sandywp / plugins / aryo-activity-log
Activity Log
Monitor & Record User Changes
Monitor every change on your WordPress site — who did what, when, and where it came from — for a complete audit trail and stronger security.
Ready in seconds.
v2.14.1 200,000+ installs WP 6.2+ PHP 7.4+

What you get inside
3 screens-
The log viewer page
-
The settings page
-
Screen Options
About this plugin
An easy to use, fully supported WordPress activity log plugin.
Want to know exactly who does what on your WordPress site? Activity Log works like an airplane’s black box: it quietly records every action in the WordPress admin — and now every request made through the REST API, WP-CLI, WP-Cron, and more — so you always know:
- If someone is trying to hack your site
- When a post was published, and who published it
- If a plugin/theme was activated/deactivated
- Suspicious admin activity
The plugin doesn’t require any setup; it works right out of the box, runs on its own database table so it doesn’t slow down your site, and stays out of your way until you need it.
What’s New
- Request Source Tracking – See exactly where each change came from: the WP Admin, the REST API, WP-CLI, WP-Cron, XML-RPC, or the WP Abilities API, including which Application Password was used. Filter the log by source to quickly spot automated or API-driven changes alongside manual admin activity.
- Email Logging – Capture all emails sent from your WordPress site for streamlined debugging and compliance. Especially useful for WooCommerce stores tracking order emails alongside other site events.
- Export to CSV – Export your Activity Log data to CSV, or build support for your own format with our dedicated Export API.
- Data Privacy and GDPR Compliance – Export or erase log data directly through the WordPress Privacy Tools.
If you have more than a handful of users, keeping track of who did what by hand is virtually impossible. Activity Log solves that by tying every action back to the user who triggered it, in an easy-to-filter view right on your WordPress dashboard.
With the Activity Log you can record:
- WordPress – Core updates
- Posts – Created, updated, deleted
- Pages – Created, updated, deleted
- Custom Post Type – Created, updated, deleted
- Tags – Created, updated, deleted
- Categories – Created, updated, deleted
- Taxonomies – Created, updated, deleted
- Menus – Created, updated, deleted
- Media – Created, updated, deleted
- Comments – Created, approved, unapproved, trashed, untrashed, spammed, unspammed, deleted
- Users – Login, logout, login failed, update profile, registered, deleted
- Plugins – Installed, updated, activated, deactivated, changed
- Themes – Installed, updated, deleted, activated, changed (Editor and Customizer)
- Widgets – Added to sidebar, deleted from sidebar, order widgets
- Setting – General, writing, reading, discussion, media, permalinks
- Options – Extended custom settings for 3rd party plugins
- Export – Exported activity log file
- Request Source – WP Admin, REST API, WP-CLI, WP-Cron, XML-RPC, WP Abilities, and Application Password name when used
- WooCommerce – Track products, orders, customers, and more
- bbPress – Forums, topics, replies, taxonomies, and other actions
- Emails sent from WordPress site – Sending successful, sending failed
- There’s more, of course, but you get the point…
For each event recorded by the activity log, the following details are also logged:
- Date and time of occurrence
- User and user role responsible for the change
- Source IP address from which the change originated
- Request source — WP Admin, REST API, WP-CLI, WP-Cron, XML-RPC, or WP Abilities
- Affected object where the change occurred
Data Storage and Performance
All events are stored in a dedicated custom database table, keeping the impact on your site’s performance to a minimum — even under heavy traffic.
Uninstall Clean-up
Uninstalling the plugin removes all of its data from your database automatically, leaving nothing behind.
What users have to say
- “Its tools, particularly for data privacy and GDPR compliance, make it indispensable for websites operating within European Union boundaries or dealing with EU citizens’ data” – HubSpot.com
- “If you’re after a competent WP security audit log plugin with all the basic features you need, Activity Log is it!” – WPAstra.com
- “Activity Log features a remarkably straightforward dashboard interface, providing administrators with an at-a-glance understanding of site interactions” – Malcare.com
- “Thanks to this step, we’ve discovered that our site was undergoing a brute force attack” – Artdriver.com
- “Activity Log lets you track a huge range of activities. Overall, very easy to use and setup” – ElegantThemes.com
Contributions:
Would you like to contribute to this plugin? You’re more than welcome to submit your pull requests on the GitHub repo. And, if you have any notes about the code, please open a ticket on the issue tracker.
Questions
- Requirements
Requires PHP 7.4 for list management functionality.
- What is the plugin license?
This plugin is released under a GPL license.
- Will this slow down my site?
No. Activity Log stores every event in its own dedicated database table instead of mixing into WordPress’ core tables, so logging has minimal impact on your site’s performance, even under heavy traffic.
- Can I export logs?
You can easily export logs with Activity Log. We also support exporting filtered results. Filter by the time the action took place, roles, users, options, action type, and more.
- Can I see where a change came from?
Yes. Each log entry records its Request Source, so you can tell whether a change was made through the WP Admin, the REST API, WP-CLI, WP-Cron, XML-RPC, or the WP Abilities API. If the request was authenticated with an Application Password, its name is shown as well. Use the Source filter on the log screen to narrow results down to a specific channel.
- How long are logs kept?
By default, logs are kept for 30 days, but you can set your own retention period from the settings page — from a few days to forever. Failed login attempts and email logs can also be kept or discarded independently.
- Do I have to collect visitor IP addresses?
No. If you’d rather not store IP addresses for privacy reasons, set the “Visitor IP Detected” option to “Do not collect IP” and the IP column will be hidden going forward.
- Does this work on WordPress Multisite?
Yes. Activity Log fully supports Multisite, logging activity per site and cleaning up its data correctly when a site is removed from the network.
sandywp / also on the shelf
Try another plugin
4.7 · 300K+ installs
The #1 user-rated activity log plugin for event logging, activity monitoring and change tracking.
Stream – Activity Log & Audit Trail
4.3 · 80K+ installs
Real-time activity log and audit log for WordPress. Track every user action — logins, edits, plugin & settings changes — and…
Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File…
4.8 · 30K+ installs
Smart WordPress security that blocks bots automatically, guides you to what matters, and repairs problems — without drowning you…
Spin up a real WordPress site in seconds.
Test plugins, build a demo, hand a client a link — then squash it and start again. No local setup, no Docker.