Skip to content
Feature · For WordPress

Audit log, a full timeline of who did what, when.

Every important action on your site is recorded automatically, admin logins, failed login attempts, logouts, plugin and theme activations, and more. If something goes wrong, you’ll have a full timeline of who did what and when, making it easy to spot suspicious activity or roll back unwanted changes.

Availability: included from Basic upwards, via the Premium add-on · Security audit log

GuardianGaze plugin view inside the WordPress admin

The plugin view: findings, severity and next steps inside the WordPress admin

At a glance

Audit Log at a glance

What it does

Authentication events

Successful logins, failed login attempts (with IP), logouts, password resets, 2FA challenges.

How it helps

User & role changes

New user registrations, role promotions or demotions, user deletions, profile edits.

What's next

Plugin & theme actions

Installations, activations, deactivations, deletions, updates, including who triggered each.

Why it exists

The feature nobody buys and everybody needs once

No one has ever chosen a security plugin for its audit log. Then a site is compromised, and every question that matters is a question the log answers: which account was used, when was it first used, what did it change, and is anything else affected.

Without a log, none of those have answers. You are left estimating scope, and both available estimates are bad. Over-estimate and you rebuild a site that did not need rebuilding, at considerable cost. Under-estimate and you clean the visible damage while leaving the account, the plugin or the scheduled task that let it happen, which is why so many sites get reinfected within a week of a successful cleanup.

The log is the difference between responding to an incident and guessing at one.

What it records

Authentication, users, code and configuration

Authentication: successful logins, failed attempts, lockouts, and where they came from. A successful login from an unfamiliar location minutes after a run of failures is a story that tells itself.

User and role changes: accounts created, deleted, or promoted. Privilege escalation is one of the most reliable indicators of compromise, because an attacker with a foothold nearly always wants a durable administrator account that survives a password reset.

Plugin and theme activity: installations, activations, deactivations and updates. Installing a plugin is executing arbitrary code on your server, which makes it the single most consequential action available in the WordPress admin.

Configuration and file events: settings changes and modifications, tying the log to what the file monitor sees so a change has a who as well as a what.

The ordinary use

Most of its value has nothing to do with attacks

On any site with more than one administrator, the log earns its place on ordinary weeks. A plugin was deactivated and the site broke. A setting changed and nobody remembers changing it. A user has a role they should not have. Someone updated something on a Friday.

These are not attacks: they are the normal friction of shared access, and they consume real time when the answer is unavailable. The log converts a conversation into a lookup.

It is also the thing that makes an incident explainable afterwards to people who need an explanation: a client, an insurer, a payment processor asking what happened and what you did about it. An honest reconstruction is much easier to write when it is a record rather than a recollection.

FAQ

Audit Log - common questions

Which plan includes the audit log?

Basic and above, through the Premium add-on.

What does it record?

Logins and failures, lockouts, user and role changes, plugin and theme installs, activations and updates, settings changes, and file events.

Can the log be tampered with by an attacker?

Records are held off your site rather than only in your database, which is what stops an attacker with database access from simply editing their way out of the record.

How long is history kept?

Retention depends on your plan; the dashboard shows what is available for your licence. The practical requirement is that history outlives the gap between compromise and discovery, which is why real-time monitoring and the log belong together.

Is this useful if I am the only admin?

Less so day to day, and just as valuable during an incident. It also answers the question of whether the only admin was really the only person using that account.

Related

Works with

Login Security →

Brute force stops at the door.

Notifications →

Alerts that matter, digests for the rest.

File Integrity →

Byte-level change detection on every file.

See it on your own site

The free scan takes under five minutes and tells you the truth.