WordPress activity log: what it records and what to look for
A WordPress activity log answers the questions that come up after something changes: who added that administrator, when was that plugin switched on, and did anyone sign in from somewhere new. WordPress keeps no such record on its own.
BetterShield keeps one from the moment it is activated, on your own server. This guide covers what it records and leaves out, how to search it, what its sealed days prove, and the rows worth a second look.
Quick summary
- The log is under BetterShield › Activity › Site activity. It records sign-ins, accounts and roles, plugins, themes and core updates, key site settings, and BetterShield’s own work.
- Edits to posts, pages and other content are not recorded. It is a security log, not an editing history.
- You can filter by area, person and dates, search it, and export it with Export CSV.
- Each finished day is sealed and chained to the day before. A sealed day that changes later opens a High finding.
- Rows are kept for 30 days, or 90 with Ultra.
What the WordPress activity log records
Five kinds of change, each in plain past-tense rows such as “Role changed” or “Plugin activated”:
- Signing in: sign-ins, failed sign-ins, sign-outs, password reset requests, lockouts, two-factor and passkey use, and sign-ins from a new network.
- Accounts: users created, deleted or removed, role changes, changes to what a role may do, email and password changes, and application passwords created, used or revoked.
- Plugins, themes and WordPress: installs, updates, activations, deactivations and deletions, and core updates.
- Key site settings: the WordPress and site addresses, the administration email, whether anyone can register, the default role, the permalink structure and search engine visibility.
- BetterShield’s own work: audits, fixes applied or undone, file checks, alerts sent, safe mode, recovery links, incidents and changes made by an AI assistant.
A few rules keep the log readable and small. A burst of failed sign-ins from one source becomes one row that says how many more attempts it stands for. If one routine kind of event passes 500 in an hour, the rest of that hour is counted rather than listed, and the log says so; security-relevant events are never counted this way. IP addresses are stored only as their network: a /24 for IPv4 and a /64 for IPv6.
How to track user activity in WordPress
Four figures head the screen: Entries, Who appears, Sealed days and Kept for. Below them, rows are grouped by day, newest first.
Each row shows the time, what happened and who did it: an account, the site itself, a signed-out visitor or an agent. A severity chip appears when a row is above routine, from Low to Critical. Rows from the command line say via WP-CLI, and a row that came from a request names its network.
To narrow it down:
- Category picks one area: Access, Exposure, Configuration, Updates & extensions or BetterShield.
- Search activity matches who did it, what it was done to, the event’s name or an account’s login. An IP address finds every row from its network.
- Filters adds Who and From and To dates.
- Every row offers Everything from this person and Everything from this network.
The page address keeps your narrowing, so a view can be bookmarked. Export CSV downloads what the filters show, up to 10,000 rows per file; if more match, the screen says so. From the terminal, wp bettershield activity --format=csv does the same. More in the Activity log guide and WP-CLI commands.
Sealed days: a tamper-evident WordPress audit log
A log is only useful if nobody has tidied it. Once a day, BetterShield seals each finished day, counted in UTC, with a digest chained to the day before it, then checks every sealed day again. Each day’s heading shows one of:
- Sealed, chain intact
- Sealed, and the rows no longer match
- Open until the day is over
- Not sealed yet, the next daily check seals it
The Sealed days figure sums it up as Intact, Changed, None yet or Not checked yet.
A sealed day that no longer matches means rows were edited or removed after the day closed. The audit then opens “A sealed day of the activity log no longer matches its seal”, rated High. wp bettershield verify_log runs the same check on demand and exits non-zero if a day fails.
This makes changes visible, not impossible. BetterShield’s readme says it plainly: the log is tamper-evident, not tamper-proof. Anyone who can write to the database can also rewrite the seals, but they have to redo every later day to hide it, not just delete a row.
What to look for in your WordPress audit log
Most rows are routine. These are the ones worth reading twice.
New power. “User created”, “Role granted” and “Role changed” rows involving a role that can manage settings or users carry a High chip. “What a role may do changed” is usually High too, because changing a role changes every account that holds it.
New keys. “Application password created” on an administrator or editor account is High. An application password signs in without the second factor, so ask who made it and for what.
Account changes close together. An “Email address changed” on an administrator, followed by a “Password reset requested”, is worth a look. When an administrator or editor account’s email, password and an application password all change within an hour, BetterShield adds its own row saying so.
Unexpected sign-ins. “Signed in from a new network”, “Dormant privileged account signed in”, and long runs of “Sign-in failed”.
Code arriving. “Plugin installed” or “Plugin activated” when nobody remembers doing it, and “An update did not match its published copy”.
Settings that move a site. “Site setting changed” on the site address, administration email, registration or default role.
Protections coming off. “Hardening undone”, “Login protection changed”, “Safe mode started” and “Sign-in change made without a recovery check”.
Assistants. Rows by an agent, such as “Agent applied a change on its own”. On WordPress 7.1 or newer, each call an assistant makes is also listed in Agent activity.
Use Everything from this person on any row that surprises you. Seeing the rest of that account’s day usually settles it.
How the log feeds the rest of BetterShield
You do not have to read the log every day for it to be useful:
- Alerts. Events rated High or Critical are emailed as they happen, and the weekly summary counts activity by area. See Email alerts.
- The Overview. Since you last looked shows what changed since your last visit. Unusual for this site notes failed sign-ins, or gaps between scheduled tasks, far outside the site’s own recent pattern, once 14 days of history exist.
- Incidents. A new privileged account or a new PHP file can open an incident, and related rows join it. See Incidents.
- Previews. Preview the change for Disable XML-RPC and Refuse application passwords reads the log to say whether anything has used them recently.
Under Previous values and reversible responses, Record supported previous values (off by default) keeps what a few kinds of change replaced, such as the default role or what a role may do, and holds new administrators for review. Those rows then offer Review change. With Ultra, Put this back and Suspend this account can act on them.
How long the log is kept
Rows are removed after 30 days. With Ultra they are kept for 90, and an alert channel can also receive the activity record for the event classes you choose, in Slack, a webhook or a syslog collector. The note at the foot of the log says which retention applies. If you need a longer record without Ultra, export the CSV on a schedule that suits you.
Common mistakes
- Expecting content history. Post and page edits are not recorded. Use WordPress revisions for those.
- Reading a burst as many people. One summarized row can stand for many attempts from one network. Read the count it shows.
- Treating a broken seal as proof of who. It shows that rows changed after the day closed. Look at the days around it and the accounts active then.
- Waiting too long to export. After 30 days a row is gone. Export first if you need it for a report.
Frequently asked questions
Does the activity log record post and page edits?
No. It records sign-ins, accounts and roles, plugins, themes and core, key settings, and BetterShield’s own work. Content edits are left to WordPress’s own revisions.
Is the WordPress activity log tamper-proof?
No, and it does not claim to be. It is tamper-evident: each finished day is sealed and chained, and a sealed day that changes later opens a high-severity finding.
Can I export the activity log?
Yes. Export CSV downloads what the current filters show, up to 10,000 rows per file, and wp bettershield activity --format=csv does the same from the terminal.
Does it store visitors’ IP addresses?
Only as their network, a /24 for IPv4 and a /64 for IPv6, and searching by an address finds every row from that network. Everything is stored on your own server.
Conclusion
A WordPress activity log earns its place on the day something changes and nobody knows why. BetterShield records the changes that matter for security, seals each day so later edits show, and points you to the rows worth reading through alerts, the Overview and incidents.
BetterShield is free on WordPress.org. The features page shows the log beside the audit, hardening and sign-in protection.