDR'] ) ? sanitize_text_field( wp_unslash( $_SERVER['REMOTE_ADDR'] ) ) : 'unknown';
    $line = sprintf( "[%s] %s | IP: %s\n", gmdate( 'Y-m-d H:i:s' ), $message, $ip );

    file_put_contents( $log_dir . '/logins.log', $line, FILE_APPEND | LOCK_EX );
}

add_action( 'wp_login', 'sajjad_log_successful_login', 10, 2 );
function sajjad_log_successful_login( $user_login, $user ) {
    sajjad_login_log_write( sprintf( 'Login success: %s (ID %d)', sanitize_user( $user_login ), $user->ID ) );
}

add_action( 'wp_login_failed', 'sajjad_log_failed_login', 10, 1 );
function sajjad_log_failed_login( $username ) {
    sajjad_login_log_write( sprintf( 'Login failed: %s', sanitize_user( $username ) ) );
}

add_action( 'set_user_role', 'sajjad_log_role_change', 10, 3 );
function sajjad_log_role_change( $user_id, $role, $old_roles ) {
    sajjad_login_log_write( sprintf( 'Role change: user %d from %s to %s', (int) $user_id, implode( ',', array_map( 'sanitize_key', $old_roles ) ), sanitize_key( $role ) ) );
}

This is intentionally simple. The .htaccess file blocks web access on Apache, but on Nginx you'll need a matching rule, or better, write the log outside the web root. For production use across many events, a maintained plugin is usually a better choice than rolling your own.

Don't Forget Server Logs

WordPress activity logs show what happened inside WordPress. Server logs show every request that reached your site, including ones that never got as far as logging in.

  • Access logs: Record every HTTP request, with IP, URL, status code, and user agent. Useful for spotting brute-force attempts, scanners, and unusual traffic.
  • Error logs: Record PHP and web server errors. A sudden spike can indicate an attack or a broken plugin.
  • SSH and authentication logs: On your own server, these show who logged in at the system level.

On a typical Ubuntu server, you can check these from the command line:

# Recent POST requests to the login page (Nginx)
sudo grep "POST /wp-login.php" /var/log/nginx/access.log | tail -20

# Count requests per IP to xmlrpc.php
sudo awk '$7 ~ /xmlrpc.php/ {print $1}' /var/log/nginx/access.log | sort | uniq -c | sort -rn | head

# Recent SSH logins
sudo grep "Accepted" /var/log/auth.log | tail -20

On Apache, the access log is usually at /var/log/apache2/access.log. On RHEL-based systems, SSH logins appear in /var/log/secure. On shared hosting, you can usually download access and error logs from your control panel.

How to Review Logs Effectively

A consistent routine turns logs into a real security tool.

  1. Daily (or via alerts): Respond to high-severity alerts immediately.
  2. Weekly: Skim the log for new users, role changes, plugin changes, and admin logins from unfamiliar locations.
  3. Monthly: Look for patterns, such as repeated failed logins for the same username, and review whether your alerts are still useful.
  4. After any incident: Export the relevant time window and keep a copy before logs roll over.

When reviewing, ask:

  • Do I recognize every administrator login?
  • Did anyone install, activate, or edit plugins or themes unexpectedly?
  • Were there any role changes I didn't approve?
  • Did any critical settings change?

Storing Logs Safely

Logs stored in your WordPress database have a weakness: if an attacker gains admin or database access, they can delete the evidence. For higher-value sites, consider:

  • External log storage: Premium versions of WP Activity Log can send logs to external databases or services.
  • Centralized logging: Forward server logs to a service or a separate log server using tools like rsyslog.
  • Regular exports: Periodically export logs to a secure location.
  • Sensible retention: Keep enough history to investigate incidents, but don't keep personal data longer than necessary for privacy reasons.

Remember that activity logs contain personal data such as IP addresses and usernames. Mention logging in your privacy policy and limit who can see the logs.


FAQ: WordPress Activity Logs

No. WordPress stores post revisions and registration dates, but it doesn't record logins, settings changes, or plugin activity. You need a plugin such as WP Activity Log, Simple History, or Stream for that.

WP Activity Log is the most comprehensive option for business sites and stores. Simple History is a great lightweight choice for smaller sites, and Stream suits users who like a simple filterable list.

Logging adds a small amount of work on events like logins and saves, which is rarely noticeable. Very long retention periods on busy sites can grow the database, so set a sensible retention limit.

Several months is a reasonable default for small sites. Stores, agencies, and regulated businesses may need longer. Balance investigation needs against database size and privacy obligations.

Yes, if they gain administrator or database access, logs stored in the WordPress database can be altered or deleted. Sending logs to external storage or exporting them regularly reduces this risk.

Alert on new administrator accounts, role promotions, plugin or theme installations, file edits from the dashboard, admin logins from new IPs, and changes to the admin email or site URL.


Conclusion

Monitoring WordPress activity logs gives you a clear picture of who is doing what on your site. Because WordPress doesn't log user activity on its own, install a dedicated plugin like WP Activity Log, Simple History, or Stream, and make sure it records logins, user and role changes, plugin and theme changes, settings changes, and key content updates.

Then make the logs work for you. Set up alerts for high-risk events, review the log on a regular schedule, and combine it with server access logs for a fuller view. Store logs somewhere an attacker can't easily erase them, and limit who can see them. With good logging in place, you'll catch problems sooner and understand them better when they happen.

Share :

Related Posts

What are the best WordPress security plugins?

What are the best WordPress security plugins?

The best WordPress security plugins for most sites are Wordfence, Sucuri Security, Solid Security, MalCare, All-In-One Security (AIOS), Patchstack, a

Dive Deeper
What are the most common website security threats?

What are the most common website security threats?

The most common website security threats are vulnerable or outdated software, weak and stolen passwords, malware infections, injection attacks like S

Dive Deeper
What is the difference between posts and pages in WordPress?

What is the difference between posts and pages in WordPress?

The main difference between posts and pages in WordPress is that posts are timely, dated entries that appear in your blog feed, archives, and RSS fee

Dive Deeper