
ActivityLog – wordpress logging for actions inside admin Security & Risk Analysis
wordpress.org/plugins/activitylogA WordPress plugin that logs user logins, logouts, post/page creation/updates/deletion, and plugin activation/deactivation/deletion events.
Is ActivityLog – wordpress logging for actions inside admin Safe to Use in 2026?
Generally Safe
Score 92/100ActivityLog – wordpress logging for actions inside admin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'activitylog' v1.1 exhibits a generally strong security posture based on the provided static analysis. The absence of any detected entry points such as AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the potential attack surface. Furthermore, the code signals indicate good development practices, with no dangerous functions identified, all SQL queries utilizing prepared statements, and a reasonable percentage of output escaping. The presence of nonce and capability checks, although limited in number, is a positive sign. The vulnerability history being completely clear of known CVEs is a significant strength, suggesting a history of secure development or prompt patching of any past issues. However, the zero taint flows analyzed means this aspect of security couldn't be thoroughly vetted. While the current analysis presents a positive outlook, the limited scope of taint analysis and the relatively low number of capability and nonce checks are minor areas for potential improvement to further solidify its security. Overall, the plugin appears to be developed with security in mind, but continuous vigilance and more comprehensive dynamic analysis would be beneficial.
Key Concerns
- Untrusted input not analyzed via taint analysis
- Low number of capability checks
- Low number of nonce checks
- Moderate output escaping (74%)
ActivityLog – wordpress logging for actions inside admin Security Vulnerabilities
ActivityLog – wordpress logging for actions inside admin Release Timeline
ActivityLog – wordpress logging for actions inside admin Code Analysis
Output Escaping
ActivityLog – wordpress logging for actions inside admin Attack Surface
WordPress Hooks 10
Maintenance & Trust
ActivityLog – wordpress logging for actions inside admin Maintenance & Trust
Maintenance Signals
Community Trust
ActivityLog – wordpress logging for actions inside admin Alternatives
WP Activity Log
wp-security-audit-log
The #1 user-rated activity log plugin for event logging, activity monitoring and change tracking.
Unbranded Portal Connector
unbranded-portal-connector
Log all of your user activity and report directly into your Unbranded Portal, without bloating your database.
Simple History – Track, Log, and Audit WordPress Changes
simple-history
Track changes and user activities on your WordPress site. See who created a page, uploaded an attachment, and more, for a complete audit trail.
Stream – Activity Log & Audit Trail
stream
Real-time activity log and audit log for WordPress. Track every user action — logins, edits, plugin & settings changes — and get alerts.
Adminify Activity Log & Audit Trail
adminify-activity-logs
Track every change in your WordPress dashboard. Free user activity log with role, time, component, and action filters. No setup, no paid tier.
ActivityLog – wordpress logging for actions inside admin Developer Profile
5 plugins · 3K total installs
How We Detect ActivityLog – wordpress logging for actions inside admin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wrapname="alpl_log_retention_days"name="activitylog"name="filter"