Product
Solutions
Compare
Resources
Get early access Talk to us
Activity log

Every change, on every site, with the evidence attached

Who did what, on which site, when, and what happened as a result. Updates, restores, logins, permission changes and policy edits, all recorded automatically and exportable whenever you need them.

Included on every plan. No add-on pricing.

Updated

app.wpcentrify.com/activity
ActivityExample data
Events today
214
across 34 sites
Actors
9
6 team, 3 automated
Retention
12 mo
configurable
Exports
Any period
CSV, JSON
UPYoast SEO 24.0 to 24.1
22 sites, automated, all checks passed
Success09:14Auto
RBElementor 3.31.2 rolled back
harvest-collective.store, visual regression
Rollback03:41Auto
LGJonah T. opened wp-admin
northridge-dental.com, plugins screen
Session09:41Manual
PMPermission changed
Rea C. scoped to 4 sites until 30 Sep
Policy08:02Amara O.

What is a WordPress activity log?

A WordPress activity log is a dated record of what happened on a WordPress site: who signed in, which plugins and themes were installed, updated or switched off, which posts and pages changed and which settings were edited, each with the person and the time. WordPress saves revisions of posts, but it keeps no record of who changed a plugin, a user or a setting, so the log has to come from a plugin or a management platform.

WPCentrify keeps an activity log for every WordPress site you connect and shows them together in one timeline. It records the changes made inside wp-admin on each website and everything done from WPCentrify itself, such as updates, backups, restores and one-click logins, so you can answer "what changed, who did it and when" for one site or for all of them. Our guide to the WordPress audit log covers what to log and for how long.

WPCentrify activity log at a glance

  • One timeline per website and one for your whole workspace, filterable by website, person, area and date.
  • Changes made in wp-admin are recorded as well as changes made from WPCentrify.
  • Each entry names the person, the website, the time and the result.
  • Administrators are always recorded and cannot be excluded.
  • Passwords and other secrets are never written to the log.
  • Any period can be exported as a CSV file.
The problem

The question you cannot answer under pressure

A client calls to say something broke over the weekend. You need to know what changed and when, and the honest answer is usually that nobody wrote it down. WordPress itself keeps almost no history: you can see current plugin versions but not when they changed or who changed them. Our guide to the WordPress audit log sets out exactly what WordPress records on its own and what it misses.

Without a record you are reconstructing events from memory and file timestamps, while a client waits and forms an opinion about your professionalism.

What this looks like without a platform

  • No record of when a plugin was updated or by whom
  • Disputes about whether a change was authorized
  • Reconstructing a weekend incident from file modification dates
  • Reports written from memory rather than from a log
How it works

WordPress activity monitoring: what gets recorded

Everything the platform does

Every update, backup, restore, policy change, permission change and one-click login, with actor and timestamp.

Evidence, not just an entry

An update record includes the risk score it received, the checks that ran, the before and after screenshots, and the result. A restore record includes what was restored and how long it took.

Site changes detected outside WPCentrify

If somebody activates a plugin directly in wp-admin, that appears too, so the log reflects the site rather than only your actions. Deciding whether that change was authorized in the first place is the job of security monitoring that watches for unexpected change.

Tamper-evident

Entries are append-only and cannot be edited or deleted from the interface, including by an account owner. A log you can quietly edit is not evidence. That matters most during an incident, when the log is read next to what the malware scan found.

In practice

Using the record

Filter across the whole portfolio

Search by site, client, person, action type or date range. Answer "what happened to this site last Friday" in seconds.

Export for any period

CSV or JSON export for compliance requests, disputes or your own analysis. Exposure windows from vulnerability monitoring come out the same way, which is what a client asking how long they were at risk actually wants.

Feeds client reports automatically

The monthly client report is generated from the log, which is why it is accurate rather than remembered.

Retention that matches your obligations

Retention is configurable per plan, with long-horizon retention available where a client contract or regulator requires it.

At scale

Built for a portfolio, not a single site

  • Unified timeline across every connected site
  • Filter by site, client, actor, action type or date
  • Change evidence including screenshots attached to update records
  • Append-only and tamper-evident
  • CSV and JSON export
  • Configurable retention windows
Answers

Questions about activity log

What people ask before they turn this on.

No. Entries are append-only and cannot be modified or deleted from the interface by anyone, including the account owner. That is what makes it usable as evidence.

Yes, for the significant ones: plugin and theme activation, deactivation, updates, user role changes and core updates. The log reflects the state of the site, not only actions taken through WPCentrify.

Twelve months by default, configurable to longer horizons where a client contract or regulatory obligation requires it.

Use an activity log. WordPress keeps revisions of posts but no record of who installed a plugin, changed a user's role or edited a setting. WPCentrify records those changes on every connected site, with the person and the time, and shows them in one timeline you can filter by website, person or date.

No. WordPress saves revisions of posts and pages with the author of each one, but it does not record sign-ins, plugin and theme changes, user changes or settings changes. You need an activity log plugin on each site, or a platform such as WPCentrify that records them for every site you manage.

Not with WPCentrify. The WPCentrify connector plugin that each site already runs to be managed records the activity, so there is no separate activity log plugin to install, update and keep compatible on each site.

Yes. WPCentrify shows a timeline for each website and one for your whole workspace, so you can see everything that happened across every site on a given day, or everything one person did, from one screen.

Not noticeably. The WPCentrify connector saves the events of a request in a single database write at the end of that request and sends them to WPCentrify in the background, so pages do not wait for the log.

Early access open

Try activity log on your own sites

Connect a site in under two minutes and see this working against something real. Free during early access.

Free during early access. Keep your data, export any time.