Everything the platform does
Every update, backup, restore, policy change, permission change and one-click login, with actor and timestamp.
Who did what, on which site, when, and what happened as a result. Updates, restores, logins, permission changes and policy edits, all recorded automatically and exportable whenever you need them.
Included on every plan. No add-on pricing.
Updated
A WordPress activity log is a dated record of what happened on a WordPress site: who signed in, which plugins and themes were installed, updated or switched off, which posts and pages changed and which settings were edited, each with the person and the time. WordPress saves revisions of posts, but it keeps no record of who changed a plugin, a user or a setting, so the log has to come from a plugin or a management platform.
WPCentrify keeps an activity log for every WordPress site you connect and shows them together in one timeline. It records the changes made inside wp-admin on each website and everything done from WPCentrify itself, such as updates, backups, restores and one-click logins, so you can answer "what changed, who did it and when" for one site or for all of them. Our guide to the WordPress audit log covers what to log and for how long.
A client calls to say something broke over the weekend. You need to know what changed and when, and the honest answer is usually that nobody wrote it down. WordPress itself keeps almost no history: you can see current plugin versions but not when they changed or who changed them. Our guide to the WordPress audit log sets out exactly what WordPress records on its own and what it misses.
Without a record you are reconstructing events from memory and file timestamps, while a client waits and forms an opinion about your professionalism.
Every update, backup, restore, policy change, permission change and one-click login, with actor and timestamp.
An update record includes the risk score it received, the checks that ran, the before and after screenshots, and the result. A restore record includes what was restored and how long it took.
If somebody activates a plugin directly in wp-admin, that appears too, so the log reflects the site rather than only your actions. Deciding whether that change was authorized in the first place is the job of security monitoring that watches for unexpected change.
Entries are append-only and cannot be edited or deleted from the interface, including by an account owner. A log you can quietly edit is not evidence. That matters most during an incident, when the log is read next to what the malware scan found.
Search by site, client, person, action type or date range. Answer "what happened to this site last Friday" in seconds.
CSV or JSON export for compliance requests, disputes or your own analysis. Exposure windows from vulnerability monitoring come out the same way, which is what a client asking how long they were at risk actually wants.
The monthly client report is generated from the log, which is why it is accurate rather than remembered.
Retention is configurable per plan, with long-horizon retention available where a client contract or regulator requires it.
What people ask before they turn this on.
No. Entries are append-only and cannot be modified or deleted from the interface by anyone, including the account owner. That is what makes it usable as evidence.
Yes, for the significant ones: plugin and theme activation, deactivation, updates, user role changes and core updates. The log reflects the state of the site, not only actions taken through WPCentrify.
Twelve months by default, configurable to longer horizons where a client contract or regulatory obligation requires it.
Use an activity log. WordPress keeps revisions of posts but no record of who installed a plugin, changed a user's role or edited a setting. WPCentrify records those changes on every connected site, with the person and the time, and shows them in one timeline you can filter by website, person or date.
No. WordPress saves revisions of posts and pages with the author of each one, but it does not record sign-ins, plugin and theme changes, user changes or settings changes. You need an activity log plugin on each site, or a platform such as WPCentrify that records them for every site you manage.
Not with WPCentrify. The WPCentrify connector plugin that each site already runs to be managed records the activity, so there is no separate activity log plugin to install, update and keep compatible on each site.
Yes. WPCentrify shows a timeline for each website and one for your whole workspace, so you can see everything that happened across every site on a given day, or everything one person did, from one screen.
Not noticeably. The WPCentrify connector saves the events of a request in a single database write at the end of that request and sends them to WPCentrify in the background, so pages do not wait for the log.
Connect a site in under two minutes and see this working against something real. Free during early access.
Free during early access. Keep your data, export any time.