
Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity Security & Risk Analysis
wordpress.org/plugins/logtivityLogtivity is the activity log service for WordPress admins. Logtivity is a unified activity log platform that tracks activity and errors across all yo …
Is Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity Safe to Use in 2026?
Generally Safe
Score 98/100Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The logtivity plugin, version 3.3.6, exhibits a generally strong security posture based on the provided static analysis. The plugin demonstrates excellent adherence to secure coding practices by implementing robust authentication and permission checks across all identified entry points, including its AJAX handlers and REST API routes. The absence of dangerous functions, raw SQL queries, file operations, and critical or high-severity taint flows further bolsters this positive assessment. The presence of nonce and capability checks further indicates a conscious effort to protect against common WordPress attack vectors.
However, there are a couple of areas for potential improvement. While the overall output escaping is at 63%, this means a significant portion of outputs are not properly escaped, which could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is involved in these unescaped outputs. Additionally, the plugin makes two external HTTP requests, which, while not inherently a vulnerability, represent an external dependency that could be a vector for future issues if the external service is compromised or if data is not handled securely during the request and response.
The vulnerability history being entirely clear is a significant strength, suggesting a mature and well-maintained codebase. The lack of any recorded CVEs, common vulnerability types, or recent past issues indicates a likely commitment to security by the developers. In conclusion, logtivity 3.3.6 appears to be a secure plugin with a strong foundation, but the moderate rate of unescaped output warrants attention to prevent potential XSS flaws.
Key Concerns
- Moderate rate of unescaped output
- External HTTP requests present
Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity <= 3.3.6 - Unauthenticated Information Exposure
Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity <= 3.3.6 - Unauthenticated Information Disclosure via REST API
Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity Release Timeline
Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity Code Analysis
Output Escaping
Data Flow Analysis
Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity Attack Surface
AJAX Handlers 7
REST API Routes 1
WordPress Hooks 99
Maintenance & Trust
Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity Maintenance & Trust
Maintenance Signals
Community Trust
Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity Alternatives
404 to 301 – Redirect Manager, 404 Error Logs & Notifications
404-to-301
Custom redirects (301, 302, 307), automatic 404 redirection, full 404 error logs and email alerts — a complete redirect & 404 toolkit.
Activity Log Pro – User Activity Log, Audit Log & Security Monitor
activity-log-pro
WordPress activity log & admin user tracking. Track logins, content changes, and security events to see who did what, when, and where.
LogDash Activity Log
logdash-activity-log
The ultimate solution for tracking activities and security issues on your WordPress site.
ManicSoup Activity Log & Security Monitoring
manicsoup-logger
A clean, self-hosted WordPress activity log with built-in attack detection. See who did what, when, and where — and catch credential attacks.
Activity Track – User Activity Log
activity-track
User activity log for WordPress — track logins, edits, and admin actions with real-time alerts, audit trail, and AI-powered summaries.
Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity Developer Profile
1 plugin · 2K total installs
How We Detect Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/logtivity/Logtivity.php/wp-content/plugins/logtivity/Core/UpdateChecker.php/wp-content/plugins/logtivity/Core/Logtivity_Options.php/wp-content/plugins/logtivity/Core/Logtivity_Admin.php/wp-content/plugins/logtivity/Core/Logtivity_Ajax.php/wp-content/plugins/logtivity/Core/Logtivity_API.php/wp-content/plugins/logtivity/Core/Logtivity_Logger.php/wp-content/plugins/logtivity/Core/Logtivity_Helpers.php+29 moreHTML / DOM Fingerprints
logtivity-admin-wraplogtivity-main-contentlogtivity-tablelogtivity-filter-formlogtivity-log-detailLogtivity is free software: you can redistribute it and/or modifyLogtivity is distributed in the hope that it will be usefulThis file is part of Logtivity.data-logtivity-iddata-logtivity-typelogtivity_settingslogtivity_ajax_url/wp-json/logtivity/v1/logs/wp-json/logtivity/v1/settings