Activity Log – Monitor & Record User Changes
by Elementor · Security
Also makes 13 other plugins · 12.3M+ installs across the portfolio →
Monitor every change on your WordPress site — who did what, when, and where it came from — for a complete audit trail and stronger security.
86 health vs 64 average across 997 Security plugins
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Excellent listing optimization
Well tuned across the board
Daily downloads
Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
214.3K
now · peak 312.7K
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Rating trend
Star average over time · dips mark rough releases
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
Release cadence
Occasionally updatedHow often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.
1
releases in the last 12 months
3mo ago
latest release · v2.11.2
77
tagged releases on record
Recent releases
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “200K+”. Our estimate pins where the real number sits.
Refined from the date this plugin crossed into its current band.
Install history · since 2015-03-10 · 1,491 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. The recent download trend is too spiky to read.
Details
Recent reviews
All reviews on wp.org ↗- ★★★★★ taki041.8y ago
woring and easy to use thank
Read on wp.org ↗ - ★★★★★ Abdullah Al Nadim2.6y ago
Love it_ Very Easy To Use
Read on wp.org ↗ - ★★★★★ matteo raggi2.7y ago
It is easy and I use it for 2 webitess for now and completely free, thanks!
Read on wp.org ↗ - ★★★★★ Bjarne Oldrup2.9y ago
Being able to see what preceded an error on a website is so immensely helpful that you cannot imagine it before you actually try it. Especially when working with clients. So many times have we been able to identify the cause of an issue, as we could see that “Oh, this person edited that page last Monday” or “Aha, function x stopped working after updating plugin y”. It’s also valuable to check if someone else is working on a website, before making major changes, not disturbing each of the others work. Activity Log is installed on all my websites, and has been for years. It fills a gap that, weirdly enough, is present in a CMS that encourages multiple users and roles. Highly recommended. Five stars easily ⭐⭐⭐⭐⭐
Read on wp.org ↗ - ★★★★★ nicolasvsedeco3.2y ago
Greate user logs to go back in time to see who have done something wrong. In my opinion, this is a must plugin
Read on wp.org ↗ - ★★★★★ stapolin3.3y ago
I have installed this plugin on all my clients websites which helps me keep track of who did what making troubleshooting any issues quick and simple when something goes wrong. I could have created a similar plugin myself, but what’s the point when the authors of Activity Log have already done such a great job? So, instead, I coded a script to send the info from this plugin to a central database where I can keep an eye on all client sites in one place, which is definitely easier than checking each one individually. The only thing that is kind of annoying about this plugin is the Elementor ad a the top of the admin back-end. I am a big fan of Elementor for certain types of sites and use it on many sites, but I don’t need or want my clients to see these ads because it looks very unprofessional. I certainly don’t mind having ads there if they support the authors in keeping plugins updated, but it can be quite annoying when they are, as the phrase goes, “in your face”.
Read on wp.org ↗ - ★★★★★ Clicknathan3.8y ago
WP Plugin guidelines state that plugins should not create a top level navigation element in /wp-admin if it’s not necessary. That and the ad for Elementor made for an instant uninstall for me.
Read on wp.org ↗ - ★★★★★ Brendan4.1y ago
A really simple activity log, easy to use. The UI is intuitive and search feature is nice. There aren’t a lot of options or feature but it does what I need it to, and it’s free.
Read on wp.org ↗
Latest updates
via wp.org changelogRecent releases and news for this plugin
- 2026-08-24 Version 2.13.0 Removed: Email notifications feature (hidden since 2.5 for sites that never enabled it) has been fully removed 2.13.0
- 2026-08-20 Version 2.12.1 Tweak: Removed text domain loading method in favor of WordPress standard loading Fix: Re-release for WordPress.org after a failed deploy 2.12.1
- 2026-08-19 Version 2.12.0 New: Request Source Tracking – See where each change came from (REST API, WP-CLI, WP-Cron, XML-RPC, WP Abilities, Application Passwords) New: Added metadata storage for extensible log context Tweak: Large activity log ta 2.12.0
- 2024-11-12 Version 2.11.2 Security Fix: Improved code security enforcement in theme/plugin file editor 2.11.2
- 2024-11-05 Version 2.11.1 Tweak: Added ability to search in context column 2.11.1
- 2024-07-29 Version 2.11.0 New: Added logging for enabling and disabling automatic theme updates New: Added logging for enabling and disabling automatic plugin updates New: Added logging for enabling and disabling automatic core updates 2.11.0
Known vulnerabilities
via Wordfence Intelligence9 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.
- 2024-11-20 CVE-2024-10788 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.11.1 Patched in 2.11.2
- Medium · 5.3 Activity Log <= 2.8.7 - IP Address Spoofing ↗
- High · 8.3 Activity Log <= 2.8.3 - CSV Injection ↗2022-09-26 CVE-2022-27858 Improper Neutralization of Formula Elements in a CSV File Affects <= 2.8.3 Patched in 2.8.4
- High · 8.8 Activity Log 2.3.5 - 2.6.1 - SQL Injection ↗2021-05-03 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects 2.3.5 - 2.6.1 Patched in 2.7.0
- 2018-03-08 CVE-2018-8729 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.4.0 Patched in 2.4.1
- 2016-08-03 CVE-2016-10890 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.3.2 Patched in 2.3.3
- Medium · 6.1 Activity Log < 2.3.3 - Cross-Site Scripting ↗2016-08-03 CVE-2016-10891 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.3.3 Patched in 2.3.3
- 2016-07-29 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.3.3 Patched in 2.3.3
- 2014-02-27 Exposure of Sensitive Information to an Unauthorized Actor Affects < 2.0.4 Patched in 2.0.4
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 8.1.12 · WP 6.6.2
Languages
via translate.wordpress.orgTranslated into 90 languages, 16 at 90% or more
Plus 66 more locales with partial translations.
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
- 2025-07-26 300K+ → 200K+ down after 162 days in tier
- 2025-02-14 200K+ → 300K+ up after 76 days in tier
- 2024-11-30 300K+ → 200K+ down after 18 days in tier
- 2024-11-12 200K+ → 300K+ up
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
-
Stream – Activity Log & Audit Trail 80K+ installs · 4.2★ · 3 shared tags A
-
WP Admin Audit 1K+ installs · 3.8★ · 3 shared tags B -
Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File Scanning 30K+ installs · 4.8★ · 2 shared tags A -
Wordfence Security – Firewall, Malware Scan, and Login Security 5M+ installs · 4.7★ · 1 shared tag A
-
Hostinger Tools 3M+ installs · 3.6★ · 1 shared tag B
-
Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) 3M+ installs · 4.9★ · 1 shared tag A
Embed this report card
Drop a live Pulse card for Activity Log – Monitor & Record User Changes into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/aryo-activity-log" width="480" height="300" style="border:0" loading="lazy" title="Activity Log – Monitor & Record User Changes — Plugin Pulse"></iframe> Activity Log – Monitor & Record User Changes: 200K+ active installs, 4.3★ (74 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/aryo-activity-log