source on Google
Quick Summary
- A WordPress activity log records every login, content change, plugin event, and settings update on your site.
- WordPress has no built-in activity log. You need a dedicated plugin.
- AuditPulse is the only free plugin that includes email alerts, Slack notifications, and IP blocking at no cost.
- Setup takes under 60 seconds with no configuration required.
- Logging starts from the moment you activate the plugin. Past events cannot be recovered.
Table of Contents
- What Is a WordPress Activity Log?
- Why You Need a WordPress Activity Log on Every Site
- Who Changed My WordPress Site? How to Find Out
- The Best Free WordPress Activity Log Plugin in 2026
- How to Set Up WordPress Activity Logging with AuditPulse
- How to Track User Activity in WordPress
- WordPress Login Tracking and Failed Login Monitoring
- WordPress Activity Log: Free vs Paid Plugins Compared
- What Events Should a WordPress Activity Log Record?
- Frequently Asked Questions

You log into your WordPress admin one morning and something is different. A page has been edited. A plugin was deactivated. A user account was created that you do not recognise. You have no idea who did it, when it happened, or why.
This is exactly the situation a WordPress activity log prevents. With the right free WordPress activity log plugin installed, every single change on your site is recorded with the user’s name, IP address, and timestamp so you always know what happened and who did it.
This guide covers everything: what a WordPress audit log is, what events it should record, how to set one up for free, and how to track every user on your site without spending a penny.
What Is a WordPress Activity Log?
A WordPress activity log (also called a WordPress audit log or WordPress event log) is a running record of everything that happens inside your WordPress admin dashboard. Every time a user logs in, edits a post, installs a plugin, changes a setting, or modifies a user account, the action is recorded with a full timestamp and the IP address it came from.
Think of it as CCTV for your WordPress backend. You may never need it, but the day something goes wrong, you will be glad it was running.
A proper WordPress admin activity log records:
- Every user login and logout, including failed attempts
- All post and page edits, including who made the change and when
- Plugin installs, updates, activations, and deactivations
- Theme switches and customiser changes
- Settings changes including permalink structure, general settings, and reading options
- User account creation, deletion, and role changes
- WooCommerce order and product events
- The IP address on every single event
Why You Need a WordPress Activity Log on Every Site
Most WordPress site owners install a WordPress activity log plugin after something goes wrong. Do not make that mistake. Here is why you need one running before anything breaks:
1. You Have Multiple Users or an Agency Managing Your Site
If anyone other than you has access to your WordPress admin, a WordPress user activity tracking plugin is essential. When there are editors, admins, or a web agency involved, you need a clear record of who changed what. Without WordPress admin monitoring, you are trusting everyone blindly.
2. Something Breaks and You Do Not Know Why
A plugin conflict, a broken layout, a missing page. These things happen. With a WordPress change log running, you can go back and see exactly which plugin was installed or which setting was changed at the time the problem started. Without one, you are guessing.
3. You Need to Spot Suspicious Activity Early
Brute force attacks on WordPress are extremely common. According to Wordfence threat intelligence reports, millions of login attempts are blocked across WordPress sites every day. WordPress failed login monitoring lets you see when someone is repeatedly trying to break into your admin, which IP they are coming from, and which username they are targeting. This is the first step in locking them out before they get in.
4. Compliance and Client Accountability
If you manage sites for clients, a WordPress audit log protects you. When a client asks why something changed or claims work was done that was not, the log is your proof. It is also increasingly required for GDPR compliance and security audits.
Who Changed My WordPress Site? How to Find Out
This is one of the most searched questions among WordPress site owners: who changed my WordPress site and how do I find out?
WordPress itself does not keep a full activity log. The built-in revisions system saves snapshots of posts and pages, but it does not record logins, plugin changes, settings edits, or user modifications. If you want to know who changed your WordPress site, you need a dedicated WordPress activity log plugin.
Once a plugin is active, every action is stamped with:
- The username who performed the action
- The date and time it happened
- The IP address the action came from
- A full description of what changed
The key point: activity logging only starts from the moment you install the plugin. Past events cannot be recovered. This is why you should install a WordPress user activity log today, not after something has already gone wrong.
The Best Free WordPress Activity Log Plugin in 2026
There are several free WordPress activity log plugins available, but most of them charge for the features that actually matter: alerts, IP tracking, and health monitoring. AuditPulse is the exception.
AuditPulse is a free WordPress activity log plugin built by CrestVox Studio and available on WordPress.org. It includes every feature that competing plugins put behind a paywall, at no cost and with no licence key required.
What AuditPulse Logs for Free
AuditPulse records all of the following out of the box, with zero configuration needed:
- User logins and logouts with IP address and timestamp
- Failed login attempts with the IP address of the attacker
- Post and page changes: created, updated, trashed, restored
- Plugin events: installed, activated, deactivated, deleted, updated
- Theme changes: switched, customised, updated
- WordPress settings changes: general, reading, permalink, discussion
- User account events: created, updated, deleted, role changed
- WooCommerce events: order status changes, products created and edited
- IP address on every event, including content edits and settings changes
Free Features Competitors Charge For
This is what makes AuditPulse different from every other free WordPress activity log plugin:
- Email alert rules: get notified instantly when a specific event happens, such as a failed login or a plugin being deactivated. WP Activity Log charges $99 per year for this. AuditPulse includes it free.
- Slack webhook notifications: send alerts directly to a Slack channel the moment something happens on your site. No other free plugin offers this.
- IP whitelist and blocklist: allow or block specific IP addresses. Essential for locking out known bad actors.
- Site health dashboard: a real-time overview of your site’s security and activity status.
- Export logs to CSV: download your full activity log as a spreadsheet for external review or compliance reporting.
- Adjustable log retention: choose how long logs are kept. Default is 90 days.
- Disable individual event types: turn off logging for categories you do not need to reduce database overhead.
How to Set Up WordPress Activity Logging with AuditPulse
Setting up WordPress activity tracking with AuditPulse takes under 60 seconds. There is no API key, no account creation, and no configuration wizard.
Step 1: Install AuditPulse from WordPress.org
- Log in to your WordPress admin dashboard.
- Go to Plugins > Add New Plugin. You can also download it directly from the AuditPulse page on WordPress.org.
- Search for AuditPulse.
- Click Install Now, then Activate.
WordPress activity logging starts immediately from the moment you activate the plugin. No setup required.
Step 2: Open the Activity Log
Go to AuditPulse > Activity Log in your WordPress admin sidebar. You will see a full table of every event recorded since activation, showing the event type, description, username, IP address, and timestamp. You can filter by event type, user, or date range, and search across all columns.
Step 3: Set Up Alert Rules (Optional but Recommended)
Go to AuditPulse > Alert Rules and create your first rule. The most important one to set up first is failed login alerts: get notified by email or Slack the moment someone fails to log in to your WordPress admin. This is your early warning system for brute force attacks.
Step 4: Review the IP Rules and Health Dashboard
Check the Site Health dashboard for a quick overview of your site’s security status. If you see a suspicious IP in your activity log, add it to your IP blocklist directly from the AuditPulse interface.
How to Track User Activity in WordPress
If you want to track user activity in WordPress specifically, AuditPulse gives you a full picture of what every logged-in user is doing on your site.
For each user, the WordPress user activity log shows:
- When they logged in and from which IP address
- Every post, page, or custom post type they edited
- Any plugins they installed, activated, or deactivated
- Any settings they changed in the WordPress admin
- Any user accounts they created or modified
You can filter the activity log by username to see a complete history of a specific user’s actions. This is useful when managing a team of editors, reviewing a contractor’s work, or investigating a security incident.
WordPress Login Tracking and Failed Login Monitoring
WordPress login tracking is one of the most important security features you can add to your site. Every login attempt, whether successful or failed, is recorded with the username used, the IP address, and the exact time.
WordPress failed login monitoring specifically lets you spot brute force attacks before they succeed. A brute force attack is when a bot or a person tries hundreds or thousands of username and password combinations in rapid succession. Without a log, you would never know this was happening. With AuditPulse running, you see every failed attempt with its IP address and can add that IP to your blocklist immediately.
Recommended alert rule to create on day one: send me an email if there are more than 3 failed login attempts from the same IP within 10 minutes.
WordPress Activity Log: Free vs Paid Plugins Compared
Here is how AuditPulse compares to the most popular WordPress activity log plugins on their free tiers. For a broader overview of all available options, WPBeginner has a detailed plugin comparison worth reading alongside this guide:
| Feature | AuditPulse (Free) | WP Activity Log (Free) | Simple History (Free) | Activity Log (Free) |
|---|---|---|---|---|
| IP address on every event | Yes | Partial | No | No |
| Email alert rules | Yes | Paid only ($99/yr) | No | No |
| Slack notifications | Yes | No | No | No |
| IP blocklist | Yes | No | No | No |
| Site health dashboard | Yes | No | No | No |
| Export to CSV | Yes | No | Yes | No |
| WooCommerce logging | Yes | Yes | No | No |
| Data stays on your server | Yes | No (cloud sync) | Yes | Yes |
| Licence key required | No | No | No | No |
| Cost for alerts | Free | $99/year | Not available | Not available |
What Events Should a WordPress Activity Log Record?
A good WordPress site activity log should cover at minimum these eight categories of events:
- Authentication events: logins, logouts, failed logins, and session expiry
- Content changes: posts, pages, and custom post type edits including status changes
- Plugin events: installs, activations, deactivations, deletions, and updates
- Theme events: theme switches, customiser changes, and updates
- User account changes: new accounts, role changes, profile edits, password resets
- WordPress settings changes: anything in Settings in the WordPress admin
- WooCommerce events: orders, products, and store settings if applicable
- Security events: IP addresses flagged, blocklist hits, and repeated failed logins
AuditPulse covers all eight categories in the free version with no configuration needed.
Frequently Asked Questions
Does WordPress have a built-in activity log?
No. WordPress does not have a native WordPress activity log. The built-in revisions system saves versions of posts and pages, but it does not record logins, plugin events, settings changes, or user account activity. You need a WordPress activity log plugin for full tracking.
Is there a completely free WordPress activity log plugin?
Yes. AuditPulse is a completely free WordPress activity log plugin with no paid tier, no licence key, and no features locked behind an upgrade. It includes email alerts, Slack notifications, IP rules, and a site health dashboard all for free.
How do I find out who changed something on my WordPress site?
Install a WordPress activity log plugin such as AuditPulse. Go to the Activity Log screen in your WordPress admin and filter by date, user, or event type. Every change shows the username, IP address, and exact timestamp. If the plugin was not installed at the time the change was made, that event will not be recoverable.
Can I track specific users in WordPress?
Yes. With WordPress user activity tracking enabled, you can filter the activity log by any specific user and see a complete chronological list of every action they took on your site.
How do I get alerts when someone logs into my WordPress admin?
In AuditPulse, go to Alert Rules and create a new rule for the User Login event. Set up your email address or Slack webhook and save. You will receive a notification every time someone logs into your WordPress admin.
Does the activity log slow down my WordPress site?
A well-built WordPress activity log plugin adds minimal overhead. AuditPulse stores logs in a dedicated database table and uses efficient queries. The impact on site speed is negligible for most WordPress sites.
How long are activity logs kept?
AuditPulse keeps logs for 90 days by default. You can adjust this in the settings to keep logs for longer or shorter depending on your storage and compliance needs.
Start Tracking Your WordPress Site for Free Today
A WordPress activity log is not a tool for paranoid site owners. It is basic operational awareness. If you have more than one person with access to your WordPress admin, or if your site is running any business-critical function, you need to know what is happening on it.
AuditPulse gives you complete WordPress activity tracking for free: logins, content changes, plugin events, settings changes, WooCommerce activity, email alerts, Slack notifications, IP rules, and a health dashboard. No paid plan, no account, no licence key. Install and logging starts in under 60 seconds.
Download AuditPulse free from WordPress.org and start monitoring your site today.
Related Articles
- WordPress Development Services
- WordPress Maintenance Service India
- How to Hire a WordPress Developer India
CrestVox Studio helps Indian and UK businesses build fast, conversion-ready WordPress and Shopify websites. Get a Free Consultation to discuss your project.