BetterShield

Read the site activity log

5 min read

What the BetterShield activity log records and leaves out, how to filter, search and export it, how long rows are kept, and how daily seals work.

The activity log records who did what on your site, and when. Find it under BetterShield › Activity › Site activity.

What is recorded

  • Signing in: sign-ins, failed sign-ins, sign-outs, password reset requests, lockouts, two-factor and passkey use, and sign-ins from a new network.
  • Accounts: users created, deleted or removed, role changes, changes to what a role may do, email and password changes, and application passwords created, used or revoked.
  • Plugins, themes and WordPress: installs, updates, activations, deactivations and deletions, and core updates.
  • Key site settings: the WordPress and site addresses, the administration email, whether anyone can register, the default role, the permalink structure and search engine visibility.
  • BetterShield’s own work: audits, fixes applied or undone, file checks, alerts sent, safe mode, recovery links, incidents and changes made by an AI assistant.

Edits to posts, pages and other content are not recorded.

A burst of failed sign-ins or reset requests from one source becomes one row that says how many more attempts it stands for. If one kind of routine event passes 500 in an hour, the rest of that hour is counted instead of listed, and a notice above the log says so. Security-relevant events are never counted this way.

IP addresses are stored only as their network: a /24 for IPv4, a /64 for IPv6.

The figures at the top

FigureWhat it shows
EntriesRows kept, or rows matching your filters.
Who appearsHow many people and processes are in the log.
Sealed daysWhat the last daily seal check found: Intact, Changed, None yet or Not checked yet.
Kept forDays a row is kept before it is removed.

Previous values and reversible responses

A collapsed panel for people who manage BetterShield. Tick Record supported previous values and click Save capture preference to keep the earlier value when one of these changes: the default role, public registration, the administration email address, the WordPress address, what a role may do, a plugin being activated, or a new administrator. Off by default. It holds up to 1,000 captures (20 per request, 100 per hour), and these records can include email addresses and outlive the log.

Rows of those kinds show Review change: the value Before the recorded change, After the recorded change and the Current value. Where nothing was captured, it names the screen to check by hand.

  • Put this back (Ultra) sets the earlier value again, or deactivates the plugin. A later edit is never overwritten, and the WordPress address is never put back automatically.
  • Suspend this account (Ultra) stops a new administrator signing in and using credentials, without deleting anything.
  • Undo this response reverses either one while the target is unchanged.

Each needs a working recovery method and safe mode off.

  • Category: All activity, or one area: Access, Exposure, Configuration, Updates & extensions or BetterShield, each with its count.
  • Search activity: matches who did it, what it was done to, the event’s name (so “sign-in” finds failed sign-ins), an account’s login, or an IP address, which finds every row from its network.
  • Filters: Who (Anyone, or one of the listed people and processes) and From and To dates, read in the site’s time zone. Clear filters empties the panel.
  • Clear all, beside the result count, removes every filter and the search.

Each row also offers Everything from this person and Everything from this network. The page address keeps these narrowings and the dates, so a view can be bookmarked.

Reading a row

Rows are grouped by day, newest first. Each shows the time, what happened, a severity chip when it is above routine, who did it (an account, the site itself, a signed-out visitor or an agent), what it was about, via WP-CLI when it came from the command line, the network, and the area. Show older entries loads more.

Export CSV

Export CSV downloads what the current filters show, with times in UTC. One file carries up to 10,000 rows. If more match, the screen says so and the file’s last line says it was cut short: narrow the dates and export again. From the command line, wp bettershield activity --format=csv does the same (WP-CLI commands).

With Ultra, an alert channel set to Every event under Ultra › Alert channels also sends the activity record, in the classes you choose, to Slack, a webhook or a syslog collector.

Daily seals

Once a day, BetterShield seals each finished day (in UTC) with a digest chained to the day before, then checks every sealed day again. Each day heading shows one of:

  • Sealed, chain intact
  • Sealed, and the rows no longer match
  • Open until the day is over
  • Not sealed yet, the next daily check seals it

A sealed day that no longer matches means its rows were edited or removed after the day closed. The audit then opens a high-severity finding, “A sealed day of the activity log no longer matches its seal”. Anyone who can write to the database can also rewrite the seals, so this makes tampering visible, not impossible. To check on demand, run wp bettershield verify_log.

How long rows are kept

Rows are removed after 30 days, or 90 days (Ultra). The note at the foot of the log says which applies. If Ultra is switched off, the log shows 30 days again.

On a multisite network

Network administrators get BetterShield › Activity in the network admin: every site’s activity in one list, each row naming its site, with a Site filter. It has no export and no seals. Use each site’s own log for those, or wp bettershield activity --sites=all. See Multisite networks.

Close the open doors today

Install the free plugin. The first audit runs when you activate it, and nothing changes until you choose a fix.

Requires WordPress 6.7 or newer and PHP 8.0 or newer.

Get BetterShield