[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fCnJ2z3pWFpwaZspjadYKDtbq2EilZvk3DeHKmCuyB08":3,"$f2lA9vBN8pixYba4WT_5dlmVyaYe4MVDPftCOx8g-l9w":373,"$fHiVfAs23856bCEd1Gk7wiOUUcVWOr0vh-lGyEhdXKt0":377},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":13,"last_updated":14,"tested_up_to":15,"requires_at_least":16,"requires_php":17,"tags":18,"homepage":24,"download_link":25,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28,"discovery_status":29,"vulnerabilities":30,"developer":31,"crawl_stats":27,"alternatives":37,"analysis":136,"fingerprints":313},"blogcutter-activity-log-security-audit","BlogCutter Activity Log & Security Audit","5.1.0","Blog Cutter AI","https:\u002F\u002Fprofiles.wordpress.org\u002Fblgctterai\u002F","\u003Cp>\u003Cstrong>BlogCutter Activity Log & Security Audit\u003C\u002Fstrong> provides comprehensive activity monitoring for WordPress site administrators. Track every important action on your website including user logins, content changes, settings modifications, and more.\u003C\u002Fp>\n\u003Cp>This plugin delivers detailed audit logging with an intuitive dashboard interface, helping you maintain security and accountability on your WordPress installation.\u003C\u002Fp>\n\u003Ch3>🛡️ Security & Monitoring Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>User Activity Monitoring\u003C\u002Fstrong> – Track user logins, logouts, and administrative actions\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Session Tracking\u003C\u002Fstrong> – See currently logged-in users, IP addresses, and last activity\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Failed Login Detection\u003C\u002Fstrong> – Monitor unauthorized access attempts with IP logging\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Brute Force Protection\u003C\u002Fstrong> – Track multiple failed login attempts from same IP\u003C\u002Fli>\n\u003Cli>\u003Cstrong>User Role Changes\u003C\u002Fstrong> – Track role promotions and demotions\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Content Auditing\u003C\u002Fstrong> – Log post and page creations, updates, and deletions\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Media Library Tracking\u003C\u002Fstrong> – Monitor file uploads and deletions\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Comment Management\u003C\u002Fstrong> – Track new comments, status changes, and deletions\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Taxonomy Tracking\u003C\u002Fstrong> – Monitor categories, tags, and custom taxonomy changes\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Widget & Menu Updates\u003C\u002Fstrong> – Track modifications to widgets and navigation menus\u003C\u002Fli>\n\u003Cli>\u003Cstrong>404 Error Monitoring\u003C\u002Fstrong> – Identify broken links and potential security scans\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Search Query Logs\u003C\u002Fstrong> – View what visitors search for on your site\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Theme Changes\u003C\u002Fstrong> – Log theme switches and updates\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Plugin Activity\u003C\u002Fstrong> – Track plugin activations, deactivations, and updates\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Settings Modifications\u003C\u002Fstrong> – Monitor WordPress configuration changes\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Email Logging\u003C\u002Fstrong> – Optional tracking of outgoing emails\u003C\u002Fli>\n\u003Cli>\u003Cstrong>API Activity\u003C\u002Fstrong> – Track REST API requests (optional)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>File Changes\u003C\u002Fstrong> – Monitor theme and plugin file modifications\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>📊 Dashboard Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Activity Dashboard\u003C\u002Fstrong> – View all site events with color-coded categories\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Search & Filter\u003C\u002Fstrong> – Search logs by type, user, IP address, or keywords\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Active Sessions\u003C\u002Fstrong> – Real-time display of currently online users\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Security Alerts\u003C\u002Fstrong> – Dedicated view for security-related events\u003C\u002Fli>\n\u003Cli>\u003Cstrong>CSV Export\u003C\u002Fstrong> – Download activity logs for external analysis\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Log Rotation\u003C\u002Fstrong> – Automatic cleanup based on configurable storage limits\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Session Timeout\u003C\u002Fstrong> – Configurable automatic session cleanup\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Pagination\u003C\u002Fstrong> – Easy navigation through large log sets\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>⭐ Key Benefits\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Complete visibility into all website activity\u003C\u002Fli>\n\u003Cli>Easy-to-use interface suitable for any skill level\u003C\u002Fli>\n\u003Cli>Performance-optimized design\u003C\u002Fli>\n\u003Cli>All data stored locally on your server\u003C\u002Fli>\n\u003Cli>Fully translatable with proper internationalization support\u003C\u002Fli>\n\u003Cli>GDPR compliant with local-only data storage\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>🔍 Search & Filter Keywords\u003C\u002Fh3>\n\u003Cp>The plugin supports searching logs by various keywords and tags:\u003Cbr \u002F>\n– \u003Cstrong>AUTH\u003C\u002Fstrong> – Authentication events (login, logout, failed attempts)\u003Cbr \u002F>\n– \u003Cstrong>SECURITY\u003C\u002Fstrong> – Security alerts and warnings\u003Cbr \u002F>\n– \u003Cstrong>CONTENT\u003C\u002Fstrong> – Posts, pages, media, comments changes\u003Cbr \u002F>\n– \u003Cstrong>USER\u003C\u002Fstrong> – User management and role changes\u003Cbr \u002F>\n– \u003Cstrong>SYSTEM\u003C\u002Fstrong> – System events, plugins, themes\u003Cbr \u002F>\n– \u003Cstrong>TRAFFIC\u003C\u002Fstrong> – Visitor tracking, 404 errors\u003Cbr \u002F>\n– \u003Cstrong>SETTINGS\u003C\u002Fstrong> – Configuration changes\u003C\u002Fp>\n","Complete activity log and security audit plugin for WordPress. Monitor user actions, track sessions, log content changes, and maintain comprehensive s &hellip;",10,578,0,"2026-03-16T01:39:00.000Z","6.9.5","5.4","7.4",[19,20,21,22,23],"activity-log","security","security-audit","session-management","user-tracking","https:\u002F\u002Fblogcutter.com\u002Fwp-activity-log-security-audit-plugin","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fblogcutter-activity-log-security-audit.zip",100,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":32,"display_name":7,"profile_url":8,"plugin_count":33,"total_installs":11,"avg_security_score":26,"avg_patch_time_days":34,"trust_score":35,"computed_at":36},"blgctterai",5,30,94,"2026-08-28T22:43:40.148Z",[38,60,83,104,121],{"slug":39,"name":40,"version":41,"author":42,"author_profile":43,"description":44,"short_description":45,"active_installs":13,"downloaded":46,"rating":26,"num_ratings":47,"last_updated":48,"tested_up_to":49,"requires_at_least":50,"requires_php":51,"tags":52,"homepage":56,"download_link":57,"security_score":58,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":59},"telelog","TeleLog","1.0.3","Mahdyar Hasanpour","https:\u002F\u002Fprofiles.wordpress.org\u002Fmahdyarme\u002F","\u003Cp>This plugin is still under development and more hooks will be added soon, but for now, the full list of its hooks are:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Post publish\u003C\u002Fli>\n\u003Cli>Post update\u003C\u002Fli>\n\u003Cli>New comment\u003C\u002Fli>\n\u003Cli>Login fail\u003C\u002Fli>\n\u003Cli>New plugin activation\u003C\u002Fli>\n\u003Cli>New plugin deactivation\u003C\u002Fli>\n\u003Cli>Theme switch\u003C\u002Fli>\n\u003Cli>New user registation\u003C\u002Fli>\n\u003Cli>New WooCommerce order\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Set up\u003C\u002Fh3>\n\u003Col>\n\u003Cli>Create a new Telegram bot. (\u003Ca href=\"https:\u002F\u002Fcore.telegram.org\u002Fbots#3-how-do-i-create-a-bot\" rel=\"nofollow ugc\">Learn more\u003C\u002Fa>)\u003C\u002Fli>\n\u003Cli>Go to TeleLog admin page from your wordpress dashboard.\u003C\u002Fli>\n\u003Cli>Copy your bot token from botfather and paste it in the “API Key” field.\u003C\u002Fli>\n\u003Cli>If you want TeleLog to send the logs to your personal account, you can use your userid and put it in the “Chat ID” field (\u003Ca href=\"https:\u002F\u002Ft.me\u002Fuserinfobot\" rel=\"nofollow ugc\">Find your userid\u003C\u002Fa>), the other option is to create a channel and make your bot an admin with “Post Messages” access and enter the channel username as “Chat ID”, with an atsign(@) before it, e.g: \u003Ccode>@username\u003C\u002Fcode>.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>For every event that TeleLog sends it also reports the:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>User who did the change\u003C\u002Fli>\n\u003Cli>The object on which the change happenned.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>TeleLog in your language!\u003C\u002Fh4>\n\u003Cp>We need help translating TeleLog, feel free to contribute to our\u003Cbr \u002F>\n \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fmahdyar\u002Ftelelog\" rel=\"nofollow ugc\">GitHub Repository\u003C\u002Fa>. TeleLog currently supports:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>English\u003C\u002Fli>\n\u003Cli>Persian\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Install TeleLog from within WordPress\u003C\u002Fh3>\n\u003Col>\n\u003Cli>Visit ‘Plugins > Add New’\u003C\u002Fli>\n\u003Cli>Search for ‘TeleLog’\u003C\u002Fli>\n\u003Cli>Install and activate the TeleLog plugin\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch3>Install TeleLog manually\u003C\u002Fh3>\n\u003Col>\n\u003Cli>Upload the \u003Ccode>telelog\u003C\u002Fcode> directory to the \u003Ccode>\u002Fwp-content\u002Fplugins\u002F\u003C\u002Fcode> directory\u003C\u002Fli>\n\u003Cli>Activate the TeleLog plugin from the ‘Plugins’ menu in WordPress\u003C\u002Fli>\n\u003C\u002Fol>\n","Keep track of everything happening on your WordPress in Telegram",1071,1,"2021-10-07T09:00:00.000Z","5.8.13","4.4","7.0",[19,53,54,23,55],"audit-log","security-audit-log","wordpress-activity-logs","https:\u002F\u002Fgithub.com\u002Fmahdyar\u002Ftelelog","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Ftelelog.1.0.3.zip",85,"2026-04-06T09:54:40.288Z",{"slug":61,"name":62,"version":63,"author":64,"author_profile":65,"description":66,"short_description":67,"active_installs":68,"downloaded":69,"rating":70,"num_ratings":71,"last_updated":72,"tested_up_to":73,"requires_at_least":74,"requires_php":75,"tags":76,"homepage":78,"download_link":79,"security_score":80,"vuln_count":81,"unpatched_count":13,"last_vuln_date":82,"fetched_at":28},"stream","Stream – Activity Log & Audit Trail","4.3.0","XWP","https:\u002F\u002Fprofiles.wordpress.org\u002Fxwp\u002F","\u003Cp>Stream is a complete activity log and audit trail for your WordPress site: see what changed, who changed it, and when. From plugin activations to post edits, login attempts to new user creation, every user and system action is recorded in an audit log built for debugging, security monitoring, and compliance.\u003C\u002Fp>\n\u003Cp>Every logged action is displayed in an activity stream and organized for easy filtering by User, Role, Context, Action or IP address. Admins can highlight entries in the activity log—such as suspicious user activity—to investigate what’s happening in real time. Stream also lets you configure email alerts and webhooks for integrations like Slack and IFTTT, so your team knows the moment something goes wrong.\u003C\u002Fp>\n\u003Cp>Stream keeps its own logs healthy too: records are automatically purged on the retention schedule you choose, with batched deletion and orphaned-data cleanup that stay reliable even on very large sites.\u003C\u002Fp>\n\u003Cp>Stream is also AI-ready: its abilities are exposed through the WordPress Abilities API and MCP Adapter, so AI assistants and other tools can securely query your site’s activity records.\u003C\u002Fp>\n\u003Cp>For advanced users, Stream supports a network view of all activity records on your Multisite, exclude rules to ignore certain kinds of user activity, and a WP-CLI command for querying records.\u003C\u002Fp>\n\u003Cp>Stream is free and fully open source — development happens in the open \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fxwp\u002Fstream\" rel=\"nofollow ugc\">on GitHub\u003C\u002Fa>, maintained by \u003Ca href=\"https:\u002F\u002Fxwp.co\" rel=\"nofollow ugc\">XWP\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>With Stream’s powerful activity logging, you’ll have the information you need to responsibly manage your WordPress sites.\u003C\u002Fp>\n\u003Ch4>Built-In Tracking Integrations For Popular Plugins:\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Advanced Custom Fields\u003C\u002Fli>\n\u003Cli>bbPress\u003C\u002Fli>\n\u003Cli>BuddyPress\u003C\u002Fli>\n\u003Cli>Easy Digital Downloads\u003C\u002Fli>\n\u003Cli>Gravity Forms\u003C\u002Fli>\n\u003Cli>Jetpack\u003C\u002Fli>\n\u003Cli>Two Factor\u003C\u002Fli>\n\u003Cli>User Switching\u003C\u002Fli>\n\u003Cli>WooCommerce\u003C\u002Fli>\n\u003Cli>Yoast SEO\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Built-In Tracking For Core Actions:\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Posts\u003C\u002Fli>\n\u003Cli>Pages\u003C\u002Fli>\n\u003Cli>Custom Post Types\u003C\u002Fli>\n\u003Cli>Users\u003C\u002Fli>\n\u003Cli>Themes\u003C\u002Fli>\n\u003Cli>Plugins\u003C\u002Fli>\n\u003Cli>Tags\u003C\u002Fli>\n\u003Cli>Categories\u003C\u002Fli>\n\u003Cli>Custom Taxonomies\u003C\u002Fli>\n\u003Cli>Settings\u003C\u002Fli>\n\u003Cli>Custom Backgrounds\u003C\u002Fli>\n\u003Cli>Custom Headers\u003C\u002Fli>\n\u003Cli>Menus\u003C\u002Fli>\n\u003Cli>Media Library\u003C\u002Fli>\n\u003Cli>Widgets\u003C\u002Fli>\n\u003Cli>Comments\u003C\u002Fli>\n\u003Cli>Theme Editor\u003C\u002Fli>\n\u003Cli>WordPress Core Updates\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Other Noteworthy Features:\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Multisite view of all activity records on a network\u003C\u002Fli>\n\u003Cli>Limit who can view user activity records by user role\u003C\u002Fli>\n\u003Cli>Set exclude rules to ignore certain kinds of user activity\u003C\u002Fli>\n\u003Cli>Live updates of user activity records in the Stream\u003C\u002Fli>\n\u003Cli>Export your Activity Stream as a CSV or JSON file\u003C\u002Fli>\n\u003Cli>WP-CLI command for querying records\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Configuration\u003C\u002Fh3>\n\u003Cp>Most of the plugin configuration is available under the “Stream” \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> “Settings” page in the WordPress dashboard.\u003C\u002Fp>\n\u003Ch4>Request IP Address\u003C\u002Fh4>\n\u003Cp>The plugin expects the \u003Ccode>$_SERVER['REMOTE_ADDR']\u003C\u002Fcode> variable to contain the verified IP address of the current request. On hosting environments with PHP processing behind reverse proxies or CDNs the actual client IP is passed to PHP through request HTTP headers such as \u003Ccode>X-Forwarded-For\u003C\u002Fcode> and \u003Ccode>True-Client-IP\u003C\u002Fcode> which can’t be trusted without an additional layer of validation. Update your server configuration to set the \u003Ccode>$_SERVER['REMOTE_ADDR']\u003C\u002Fcode> variable to the verified client IP address.\u003C\u002Fp>\n\u003Cp>As a workaround, you can use the \u003Ccode>wp_stream_client_ip_address\u003C\u002Fcode> filter to adapt the IP address:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>add_filter(\n    'wp_stream_client_ip_address',\n    function( $client_ip ) {\n        \u002F\u002F Trust the first IP in the X-Forwarded-For header.\n        \u002F\u002F ⚠️ Note: This is inherently insecure and can easily be spoofed!\n        if ( ! empty( $_SERVER['HTTP_X_FORWARDED_FOR'] ) ) {\n            $forwarded_ips = explode( ',' $_SERVER['HTTP_X_FORWARDED_FOR'] );\n\n            if ( filter_var( $forwarded_ips[0], FILTER_VALIDATE_IP ) ) {\n                return $forwarded_ips[0];\n            }\n        }\n\n        return $client_ip;\n    }\n);\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>⚠️ \u003Cstrong>WARNING:\u003C\u002Fstrong> The above is an insecure workaround that you should only use when you fully understand what this implies. Relying on any variable with the \u003Ccode>HTTP_*\u003C\u002Fcode> prefix is prone to spoofing and cannot be trusted!\u003C\u002Fp>\n\u003Ch3>Known Issues\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>We have temporarily disabled the data removal feature through plugin uninstallation, starting with version 3.9.3. We identified a few edge cases that did not behave as expected and we decided that a temporary removal is preferable at this time for such an impactful and irreversible operation. Our team is actively working on refining this feature to ensure it performs optimally and securely. We plan to reintroduce it in a future update with enhanced safeguards.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Contribute\u003C\u002Fh3>\n\u003Cp>There are several ways you can get involved to help make Stream better:\u003C\u002Fp>\n\u003Col>\n\u003Cli>\n\u003Cp>\u003Cstrong>Report Bugs:\u003C\u002Fstrong> If you find a bug, error or other problem, please report it! You can do this by \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Fplugin\u002Fstream\" rel=\"ugc\">creating a new topic\u003C\u002Fa> in the plugin forum. Once a developer can verify the bug by reproducing it, they will create an official bug report in GitHub where the bug will be worked on.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Translate into Your Language:\u003C\u002Fstrong> Use the official plugin translation tool to \u003Ca href=\"https:\u002F\u002Ftranslate.wordpress.org\u002Fprojects\u002Fwp-plugins\u002Fstream\u002F\" rel=\"nofollow ugc\">translate Stream into your language\u003C\u002Fa>.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Suggest New Features:\u003C\u002Fstrong> Have an awesome idea? Please share it! Simply \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Fplugin\u002Fstream\" rel=\"ugc\">create a new topic\u003C\u002Fa> in the plugin forum to express your thoughts on why the feature should be included and get a discussion going around your idea.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Issue Pull Requests:\u003C\u002Fstrong> If you’re a developer, the easiest way to get involved is to help out on \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fx-team\u002Fwp-stream\u002Fissues\" rel=\"nofollow ugc\">issues already reported\u003C\u002Fa> in GitHub. Be sure to check out the \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fx-team\u002Fwp-stream\u002Fblob\u002Fmaster\u002Fcontributing.md\" rel=\"nofollow ugc\">contributing guide\u003C\u002Fa> for developers.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>Thank you for wanting to make Stream better for everyone!\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fxwp\u002Fstream\u002Fgraphs\u002Fcontributors\" rel=\"nofollow ugc\">View contributors here.\u003C\u002Fa>\u003C\u002Fp>\n","Real-time activity log and audit log for WordPress. Track every user action — logins, edits, plugin & settings changes — and get alerts.",80000,2379425,86,76,"2026-07-22T05:04:00.000Z","7.0.2","4.6","",[19,53,77,20,23],"event-log","https:\u002F\u002Fxwp.co\u002Fwork\u002Fstream\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fstream.4.3.0.zip",93,7,"2025-02-14 00:00:00",{"slug":84,"name":85,"version":86,"author":87,"author_profile":88,"description":89,"short_description":90,"active_installs":91,"downloaded":92,"rating":93,"num_ratings":94,"last_updated":95,"tested_up_to":96,"requires_at_least":97,"requires_php":51,"tags":98,"homepage":101,"download_link":102,"security_score":103,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"wp-admin-audit","WP Admin Audit","1.2.16","brandtoss","https:\u002F\u002Fprofiles.wordpress.org\u002Fbrandtoss\u002F","\u003Cp>\u003Cstrong>The modern activity log solution for WordPress\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwpadminaudit.com\u002F?utm_source=wordpress.org&utm_medium=referral&utm_campaign=WADA&utm_content=plugin+repo+description\" rel=\"nofollow ugc\">WP Admin Audit\u003C\u002Fa> is the powerful monitoring log plugin for WordPress.\u003Cbr \u002F>\nSite owners and administrators can sleep better at night knowing the plugin keeps track of all site changes, security events, and admin activities.\u003C\u002Fp>\n\u003Cp>Ever wondered\u003C\u002Fp>\n\u003Cul>\n\u003Cli>who unpublished a post?\u003C\u002Fli>\n\u003Cli>when a plugin was deactivated?\u003C\u002Fli>\n\u003Cli>how that strange new admin account appeared?\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>The WordPress activity log in WP Admin Audit answers these questions.\u003C\u002Fp>\n\u003Cp>Keep track of everything that happens on your WordPress sites to:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Have a log of every change that’s made\u003C\u002Fli>\n\u003Cli>Know about security-relevant activities\u003C\u002Fli>\n\u003Cli>Find out who did what and when they did it\u003C\u002Fli>\n\u003Cli>Analyze the steps that led to a technical problem\u003C\u002Fli>\n\u003Cli>Identify and mitigate automated login attempts by bots\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>What is being logged?\u003C\u002Fh3>\n\u003Cp>The short answer: almost all changes on your WordPress site, but you can decide what is kept in the audit log.\u003C\u002Fp>\n\u003Cp>The longer answer: WP Admin Audit has sensors that monitor the changes in your WordPress site and record what actions were performed by which user at which time on which item. A summary of the types of monitored events is below.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Content:\u003C\u002Fstrong> Page and Post changes (e.g. post created\u002Fupdated\u002Fpublished\u002Funpublished\u002Fdeleted)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Taxonomy:\u003C\u002Fstrong> Changes to Categories and Tags (e.g. tag is created, updated, or deleted)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>User:\u003C\u002Fstrong> User registration, user profile updates, password resets, user deletions, login, and logout\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WordPress:\u003C\u002Fstrong> Updates of the WordPress core version, settings updates (general\u002Fwriting\u002Freading\u002Fdiscussion\u002Fmedia\u002Fpermalink\u002Fprivacy settings)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Plugin:\u003C\u002Fstrong> Installation, activation, updates, deactivation, and deletion of plugins\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Theme:\u003C\u002Fstrong> Installation, activation (theme switch), update, and deletion of themes\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Media:\u003C\u002Fstrong> Media file and data creations, updates, and deletions\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Menu:\u003C\u002Fstrong> Creation, updates, and deletions of menus\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Comment:\u003C\u002Fstrong> Comment creations, updates, deletions, and status changes (approved, unapproved, spammed, etc.)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>File:\u003C\u002Fstrong> File changes via the  plugin file editor and theme file editor\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>See the complete list of sensors, i.e. \u003Ca href=\"https:\u002F\u002Fwpadminaudit.com\u002Fdocumentation\u002Fwp-admin-audit\u002Fsensors\u002Fevent-types\u002F?utm_source=wordpress.org&utm_medium=referral&utm_campaign=WADA&utm_content=plugin+repo+description\" rel=\"nofollow ugc\">the event types that are stored in the WordPress activity log\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>For every event WP Admin Audit records:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Event type\u003C\u002Fli>\n\u003Cli>Date and time\u003C\u002Fli>\n\u003Cli>IP address (the action\u002Fevent originated from)\u003C\u002Fli>\n\u003Cli>Acting user (the user who did the change)\u003C\u002Fli>\n\u003Cli>Subject (the item affected e.g. a post the action is done with\u002Fto)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Features (free)\u003C\u002Fh3>\n\u003Cp>Besides the WordPress event log, WP Admin Audit also features:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Powerful search & filtering:\u003C\u002Fstrong> Powerful free-text search as well as filtering by all sorts of categories makes it easy to find the data you are interested in.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Administrator & user audit:\u003C\u002Fstrong> Find inactive administrator accounts and review the users’ last login dates. Check on their individual activity log.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Login attempts audit:\u003C\u002Fstrong> Monitor logins to be aware of automated (brute-force) attacks and to identify IP addresses for blocking.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Features (premium editions)\u003C\u002Fh3>\n\u003Cp>Upgrade to the \u003Ca href=\"https:\u002F\u002Fwpadminaudit.com\u002Fpricing\u002F?utm_source=wordpress.org&utm_medium=referral&utm_campaign=WADA&utm_content=plugin+repo+description\" rel=\"nofollow ugc\">premium editions\u003C\u002Fa> for the following features:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Third-party plugin support:\u003C\u002Fstrong> Optional extensions help you capture events happening in other WordPress plugins. \u003Ca href=\"https:\u002F\u002Fwpadminaudit.com\u002Fextensions\u002F?utm_source=wordpress.org&utm_medium=referral&utm_campaign=WADA&utm_content=plugin+repo+description\" rel=\"nofollow ugc\">See our extension directory for more details.\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Notifications:\u003C\u002Fstrong> Select event types or event severity levels (e.g. critical and high) for instant notification via email. You can choose whole user groups (e.g. administrators), individual WordPress users, or selected email addresses.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Offsite archive \u002F Replication:\u003C\u002Fstrong> To increase security and for backup purposes, you can forward the events for storage to an external logging provider.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Enforce password changes:\u003C\u002Fstrong> You can enable a policy that requires users (with specific user roles) to change their passwords regularly. For example, administrator accounts can be required to change their passwords at least every 90 days.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>CSV export:\u003C\u002Fstrong> Export events, users, and login attempts to CSV files.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwpadminaudit.com\u002Ffeature-comparison\u002F?utm_source=wordpress.org&utm_medium=referral&utm_campaign=WADA&utm_content=plugin+repo+description\" rel=\"nofollow ugc\">Click here for more details and for a complete feature list\u003C\u002Fa>\u003C\u002Fp>\n","WP Admin Audit monitors the security-relevant activities on your site, keeps an event log and tells you when something out of the ordinary happens.",1000,14233,74,6,"2025-07-23T21:45:00.000Z","6.8.6","5.5",[19,53,99,54,100],"audit-trail","user-log","https:\u002F\u002Fwpadminaudit.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwp-admin-audit.1.2.16.zip",92,{"slug":105,"name":106,"version":107,"author":108,"author_profile":109,"description":110,"short_description":111,"active_installs":112,"downloaded":113,"rating":26,"num_ratings":114,"last_updated":115,"tested_up_to":96,"requires_at_least":116,"requires_php":117,"tags":118,"homepage":119,"download_link":120,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"logify-wp","Logify WP – Activity Log & User Audit Log","1.3.3","Made Neat","https:\u002F\u002Fprofiles.wordpress.org\u002Fmadeneat\u002F","\u003Cp>\u003Cstrong>Logify WP\u003C\u002Fstrong> provides real-time, detailed logs of activities happening across your WordPress website. Whether you’re an \u003Cstrong>agency\u003C\u002Fstrong>, \u003Cstrong>freelancer\u003C\u002Fstrong>, \u003Cstrong>IT team\u003C\u002Fstrong>, \u003Cstrong>developer\u003C\u002Fstrong>, or \u003Cstrong>website administrator\u003C\u002Fstrong>, Logify WP gives you full visibility into your website’s activity with a comprehensive \u003Cstrong>activity log\u003C\u002Fstrong> and \u003Cstrong>audit log\u003C\u002Fstrong>. From tracking post edits to user login attempts and plugin updates, Logify WP helps you monitor and secure your site with clear and easy-to-understand logs.\u003C\u002Fp>\n\u003Cp>Take your activity logs to the next level with activity \u003Cstrong>Notes\u003C\u002Fstrong>! This feature allows you to attach \u003Cstrong>searchable notes\u003C\u002Fstrong> linked to logged events, providing valuable context. Need to document why a plugin was installed, who approved an update, or where a license is stored? Now you can, with simple markup support for clarity.\u003C\u002Fp>\n\u003Cp>Built to be simple yet powerful, Logify WP features a clean layout of activity information, easy filtering and search options, and customizable role-based access controls. The user-friendly dashboard widget makes it easy to review recent critical activities at a glance.\u003C\u002Fp>\n\u003Ch3>Key Features:\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Activity Log Overview:\u003C\u002Fstrong> Get a complete chronological view of all logged activities across your WordPress site. Ideal for tracking patterns, diagnosing issues, and maintaining a transparent record of site events.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>User Audit Log:\u003C\u002Fstrong> Drill down into individual user activity with dedicated audit trails. See exactly what each user did, when, and from where, perfect for accountability and compliance.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Track Core WordPress Activities:\u003C\u002Fstrong> Record actions on posts, pages, custom post types, taxonomies, plugins, themes, users, and more.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Real-time Monitoring:\u003C\u002Fstrong> Get instant insights into who made changes, when, and where, via a secure \u003Cstrong>event log\u003C\u002Fstrong>.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Action Notes (New!):\u003C\u002Fstrong> Add and search \u003Cstrong>notes\u003C\u002Fstrong> linked to actions for improved tracking and accountability.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>User Login Monitoring:\u003C\u002Fstrong> Track user logins, logouts, and failed attempts with IP addresses.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Media Management:\u003C\u002Fstrong> Know who is uploading, editing, or deleting media files and when.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Role-Based Access Control:\u003C\u002Fstrong> Limit who can access the activity logs based on their WordPress role.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Advanced Search & Filters:\u003C\u002Fstrong> Filter logs by user, date, post type, and more to quickly find specific actions.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>User-Friendly Dashboard Widget:\u003C\u002Fstrong> View the most recent critical activities in a quick summary.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>IP Address Information Integration:\u003C\u002Fstrong> One-click access to IP information via WhatIsMyIpAddress.com.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Who is Logify WP for?\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Logify WP is perfect for:\u003Cbr \u002F>\n– \u003Cstrong>Agencies\u003C\u002Fstrong> managing multiple client sites.\u003Cbr \u002F>\n– \u003Cstrong>Freelancers\u003C\u002Fstrong> who need a detailed audit trail for their client work.\u003Cbr \u002F>\n– \u003Cstrong>IT Teams\u003C\u002Fstrong> maintaining the security of large WordPress environments.\u003Cbr \u002F>\n– \u003Cstrong>Website Administrators\u003C\u002Fstrong> responsible for monitoring site activity and detecting unauthorized changes.\u003Cbr \u002F>\n– \u003Cstrong>Developers\u003C\u002Fstrong> looking for a simple yet powerful logging tool.\u003Cbr \u002F>\n– \u003Cstrong>Everyday Website Users\u003C\u002Fstrong> who want a simple way to monitor and track activity on their site.\u003C\u002Fp>\n\u003Cp>Logify WP is actively being developed, with new features in the pipeline. If you’d like to suggest features, submit them via \u003Ca href=\"https:\u002F\u002Flogifywp.com\u002Fsuggest\u002F\" rel=\"nofollow ugc\">https:\u002F\u002Flogifywp.com\u002Fsuggest\u002F\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch3>Links\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Flogifywp.com\u002F\" rel=\"nofollow ugc\">Plugin Website\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Flogifywp.com\u002Fsuggest\u002F\" rel=\"nofollow ugc\">Suggest Features\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Credits\u003C\u002Fh3>\n\u003Cp>This plugin bundles \u003Ca href=\"https:\u002F\u002Fdatatables.net\" rel=\"nofollow ugc\">DataTables\u003C\u002Fa>, which is released under the \u003Ca href=\"https:\u002F\u002Fdatatables.net\u002Flicense\u002Fmit\" rel=\"nofollow ugc\">MIT License\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>DataTables ©2007-2024 SpryMedia Ltd.\u003C\u002Fp>\n\u003Ch3>Third-Party Services\u003C\u002Fh3>\n\u003Cp>This plugin utilizes third-party services under certain circumstances:\u003C\u002Fp>\n\u003Ch3>1. WordPress Documentation Links\u003C\u002Fh3>\n\u003Cp>When viewing logs, this plugin provides links to the official WordPress documentation corresponding to the version of WordPress that has been installed on your site. These links direct users to:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Service URL:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fdocumentation\u002F\" rel=\"ugc\">https:\u002F\u002Fwordpress.org\u002Fdocumentation\u002Fwordpress-version\u002Fversion-\u003Cversion>\u002F\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Purpose:\u003C\u002Fstrong> To offer quick access to documentation for the specific WordPress version installed.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data Sent:\u003C\u002Fstrong> The WordPress version number is included in the URL.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy Policy:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fabout\u002Fprivacy\u002F\" rel=\"ugc\">https:\u002F\u002Fwordpress.org\u002Fabout\u002Fprivacy\u002F\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>2. IP Address Lookup\u003C\u002Fh3>\n\u003Cp>This plugin allows users to click on logged IP addresses to view their origin information. When a user clicks an IP address in the log, it opens a link to an external service:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Service Name:\u003C\u002Fstrong> WhatIsMyIPAddress.com\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Service URL:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fwhatismyipaddress.com\u002F\" rel=\"nofollow ugc\">https:\u002F\u002Fwhatismyipaddress.com\u002Fip\u002F\u003CIP>\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Purpose:\u003C\u002Fstrong> To provide detailed information about the IP address’s geographical location and other related data.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data Sent:\u003C\u002Fstrong> The IP address clicked in the log is included in the URL.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy Policy:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fwhatismyipaddress.com\u002Fprivacy-policy\" rel=\"nofollow ugc\">https:\u002F\u002Fwhatismyipaddress.com\u002Fprivacy-policy\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Terms of Use:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fwhatismyipaddress.com\u002Fterms-of-use\" rel=\"nofollow ugc\">https:\u002F\u002Fwhatismyipaddress.com\u002Fterms-of-use\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>3. IP Geolocation Service\u003C\u002Fh3>\n\u003Cp>This plugin retrieves the geographical location of users based on their IP addresses to enhance log information. When a user’s IP address is logged, the plugin sends a request to an external service to obtain location details:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Service Name:\u003C\u002Fstrong> ip-api.com\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Service URL:\u003C\u002Fstrong> \u003Ca href=\"http:\u002F\u002Fip-api.com\u002F\" rel=\"nofollow ugc\">http:\u002F\u002Fip-api.com\u002Fjson\u002F\u003CIP>\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Purpose:\u003C\u002Fstrong> To obtain geographical location data (city, region, country) associated with the IP address for display in logs.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data Sent:\u003C\u002Fstrong> The user’s IP address is included in the API request URL.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data Received:\u003C\u002Fstrong> The service returns location information such as city, region, and country.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy Policy:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fip-api.com\u002Fdocs\u002Flegal\" rel=\"nofollow ugc\">https:\u002F\u002Fip-api.com\u002Fdocs\u002Flegal\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Terms of Service:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fip-api.com\u002Fdocs\u002Flegal\" rel=\"nofollow ugc\">https:\u002F\u002Fip-api.com\u002Fdocs\u002Flegal\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Please Note:\u003C\u002Fstrong> By using these features, data (such as your WordPress version, or your users’ IP addresses) is sent to external services. We recommend reviewing your privacy policies and terms of use to ensure compliance with local laws and regulations.\u003C\u002Fp>\n","Logify WP - Activity Log & User Audit Log tracks critical changes, logins, and updates with searchable logs for site security.",200,3296,2,"2025-12-05T11:23:00.000Z","6.2","8.0",[19,53,77,20,23],"https:\u002F\u002Flogifywp.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Flogify-wp.1.3.3.zip",{"slug":122,"name":123,"version":124,"author":125,"author_profile":126,"description":127,"short_description":128,"active_installs":13,"downloaded":129,"rating":13,"num_ratings":13,"last_updated":130,"tested_up_to":131,"requires_at_least":132,"requires_php":17,"tags":133,"homepage":75,"download_link":135,"security_score":103,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":59},"activity-lens","Activity Lens","1.0.0","Spidawebs","https:\u002F\u002Fprofiles.wordpress.org\u002Fspidawebs\u002F","\u003Cp>Activity Lens tracks user actions (login, logout, registration, deletion) and post actions (publish, edit, trash) in a separate database, ensuring minimal impact on WordPress performance. Ideal for security auditing and compliance.\u003C\u002Fp>\n\u003Cp>Features:\u003C\u002Fp>\n\u003Cp>Logs user and post activities with session tracking.\u003Cbr \u002F>\nUses a separate database for scalability.\u003Cbr \u002F>\nAdmin dashboard to view logs.\u003Cbr \u002F>\nExport logs as CSV.\u003Cbr \u002F>\nSecure with sanitized inputs and prepared queries.\u003C\u002Fp>\n\u003Ch3>License\u003C\u002Fh3>\n\u003Cp>Licensed under GPLv2 or later. See https:\u002F\u002Fwww.gnu.org\u002Flicenses\u002Fgpl-2.0.html.\u003C\u002Fp>\n","Log user and post activities in a separate database for performance and compliance.",389,"2025-06-11T13:58:00.000Z","6.8.5","5.0",[19,134,20,23],"audit","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Factivity-lens.1.0.0.zip",{"attackSurface":137,"codeSignals":269,"taintFlows":282,"riskAssessment":309,"analyzedAt":312},{"hooks":138,"ajaxHandlers":253,"restRoutes":264,"shortcodes":265,"cronEvents":266,"entryPointCount":114,"unprotectedCount":13},[139,145,149,153,157,161,165,169,173,177,181,185,188,192,195,199,203,207,211,215,219,223,227,231,235,239,243,247,250],{"type":140,"name":141,"callback":142,"file":143,"line":144},"action","admin_enqueue_scripts","enqueue_assets","blogcutter-activity-log-security-audit.php",36,{"type":140,"name":146,"callback":147,"file":143,"line":148},"admin_menu","register_menu",37,{"type":140,"name":150,"callback":151,"file":143,"line":152},"template_redirect","track_public_visitor",38,{"type":140,"name":154,"callback":155,"file":143,"line":156},"bcal_cleanup_sessions","cleanup_old_sessions",44,{"type":140,"name":158,"callback":159,"priority":11,"file":143,"line":160},"wp_mail","log_email",579,{"type":140,"name":162,"callback":163,"file":143,"line":164},"admin_init","closure",675,{"type":140,"name":166,"callback":167,"priority":11,"file":143,"line":168},"wp_login","on_login",863,{"type":140,"name":170,"callback":171,"file":143,"line":172},"wp_login_failed","on_fail",864,{"type":140,"name":174,"callback":175,"priority":11,"file":143,"line":176},"save_post","on_post_change",865,{"type":140,"name":178,"callback":179,"file":143,"line":180},"delete_post","on_post_delete",866,{"type":140,"name":182,"callback":183,"file":143,"line":184},"activated_plugin","on_plugin_action",867,{"type":140,"name":186,"callback":183,"file":143,"line":187},"deactivated_plugin",868,{"type":140,"name":189,"callback":190,"priority":11,"file":143,"line":191},"updated_option","on_setting_update",869,{"type":140,"name":162,"callback":193,"file":143,"line":194},"update_session",872,{"type":140,"name":196,"callback":197,"priority":11,"file":143,"line":198},"comment_post","on_comment",952,{"type":140,"name":200,"callback":201,"priority":11,"file":143,"line":202},"wp_set_comment_status","on_comment_status",953,{"type":140,"name":204,"callback":205,"priority":11,"file":143,"line":206},"delete_comment","on_comment_delete",954,{"type":140,"name":208,"callback":209,"priority":11,"file":143,"line":210},"add_user_role","on_user_role_add",959,{"type":140,"name":212,"callback":213,"priority":11,"file":143,"line":214},"remove_user_role","on_user_role_remove",960,{"type":140,"name":216,"callback":217,"priority":11,"file":143,"line":218},"created_term","on_term_create",965,{"type":140,"name":220,"callback":221,"priority":11,"file":143,"line":222},"edited_term","on_term_edit",966,{"type":140,"name":224,"callback":225,"priority":11,"file":143,"line":226},"delete_term","on_term_delete",967,{"type":140,"name":228,"callback":229,"file":143,"line":230},"sidebar_updated_sidebars","on_widget_change",972,{"type":140,"name":232,"callback":233,"file":143,"line":234},"wp_update_nav_menu","on_menu_update",977,{"type":140,"name":236,"callback":237,"file":143,"line":238},"wp_delete_nav_menu","on_menu_delete",978,{"type":140,"name":240,"callback":241,"priority":11,"file":143,"line":242},"switch_theme","on_theme_switch",983,{"type":140,"name":244,"callback":245,"priority":11,"file":143,"line":246},"upgrader_process_complete","on_theme_update",984,{"type":140,"name":244,"callback":248,"priority":11,"file":143,"line":249},"on_plugin_update",985,{"type":140,"name":251,"callback":252,"file":143,"line":46},"plugins_loaded","instance",[254,260],{"action":255,"nopriv":256,"callback":257,"hasNonce":258,"hasCapCheck":258,"file":143,"line":259},"bcal_clear",false,"ajax_clear_logs",true,574,{"action":261,"nopriv":256,"callback":262,"hasNonce":258,"hasCapCheck":258,"file":143,"line":263},"bcal_export","ajax_export_csv",575,[],[],[267],{"hook":154,"callback":154,"file":143,"line":268},42,{"dangerousFunctions":270,"sqlUsage":271,"outputEscaping":273,"fileOperations":280,"externalRequests":13,"nonceChecks":114,"capabilityChecks":114,"bundledLibraries":281},[],{"prepared":13,"raw":13,"locations":272},[],{"escaped":93,"rawEcho":114,"locations":274},[275,278],{"file":143,"line":276,"context":277},219,"raw output",{"file":143,"line":279,"context":277},348,3,[],[283,301],{"entryPoint":284,"graph":285,"unsanitizedCount":13,"severity":300},"render_dashboard (blogcutter-activity-log-security-audit.php:126)",{"nodes":286,"edges":298},[287,292],{"id":288,"type":289,"label":290,"file":143,"line":291},"n0","source","$_GET (x2)",130,{"id":293,"type":294,"label":295,"file":143,"line":296,"wp_function":297},"n1","sink","echo() [XSS]",181,"echo",[299],{"from":288,"to":293,"sanitized":258},"low",{"entryPoint":302,"graph":303,"unsanitizedCount":13,"severity":300},"\u003Cblogcutter-activity-log-security-audit> (blogcutter-activity-log-security-audit.php:0)",{"nodes":304,"edges":307},[305,306],{"id":288,"type":289,"label":290,"file":143,"line":291},{"id":293,"type":294,"label":295,"file":143,"line":296,"wp_function":297},[308],{"from":288,"to":293,"sanitized":258},{"summary":310,"deductions":311},"The blogcutter-activity-log-security-audit plugin v5.1.0 exhibits a generally strong security posture based on the static analysis.  A notable strength is the complete absence of directly exploitable dangerous functions and raw SQL queries; all SQL queries are properly prepared, and output escaping is highly effective at 97%.  Furthermore, the plugin demonstrates good security practices by implementing nonce and capability checks on its entry points and has a clean vulnerability history with no recorded CVEs, suggesting a commitment to security by the developers.  The limited attack surface of 2 AJAX handlers, with 0 found to be unprotected, further bolsters its security.  The absence of critical or high severity taint flows also indicates the code is well-structured with respect to data sanitization.\n\nWhile the plugin performs well in many areas, there are a few minor points of concern. The presence of file operations, though not immediately indicative of a vulnerability without further context, warrants careful consideration, as these can sometimes be leveraged in chained attacks. The total entry points are minimal, but the fact that 0 are unprotected is a very positive sign.  The vulnerability history being completely clear is a significant positive indicator. Overall, the plugin appears to be a secure option, with its strengths significantly outweighing its minor weaknesses.",[],"2026-03-17T00:13:43.341Z",{"wat":314,"direct":323},{"assetPaths":315,"generatorPatterns":317,"scriptPaths":318,"versionParams":320},[316],"\u002Fwp-content\u002Fplugins\u002Fblogcutter-activity-log-security-audit\u002Fcss\u002Fstyle.css",[],[319],"\u002Fwp-content\u002Fplugins\u002Fblogcutter-activity-log-security-audit\u002Fjs\u002Fbcal.js",[321,322],"blogcutter-activity-log-security-audit\u002Fcss\u002Fstyle.css?ver=","blogcutter-activity-log-security-audit\u002Fjs\u002Fbcal.js?ver=",{"cssClasses":324,"htmlComments":354,"htmlAttributes":367,"restEndpoints":369,"jsGlobals":370,"shortcodeOutput":372},[325,326,327,328,329,330,331,332,333,334,335,336,337,338,339,340,341,342,343,344,345,346,347,348,349,350,351,352,353],"bcal-wrap","bcal-header","bcal-nav","bcal-nav-item","bcal-nav-link","bcal-nav-link-active","bcal-main-content","bcal-stats-grid","bcal-stat-box","bcal-stat-icon","bcal-stat-value","bcal-stat-label","bcal-logs-table","bcal-log-entry","bcal-log-time","bcal-log-type","bcal-log-user","bcal-log-message","bcal-log-ip","bcal-pagination","bcal-pagination-link","bcal-pagination-current","bcal-search-form","bcal-search-input","bcal-search-submit","bcal-tab-nav","bcal-tab-nav a","bcal-tab-content","bcal-confirm",[355,356,357,358,359,360,361,362,363,364,365,366],"\u003C!-- Main Controller Class -->","\u003C!-- Schedule hourly cleanup of old sessions -->","\u003C!-- Track 404 errors -->","\u003C!-- Track regular visits - skip favicon and admin-ajax -->","\u003C!-- Track search queries if applicable -->","\u003C!-- Handle search filter -->","\u003C!-- Main Content Area -->","\u003C!-- Stats Overview -->","\u003C!-- Activity Log -->","\u003C!-- Pagination -->","\u003C!-- Settings -->","\u003C!-- Support -->",[368],"data-log-id",[],[371],"BCAL_VERSION",[],{"error":258,"url":374,"statusCode":375,"statusMessage":376,"message":376},"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fblogcutter-activity-log-security-audit\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":13,"versions":378},[]]