Who Changed It? – Activity Log
Who Changed It? records what happens on your site — logins, plugin and theme changes, user and role changes, content edits, settings changes, file editor use — and, unlike a plain activity log, classifies every event:
- Normal — routine operation.
- Strange — unusual but not necessarily harmful (a failed login, a settings change, a login at 3 AM).
- Dangerous — high-risk activity you should look at now (brute-force login bursts, new administrator accounts, theme/plugin file editor use, open registration being switched on).
Classification is a two-stage process: every event type has a base severity, and contextual heuristics can escalate it — logins at unusual hours, logins from IP addresses never seen for that user, bursts of failed logins from one IP, bursts of deletions by one user. Every escalation is stored with a human-readable reason shown in the log and in alert emails.
Features
- Color-coded activity log screen with severity icons and per-severity count chips, free-text search, filterable by severity, event type, user, and date range
- Field-level change diffs shown inline: see exactly what changed in a post, profile, or setting
- Immediate email alerts for dangerous events, throttled so a brute-force attack sends one email, not hundreds
- CSV export of the filtered log
- Configurable retention: keep everything, or automatically delete events older than a chosen number of days or months
- Mute individual event types to keep the log signal-heavy (events about the plugin itself can never be muted)
- WooCommerce support: prices, coupons, orders, refunds, store and payment gateway settings
- Extensible: log custom events, adjust severities, watch extra options, or forward events to external systems via hooks
What gets audited
Authentication (logins, failed logins, logouts, password resets), users and roles, plugin and theme installs/updates/activations/deletions, WordPress core updates, WordPress 7.0 AI connector and feature changes, theme/plugin file editor use, posts, pages and media (with field-level diffs of what changed), a watched list of sensitive site options, and data exports. On WooCommerce shops: product price changes, coupon amounts, order status changes, refunds, store settings, and payment gateway configuration.