Product
Solutions
Compare
Resources
Get early access Talk to us
Security

How to track user activity in WordPress with an audit log

A WordPress audit log shows who did what on your site and when: logins, content edits, plugin changes, settings and user role changes. WordPress does not keep one on its own, so you add it with a plugin, or with a WordPress activity log that covers every site you manage in one place.

Example WordPress audit log entry showing who made the change, what they did, on which site and from which IP address, when it happened and the result, with a note that WordPress does not log failed logins, plugin changes or role changes on its own
What a useful WordPress audit log entry records. Example with sample data.

The short answer

A WordPress audit log is a timestamped record of who did what on a site: who signed in, which plugin was deactivated, who changed a user role or edited a page. WordPress does not keep one on its own, so you add it.

  • One site: install an audit log plugin such as WP Activity Log, Simple History or Stream.
  • Record: logins and failed logins, user and role changes, plugin, theme, core and settings changes.
  • Keep it safe: keep 90 days to 12 months, and copy it somewhere a site administrator cannot edit.
  • Many sites: use one log for every site, such as the activity log in WPCentrify.

What is a WordPress audit log?

A WordPress audit log, also called an activity log or audit trail, is a list of events on a site. Each entry says who did something, what they did, where, when and with what result. It answers the questions that come up after something goes wrong: who deactivated the form plugin, when the new administrator appeared, whether anyone touched the site over the weekend.

A security audit log is the same thing seen from a security angle. It focuses on events that can signal an attack, such as failed logins, new administrators and changed files. In practice, one good WordPress user activity log covers both jobs.

Does WordPress keep an activity log on its own?

Only in small pieces. Out of the box, WordPress records:

  • Post revisions. Each saved draft or update of a post or page is stored with its author and date, so you can compare versions and restore an older one.
  • The last editor. WordPress stores who last modified each post.
  • Active login sessions. For each session that is still open, WordPress keeps the login time, IP address and browser. The record goes away when the session ends.

It does not record failed logins, plugin or theme installs and deactivations, setting changes, role changes, deleted users or past sign-ins. Your host's server logs will not fill the gap either: WordPress's own hardening guide notes that server logs do not show which logged-in user made a request. To track user activity properly, you need an audit log plugin or a platform that does it for you.

What a WordPress user activity log should record

You do not need every event. You need the ones that explain breakage and the ones that signal an attack.

What a WordPress user activity log should record
EventWhy it matters
Logins, logouts and failed loginsShows password guessing and sign-ins from places you do not expect.
New users and role changesA new administrator you did not create is one of the clearest signs of a break-in.
Plugin and theme installs, updates, activations and deletionsThe usual cause when a site breaks or a feature stops working, including automatic updates that ran overnight.
WordPress core updatesExplains changes in behavior after a release.
Settings changesCatches a changed site address, admin email or permalink setting.
Posts and pages published, edited or deletedAnswers "who changed this page?" and helps restore lost content.
Application passwords and API accessNew application passwords can give lasting access without a login.
Store events on WooCommerceProduct, price, stock, coupon and order changes have a direct cost.

Our recommendation. Most audit log plugins let you turn individual event types on or off.

Anatomy of a useful audit log entry

An entry is only useful if it answers five questions without anyone having to guess, as in the example at the top of this page:

  • Who: the user account and its role, not just "admin".
  • What: the action and the object, with versions where they matter: "Deactivated WP Mail SMTP 4.1.1".
  • Where: the site, the screen or source, and the IP address.
  • When: an exact time with its time zone.
  • Result: whether it worked, and what it changed.

This is also why shared logins are a problem. If five people use the same administrator account, the log can only ever say "admin did it". Give each person their own account with the right WordPress user role, and the log starts to mean something.

How to add an audit log to WordPress

For a single site, an audit log plugin is the quickest route. These are the main options, compared on facts from each tool's own pages.

WordPress audit log plugins compared
ToolActive installsFree versionPaid version adds
WP Activity Log300,000+Logs every event type the premium edition logs, stored in the WordPress databaseReports, email, SMS and Slack alerts, search, live sessions; external database and log mirroring on higher tiers. From $139 a year for 1 site.
Simple History300,000+Content, users, logins, plugins, themes and settings. Keeps 30 days by default and masks IP addressesAlerts, log forwarding, longer retention, CSV and JSON export. From $79 a year for 1 site.
Stream70,000+Free and open source. Filters, email and webhook alerts, CSV and JSON exportNo paid version
Wordfence Audit Log5 million+ (Wordfence)Preview mode that stores limited data on the siteFull audit log with tamper-proof storage off the site, on Wordfence premium licenses
WPCentrifyPlatform, not a pluginFree during early accessOne append-only log for every connected site, with evidence attached to each update and restore

Install counts and prices from each tool's WordPress.org page and website, checked 10 October 2026. Prices change, so check before you buy. Disclosure: WPCentrify is our product.

Whichever you choose, set it up in this order:

  1. Pick a tool that fits the job. For one site, a plugin such as WP Activity Log, Simple History or Stream. For many sites, a platform that logs every site in one place.
  2. Install it and confirm it is recording. Log out and back in, then check that the login appears in the log.
  3. Choose what to record. Keep logins, user and role changes, plugin, theme and core changes and settings on. Add content and store events if you need them.
  4. Set a retention period. Ninety days is a sensible minimum; keep 12 months if you handle payments or work under a contract that asks for it.
  5. Turn on alerts for the events that matter. New administrators, failed logins in bulk and deactivated security plugins deserve an email, not a weekly glance.
  6. Keep a copy off the site. Send the log to an external store or a service that keeps it where a site administrator cannot change it.
  7. Read it on a schedule. Spend five minutes a week on it. A log nobody reads is only useful after the damage is done.

How long should you keep WordPress audit logs?

Long enough to investigate problems that are found late, and no longer than you need. Two rules shape the answer:

  • Privacy law. Logs hold usernames, emails and IP addresses. The EU's top court ruled in the Breyer case that a dynamic IP address can be personal data for a website operator, and the GDPR names IP addresses as online identifiers. Its storage limitation principle says personal data should be kept no longer than necessary. Mention the log in your privacy policy and delete old entries on a schedule.
  • Payment rules. If a site is in scope for PCI DSS, requirement 10.5.1 asks for at least 12 months of audit log history, with the most recent three months available immediately.

For most business sites, 90 days is a sensible minimum and 12 months is enough. Some plugins default to much less: Simple History keeps 30 days unless you change it.

Keep the log where an attacker cannot edit it

Most audit log plugins store the log in the WordPress database. That is convenient, but it means anyone who gets administrator or database access can change or delete the record of what they did. The OWASP Logging Cheat Sheet recommends a central log store, copies on read-only media and tamper detection for exactly this reason, and PCI DSS asks for logs to be protected from changes and backed up to a central server.

In WordPress terms, that means one of three things: a plugin that mirrors the log to an external database or log service, a security plugin that stores events off the site (as Wordfence's audit log does on premium licenses), or a management platform that keeps the log on its own infrastructure.

How to use an audit log when something breaks

A typical case: a client says the contact form stopped sending emails sometime last week. Without a log, you check the form, the mail settings and the host, and you guess. With a log, you filter by the last seven days and see the entry in the example above: an Editor deactivated the SMTP plugin on Tuesday morning. The fix takes a minute and the conversation with the client takes two.

The same filter answers other common questions. A new administrator appeared overnight? The log shows how it was created. A page lost a section? The revision history and the log together show who edited it, and a recent backup gets it back. If the answer points to a break-in, follow our steps for a hacked WordPress site.

Tracking user activity across many WordPress sites

An audit log plugin works one site at a time: one plugin to install, configure and update per site, and one more screen to check. With twenty or fifty sites, the log that would have explained the problem is on the one site nobody looked at.

WPCentrify takes a different approach. (Disclosure: WPCentrify is our product.) Its WordPress activity log keeps one timeline for every site you connect, as part of a WordPress website management platform that also runs updates, backups, uptime and security checks.

  • One timeline for every site. Filter by site, client, person, action type or date range and answer "what happened to this site last Friday" in seconds.
  • Evidence attached, not just an entry. A safe update record includes its risk score, the checks that ran, before and after screenshots and the result. A restore record says what was restored and how long it took.
  • Changes made directly in wp-admin. Plugin and theme activations, deactivations and updates, user role changes and core updates made outside WPCentrify show up too. Users and roles themselves are managed in WordPress user management, and access to WPCentrify in team and client access.
  • Append-only. Entries cannot be edited or deleted from the interface by anyone, including the account owner.
  • Sign-in sessions on the record. Every one-click login is logged with who signed in, to which site, as which account and what they changed.
  • 12 months by default, configurable for longer, with CSV and JSON export for any period.
  • Feeds client reports, so monthly reports come from the record rather than from memory.

To be clear about the limits: the platform log records what WPCentrify does and the significant changes made on each site, not every keystroke in the post editor. If you need a full per-site record of content edits, pair it with revisions or a per-site plugin. For suspicious sign-ins, new and hidden administrators and changed files, Sentinel security monitoring watches every site and emails you when something needs a person.

Sources

All sources checked on 10 October 2026.

Answers

Questions about WordPress audit logs

Not a full one. WordPress keeps post revisions with their author, records who last edited each post and stores details of login sessions that are still active. It does not record failed logins, plugin and theme changes, settings changes, role changes or deleted users, so you need a plugin or a management platform for that.

In WordPress they usually mean the same thing: a timestamped record of who did what on the site. Audit log and audit trail are the terms used in security and compliance, activity log is the friendlier name most plugins use.

It depends on what you need. WP Activity Log and Simple History both have more than 300,000 active installs and log a wide range of events in their free versions. Stream is free and open source. Wordfence includes an audit log as a premium feature with off-site storage. If you manage many sites, a platform that logs every site in one place saves a plugin per site.

Open the page in the editor and look at its revisions. Each revision shows who saved it and when, and you can compare any two versions. For changes outside the content, such as a plugin being deactivated, you need an audit log, because WordPress does not record them.

Keep them long enough to investigate a problem that is found late, which for most sites means 90 days to 12 months. Card payment rules (PCI DSS) require at least 12 months for systems in scope. Logs contain personal data such as IP addresses, so do not keep them longer than you need.

Yes. Logs usually hold usernames, email addresses and IP addresses, and EU law treats IP addresses as personal data. Mention the log in your privacy policy, mask IP addresses if you do not need them in full and delete old entries on a schedule.

If the log is stored only in the WordPress database, anyone who gains administrator or database access can edit or erase it. That is why security guidance recommends copying logs to a separate system where they cannot be changed.

On most sites the effect is small, because each recorded event adds one database write. The log table can grow large on busy sites, so set a retention period, or send the log to an external store if your plugin supports it.

Use one log for every site instead of a separate plugin and screen per site. WPCentrify keeps a single timeline for every connected site, records what the platform and your team did with evidence attached, picks up important changes made directly in wp-admin and cannot be edited, even by the account owner.

Early access

One activity log for every site you manage

Every update, restore, login and permission change across your WordPress sites, recorded with the evidence and impossible to edit.

Free during early access. No credit card required.