{"id":280125,"date":"2026-03-10T00:39:18","date_gmt":"2026-03-10T00:39:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/activity-log-tracker-security-audit\/"},"modified":"2026-09-08T18:59:57","modified_gmt":"2026-09-08T18:59:57","slug":"blogcutter-activity-log-security-audit","status":"publish","type":"plugin","link":"https:\/\/fr.wordpress.org\/plugins\/blogcutter-activity-log-security-audit\/","author":23447953,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"6.0.0","stable_tag":"trunk","tested":"7.1.1","requires":"6.0","requires_php":"7.4","requires_plugins":null,"header_name":"BlogCutter Activity Log & Security Audit","header_author":"Blog Cutter AI Team","header_description":"Total website audit. Tracks every change by admins, authors, and users. Includes custom log rotation, session monitoring, 404 tracking, and modern dashboard.","assets_banners_color":"212d37","last_updated":"2026-09-08 18:59:57","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/blogcutter.com\/wp-activity-log-security-audit-plugin","header_author_uri":"https:\/\/blogcutter.com","rating":5,"author_block_rating":0,"active_installs":10,"downloads":755,"num_ratings":3,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":[],"upgrade_notice":{"6.0.0":"<p>Major update for WordPress 7.1. Logs move to a database table. WordPress 6.0+ is required. Review settings after updating.<\/p>"},"ratings":{"1":0,"2":0,"3":0,"4":0,"5":3},"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3478654,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3478654,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3478654,"resolution":"1544x500","location":"assets","locale":"","width":1554,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3478654,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":[],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3479529,"resolution":"1","location":"assets","locale":"","width":1135,"height":602},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3479529,"resolution":"2","location":"assets","locale":"","width":1151,"height":560},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3479529,"resolution":"3","location":"assets","locale":"","width":1144,"height":557},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3479529,"resolution":"4","location":"assets","locale":"","width":1146,"height":601},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3479542,"resolution":"5","location":"assets","locale":"","width":1157,"height":605}},"screenshots":{"1":"Dashboard with stats, time filters, type chips, and the activity table","2":"Active sessions with last activity and end-session action","3":"Security overview with failed logins grouped by IP","4":"Settings grouped by storage, security, content, and traffic","5":"Help page with storage and WordPress 7.1 notes"}},"plugin_section":[],"plugin_tags":[8531,8533,602,5603,600],"plugin_category":[54],"plugin_contributors":[257396],"plugin_business_model":[],"class_list":["post-280125","plugin","type-plugin","status-publish","hentry","plugin_tags-activity-log","plugin_tags-audit","plugin_tags-login","plugin_tags-monitoring","plugin_tags-security","plugin_category-security-and-spam-protection","plugin_contributors-blgctterai","plugin_committers-blgctterai"],"banners":{"banner":"https:\/\/ps.w.org\/blogcutter-activity-log-security-audit\/assets\/banner-772x250.png?rev=3478654","banner_2x":"https:\/\/ps.w.org\/blogcutter-activity-log-security-audit\/assets\/banner-1544x500.png?rev=3478654","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/blogcutter-activity-log-security-audit\/assets\/icon-128x128.png?rev=3478654","icon_2x":"https:\/\/ps.w.org\/blogcutter-activity-log-security-audit\/assets\/icon-256x256.png?rev=3478654","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/blogcutter-activity-log-security-audit\/assets\/screenshot-1.png?rev=3479529","caption":"Dashboard with stats, time filters, type chips, and the activity table"},{"src":"https:\/\/ps.w.org\/blogcutter-activity-log-security-audit\/assets\/screenshot-2.png?rev=3479529","caption":"Active sessions with last activity and end-session action"},{"src":"https:\/\/ps.w.org\/blogcutter-activity-log-security-audit\/assets\/screenshot-3.png?rev=3479529","caption":"Security overview with failed logins grouped by IP"},{"src":"https:\/\/ps.w.org\/blogcutter-activity-log-security-audit\/assets\/screenshot-4.png?rev=3479529","caption":"Settings grouped by storage, security, content, and traffic"},{"src":"https:\/\/ps.w.org\/blogcutter-activity-log-security-audit\/assets\/screenshot-5.png?rev=3479542","caption":"Help page with storage and WordPress 7.1 notes"}],"raw_content":"<!--section=description-->\n<p>BlogCutter Activity Log &amp; Security Audit records important actions on your WordPress site and shows them in a searchable admin dashboard. Logs stay on your site. They are not sent to BlogCutter or any other remote service.<\/p>\n\n<p>The plugin is tested with WordPress 7.1. It does not add scripts to the block editor canvas, so the iframed post editor in 7.1 does not affect logging.<\/p>\n\n<h4>What it records<\/h4>\n\n<ul>\n<li>Successful logins, logouts, and failed sign-in attempts<\/li>\n<li>Password reset requests and completions<\/li>\n<li>User account, profile, and role changes<\/li>\n<li>Application password create and revoke events<\/li>\n<li>Posts, pages, media, comments, menus, widgets, and taxonomy terms<\/li>\n<li>Plugin, theme, and WordPress core updates<\/li>\n<li>Important core setting changes (not every options-table write)<\/li>\n<li>404 errors and public search queries<\/li>\n<li>Optional guest visits (off by default, one log per IP and URL each hour)<\/li>\n<li>Optional outgoing email and REST write requests<\/li>\n<\/ul>\n\n<h4>Dashboard<\/h4>\n\n<ul>\n<li>Filter by time range and event type<\/li>\n<li>Search by user, IP, or message<\/li>\n<li>Color-coded event types<\/li>\n<li>CSV and JSON export of the current filters<\/li>\n<li>Active sessions list with the option to end another user's sessions<\/li>\n<li>Failed-login summary by IP<\/li>\n<li>Daily cleanup by age and maximum row count<\/li>\n<li>WordPress privacy exporter and eraser support<\/li>\n<li>Optional email when one IP fails login too many times in an hour<\/li>\n<\/ul>\n\n<p>On WordPress 6.9 and 7.1 the plugin also registers read-only Abilities for an audit summary and recent log rows. Those abilities are not exposed on the REST API.<\/p>\n\n<h4>Privacy<\/h4>\n\n<p>All log data is stored in a database table on your WordPress site. Administrators can export or delete it. Suggested privacy-policy text is added under Settings \u2192 Privacy. Guest visit logging is optional and off by default.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin folder to <code>\/wp-content\/plugins\/<\/code>.<\/li>\n<li>Activate <strong>BlogCutter Activity Log &amp; Security Audit<\/strong>.<\/li>\n<li>Open <strong>Activity Log<\/strong> in the admin menu.<\/li>\n<li>Review <strong>Activity Log \u2192 Settings<\/strong>.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20this%20work%20with%20wordpress%207.1%3F\"><h3>Does this work with WordPress 7.1?<\/h3><\/dt>\n<dd><p>Yes. Version 6.0.0 is tested up to WordPress 7.1. Logging runs in PHP on standard WordPress hooks and does not depend on the block editor iframe.<\/p><\/dd>\n<dt id=\"does%20it%20slow%20the%20site%20down%3F\"><h3>Does it slow the site down?<\/h3><\/dt>\n<dd><p>Logging is limited to events you enable. Guest page-visit logging is off by default. When it is on, the same IP and URL are recorded at most once per hour. Known bots can be ignored.<\/p><\/dd>\n<dt id=\"where%20are%20logs%20stored%3F\"><h3>Where are logs stored?<\/h3><\/dt>\n<dd><p>In the <code>wp_bcal_logs<\/code> database table (with your site prefix). Older file-based logs from version 5 are imported once after you update.<\/p><\/dd>\n<dt id=\"can%20i%20export%20logs%3F\"><h3>Can I export logs?<\/h3><\/dt>\n<dd><p>Yes. Export CSV or JSON from the dashboard. Exports follow the filters you have selected.<\/p><\/dd>\n<dt id=\"can%20i%20stop%20logging%20guest%20visits%3F\"><h3>Can I stop logging guest visits?<\/h3><\/dt>\n<dd><p>Yes. Guest visits are off by default. 404 and search logging can be turned off separately.<\/p><\/dd>\n<dt id=\"does%20this%20block%20brute-force%20attacks%3F\"><h3>Does this block brute-force attacks?<\/h3><\/dt>\n<dd><p>No. It records failed logins and can email the site admin after repeated failures from one IP. It does not block IPs or replace a firewall.<\/p><\/dd>\n<dt id=\"is%20the%20data%20sent%20off-site%3F\"><h3>Is the data sent off-site?<\/h3><\/dt>\n<dd><p>No. Logs stay in your WordPress database.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>6.0.0<\/h4>\n\n<ul>\n<li>Tested with WordPress 7.1<\/li>\n<li>Store events in a database table instead of a growing log file<\/li>\n<li>Import existing 5.x vault file entries on upgrade<\/li>\n<li>Add time-range and event-type filters<\/li>\n<li>Add JSON export and filter-aware CSV export<\/li>\n<li>Add logout, password reset, media, user, and application-password tracking<\/li>\n<li>Add optional failed-login email alerts<\/li>\n<li>Add session sign-out for other users<\/li>\n<li>Add daily retention by days and maximum rows<\/li>\n<li>Add WordPress privacy exporter, eraser, and policy text<\/li>\n<li>Register read-only Abilities on WordPress 6.9+<\/li>\n<li>Rebuild the admin UI to match WordPress admin patterns<\/li>\n<li>Turn guest visit logging off by default and debounce it<\/li>\n<li>Log only important core settings instead of every option update<\/li>\n<li>Require WordPress 6.0 or newer<\/li>\n<\/ul>\n\n<h4>5.1.0<\/h4>\n\n<ul>\n<li>Search, pagination, and dashboard styling updates<\/li>\n<\/ul>\n\n<h4>5.0.1<\/h4>\n\n<ul>\n<li>Search bar and pagination improvements<\/li>\n<\/ul>\n\n<h4>5.0.0<\/h4>\n\n<ul>\n<li>Session list, 404 monitoring, comments, roles, and security view<\/li>\n<\/ul>\n\n<h4>4.5.0<\/h4>\n\n<ul>\n<li>Filesystem and escaping improvements<\/li>\n<\/ul>","raw_excerpt":"Activity log and security audit for WordPress. Track logins, content changes, and admin actions from a clear dashboard.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/fr.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/280125","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fr.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/fr.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/fr.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=280125"}],"author":[{"embeddable":true,"href":"https:\/\/fr.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/blgctterai"}],"wp:attachment":[{"href":"https:\/\/fr.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=280125"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/fr.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=280125"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/fr.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=280125"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/fr.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=280125"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/fr.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=280125"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/fr.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=280125"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}