Activity Log
Record who did what, when and from where, and get notified right away of takeover signs such as a new administrator or a changed site URL
A record of who did what, and when
"Sorabun > Measure / Analyze > Activity Log" records important actions taken on your site (Pro). It helps you trace when a takeover started and what was done, and notices signs of a takeover as they happen.
Records are kept for 90 days. Connection addresses (IP addresses) are stored with the last part masked.
What gets recorded
| Category | What's recorded |
|---|---|
| Logins | Logins, failed logins (with the name that was tried), logouts, password resets, two-factor authentication turned on/off/removed |
| Users | Users created or deleted, role changes, password changes, email address changes |
| Plugins, themes, core | Plugins activated, deactivated, deleted, installed or updated; themes installed, updated or switched; WordPress updates |
| Settings | Site URL, administrator email address, "anyone can register", default role for new users, Sorabun security settings |
| Deleted content | Posts and pages moved to the trash or permanently deleted |
Choose a category at the top to filter. You can also search by username or target name. Actions worth a closer look (failed logins, user creation, role changes, etc.) are shown in a different color.
Instant notifications
These actions are common in takeovers, so you're notified the moment they happen (if no notification channel is set up, it goes to the administrator email address).
- A new administrator appears (created as an administrator, or promoted to administrator)
- The site URL or administrator email address is changed
- "Anyone can register" is turned on, or the default role for new users is set to administrator
Change your password right away and check the surrounding actions on this screen. Delete any administrator you don't recognize, then press "Check now" and "Scan files" in "Security / Speed" to make sure nothing else was changed.