[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fpN_7AgwOIANlAjfv1QfDKLfAnfWPDb2TfI_pnTTm-TM":3,"$f7T21BT0dyT6g5OARzqXdYSMcml6cfi3Nnm3kWGb2yW4":132,"$ftjZh4BxUJyatvfNPpc8c3NAgi6Tqc77vf0L1d5bZyIE":137},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":11,"num_ratings":11,"last_updated":13,"tested_up_to":14,"requires_at_least":15,"requires_php":16,"tags":17,"homepage":23,"download_link":24,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27,"discovery_status":28,"vulnerabilities":29,"developer":30,"crawl_stats":26,"alternatives":37,"analysis":26,"fingerprints":26},"videowhisper-security-audit","VideoWhisper Security Audit","1.2.1","videowhisper","https:\u002F\u002Fprofiles.wordpress.org\u002Fvideowhisper\u002F","\u003Cp>VideoWhisper Security Audit creates WordPress site health, exposure, vulnerability, integrity, readiness, and performance reports for site administrators. The plugin is designed to help administrators review site activity and configuration with AI agents or by using the built-in admin report.\u003C\u002Fp>\n\u003Cp>The free plugin is read-only. It reports findings and does not perform cleanup, quarantine, updates, file changes, role changes, or other remediation actions.\u003C\u002Fp>\n\u003Cp>Plugin homepage: https:\u002F\u002Fpromptaur.com\u002Fwordpress\u002Fsecurity-audit\u002F\u003C\u002Fp>\n\u003Cp>Main features:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Admin Scan tab with queued scan processing, live progress, per-task status, resume\u002Fretry controls, scan date, report summary, and report findings.\u003C\u002Fli>\n\u003Cli>Configurable scan execution mode: queued scans by default, or legacy synchronous scans for small\u002Fbasic sites.\u003C\u002Fli>\n\u003Cli>Importance-based scan modes: full, critical\u002Fhigh\u002Fmedium, and critical-only.\u003C\u002Fli>\n\u003Cli>Report filters for issues only or all check results, including passed informational checks when available.\u003C\u002Fli>\n\u003Cli>JSON and plain-text Markdown report output.\u003C\u002Fli>\n\u003Cli>Optional token-protected REST report endpoint.\u003C\u002Fli>\n\u003Cli>Optional token-protected MCP endpoint for read-only AI-agent reports.\u003C\u002Fli>\n\u003Cli>Optional WordPress 6.9+ Abilities for admin-only read-only security overview, vulnerability, exposure, integrity, readiness, performance risk, and Markdown audit reports.\u003C\u002Fli>\n\u003Cli>Optional exposure of those abilities through the official WordPress MCP Adapter when installed separately.\u003C\u002Fli>\n\u003Cli>Read-only integration with \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fvideowhisper-site-manager\u002F\" rel=\"ugc\">VideoWhisper AI Site Manager – Using ChatGPT Claude Codex\u003C\u002Fa> when both plugins are active, including report reads and agent-friendly queued scan tools.\u003C\u002Fli>\n\u003Cli>Separate REST and MCP enable\u002Fdisable settings.\u003C\u002Fli>\n\u003Cli>Generated local tokens with rotation controls and last-used metadata.\u003C\u002Fli>\n\u003Cli>REST\u002FMCP per-minute rate limiting and optional exact IP allowlist.\u003C\u002Fli>\n\u003Cli>Admin scan cooldown, hourly scan limit, and separate agent scan cooldown.\u003C\u002Fli>\n\u003Cli>Category toggles for security, integrity, performance, readiness, commerce, community, and backup checks.\u003C\u002Fli>\n\u003Cli>Redacted AI report defaults, with optional exact version and path disclosure for MCP reports.\u003C\u002Fli>\n\u003Cli>Optional WPVulnerability API lookups for installed plugin vulnerability data.\u003C\u002Fli>\n\u003Cli>Disclaimers in the admin report and Agents tab about report limits, sensitive information, and third-party AI analysis.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Queued scans\u003C\u002Fh4>\n\u003Cp>Queued scanning is the default admin interface. It splits inventory, exposure, vulnerability, integrity, performance, and readiness checks into small AJAX-polled batches. This avoids browser, proxy, and PHP timeout issues on larger sites while showing progress and recent queue events. Failed tasks can be retried, and unfinished jobs can be resumed from the Scan tab.\u003C\u002Fp>\n\u003Cp>Administrators that prefer the original one-request scan flow can switch Scan execution to “Synchronous legacy scan” in Settings.\u003C\u002Fp>\n\u003Ch4>Local checks\u003C\u002Fh4>\n\u003Cp>Security Audit currently checks local WordPress signals including:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Plugin and theme updates.\u003C\u002Fli>\n\u003Cli>Inactive plugins.\u003C\u002Fli>\n\u003Cli>Administrator account count.\u003C\u002Fli>\n\u003Cli>Expected WordPress database tables.\u003C\u002Fli>\n\u003Cli>Administrator role capabilities.\u003C\u002Fli>\n\u003Cli>Upload directory writability.\u003C\u002Fli>\n\u003Cli>Debug log file presence.\u003C\u002Fli>\n\u003Cli>Git metadata in the web root.\u003C\u002Fli>\n\u003Cli>XML-RPC availability.\u003C\u002Fli>\n\u003Cli>Common homepage security headers.\u003C\u002Fli>\n\u003Cli>Autoloaded option size.\u003C\u002Fli>\n\u003Cli>Expired transient count.\u003C\u002Fli>\n\u003Cli>WP-Cron disabled state.\u003C\u002Fli>\n\u003Cli>Permalink structure.\u003C\u002Fli>\n\u003Cli>Search engine visibility setting.\u003C\u002Fli>\n\u003Cli>Privacy Policy page presence.\u003C\u002Fli>\n\u003Cli>Basic WooCommerce page readiness when WooCommerce is active.\u003C\u002Fli>\n\u003Cli>Optional WPVulnerability plugin vulnerability lookups.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Agent and API reports\u003C\u002Fh4>\n\u003Cp>REST and MCP endpoints are disabled by default. When enabled, Security Audit automatically generates local tokens. Anyone with a valid token can read the selected report until the token is rotated, so treat tokens as sensitive secrets.\u003C\u002Fp>\n\u003Cp>The REST report endpoint supports:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ccode>key\u003C\u002Fcode>: generated REST token. A bearer token can also be used.\u003C\u002Fli>\n\u003Cli>\u003Ccode>mode\u003C\u002Fcode>: \u003Ccode>full\u003C\u002Fcode>, \u003Ccode>important\u003C\u002Fcode>, \u003Ccode>critical\u003C\u002Fcode>, or \u003Ccode>changed\u003C\u002Fcode>.\u003C\u002Fli>\n\u003Cli>\u003Ccode>report\u003C\u002Fcode>: \u003Ccode>issues\u003C\u002Fcode> or \u003Ccode>all\u003C\u002Fcode>.\u003C\u002Fli>\n\u003Cli>\u003Ccode>format\u003C\u002Fcode>: omit for JSON, or use \u003Ccode>markdown\u003C\u002Fcode> for plain Markdown output.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>The MCP endpoint supports read-only tools for security summary, vulnerability, exposure, integrity, performance risk, readiness, and Markdown audit reports. Tool arguments include \u003Ccode>mode\u003C\u002Fcode> and \u003Ccode>report\u003C\u002Fcode>.\u003C\u002Fp>\n\u003Cp>When VideoWhisper AI Site Manager is active, Security Audit also registers agent tools for latest summary\u002Freport reads, synchronous scan refreshes for small sites, scan task discovery, queued scan creation, queue batch processing, queue status polling, and retrying failed scan tasks.\u003C\u002Fp>\n\u003Cp>On WordPress 6.9+, administrators can also enable WordPress Abilities. These abilities are admin-only, read-only, and permission-checked with \u003Ccode>manage_options\u003C\u002Fcode> by default. They can optionally be marked public for the official WordPress MCP Adapter, which must be installed separately. Existing REST and MCP endpoints remain available and are not replaced.\u003C\u002Fp>\n\u003Cp>Some sites use an OAuth, firewall, or bearer-auth layer that consumes \u003Ccode>Authorization: Bearer\u003C\u002Fcode> before the Security Audit route receives the request. If standalone Codex MCP bearer setup returns \u003Ccode>oauth_token_invalid\u003C\u002Fcode> or a similar upstream bearer-auth error, use the MCP path-token URL shown on the Agents tab instead of the bearer URL.\u003C\u002Fp>\n\u003Cp>Endpoint protection controls include:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>REST\u002FMCP requests per minute per IP.\u003C\u002Fli>\n\u003Cli>Separate agent scan cooldown.\u003C\u002Fli>\n\u003Cli>Optional exact IPv4\u002FIPv6 allowlist.\u003C\u002Fli>\n\u003Cli>Token rotation.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Developer hooks\u003C\u002Fh4>\n\u003Cp>Security Audit exposes generic hooks that any plugin can use to extend scan data, reports, admin UI, and Site Manager integration:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ccode>vwsa_latest_snapshot\u003C\u002Fcode> filters the latest stored snapshot before reports use it.\u003C\u002Fli>\n\u003Cli>\u003Ccode>vwsa_scan_settings\u003C\u002Fcode> filters normalized scan settings for a scan context.\u003C\u002Fli>\n\u003Cli>\u003Ccode>vwsa_scan_inventory\u003C\u002Fcode> filters inventory data before findings are finalized.\u003C\u002Fli>\n\u003Cli>\u003Ccode>vwsa_scan_findings\u003C\u002Fcode> filters findings before snapshot lifecycle metadata is saved.\u003C\u002Fli>\n\u003Cli>\u003Ccode>vwsa_snapshot_before_save\u003C\u002Fcode> filters the completed snapshot before it is stored.\u003C\u002Fli>\n\u003Cli>\u003Ccode>vwsa_snapshot_saved\u003C\u002Fcode> fires after a snapshot is stored.\u003C\u002Fli>\n\u003Cli>\u003Ccode>vwsa_report\u003C\u002Fcode> filters built report output.\u003C\u002Fli>\n\u003Cli>\u003Ccode>vwsa_site_manager_integration\u003C\u002Fcode> filters the Site Manager integration definition.\u003C\u002Fli>\n\u003Cli>\u003Ccode>vwsa_admin_tabs\u003C\u002Fcode> filters admin tabs.\u003C\u002Fli>\n\u003Cli>\u003Ccode>vwsa_admin_render_tab\u003C\u002Fcode> lets extensions render custom admin tabs.\u003C\u002Fli>\n\u003Cli>\u003Ccode>vwsa_admin_scan_panel_after\u003C\u002Fcode> renders generic content after the scan panel.\u003C\u002Fli>\n\u003Cli>\u003Ccode>vwsa_admin_findings_before\u003C\u002Fcode> renders content before findings.\u003C\u002Fli>\n\u003Cli>\u003Ccode>vwsa_admin_finding_card_start\u003C\u002Fcode> renders content inside a finding card.\u003C\u002Fli>\n\u003Cli>\u003Ccode>vwsa_admin_finding_actions\u003C\u002Fcode> filters per-finding action links.\u003C\u002Fli>\n\u003Cli>\u003Ccode>vwsa_admin_findings_after\u003C\u002Fcode> renders content after findings.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Important limitations and disclaimers\u003C\u002Fh4>\n\u003Cp>Security Audit reports are informational only. Findings and AI-ready reports may be incomplete, inaccurate, outdated, or unsuitable for a specific site or legal situation.\u003C\u002Fp>\n\u003Cp>Security Audit does not provide legal advice, compliance certification, professional security advice, malware cleanup, incident response, or a guarantee that a site is secure. Administrators should verify findings and consult an experienced security, technical, or legal provider before making important changes.\u003C\u002Fp>\n\u003Cp>REST and MCP reports may expose sensitive operational information, including site configuration, component versions, possible vulnerabilities, paths, and other details. Enable agent endpoints only when you understand where the data will be sent and who can access the token.\u003C\u002Fp>\n\u003Cp>Third-party AI agents may produce incomplete, incorrect, unsafe, or unsuitable recommendations. Review all recommendations before acting and do not perform destructive changes without backups and appropriate professional review.\u003C\u002Fp>\n\u003Cp>This plugin is not a firewall, malware cleaner, legal compliance tool, vulnerability scanner guarantee, or replacement for backups, security monitoring, dedicated scanners, or experienced administrators.\u003C\u002Fp>\n\u003Ch4>External services\u003C\u002Fh4>\n\u003Cp>By default, Security Audit does not call external vulnerability services.\u003C\u002Fp>\n\u003Cp>If the administrator enables WPVulnerability lookups, the plugin sends installed plugin slugs to the public WPVulnerability API at \u003Ccode>https:\u002F\u002Fwww.wpvulnerability.net\u002F\u003C\u002Fcode> to retrieve vulnerability data. No API key is required for normal component lookups. Responses are cached locally. See:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>https:\u002F\u002Fwww.wpvulnerability.com\u002F\u003C\u002Fli>\n\u003Cli>https:\u002F\u002Fdocs.wpvulnerability.com\u002F\u003C\u002Fli>\n\u003Cli>https:\u002F\u002Fwww.wpvulnerability.com\u002Fprivacy\u002F\u003C\u002Fli>\n\u003Cli>https:\u002F\u002Fwww.wpvulnerability.com\u002Flicense\u002F\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>During scans, Security Audit may also make a local HTTP HEAD request to the site’s own homepage URL to inspect response headers. This request is sent to the configured site URL, not to a third-party vulnerability service.\u003C\u002Fp>\n","AI-ready WordPress site health and security reports for administrators, with queued scans and optional read-only REST\u002FMCP access.",0,140,"2026-07-06T08:09:00.000Z","7.0.2","6.0","7.4",[18,19,20,21,22],"audit","mcp","reports","security","site-health","https:\u002F\u002Fpromptaur.com\u002Fwordpress\u002Fsecurity-audit\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fvideowhisper-security-audit.zip",100,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":7,"display_name":7,"profile_url":8,"plugin_count":31,"total_installs":32,"avg_security_score":33,"avg_patch_time_days":34,"trust_score":35,"computed_at":36},16,1170,95,907,76,"2026-08-29T11:21:45.980Z",[38,56,73,88,112],{"slug":39,"name":40,"version":41,"author":42,"author_profile":43,"description":44,"short_description":45,"active_installs":11,"downloaded":46,"rating":11,"num_ratings":11,"last_updated":47,"tested_up_to":48,"requires_at_least":49,"requires_php":16,"tags":50,"homepage":53,"download_link":54,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":55},"boonrisk-site-security-check-report","BoonRisk – Site Security Check & Report","1.0.2","Boon Band","https:\u002F\u002Fprofiles.wordpress.org\u002Fboonband\u002F","\u003Cp>BoonRisk gives you a \u003Cstrong>clear security and readiness report\u003C\u002Fstrong> for your WordPress site. See exactly what security risks exist, why they matter, and what to do about them — all explained in plain language.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Safe & Read-Only:\u003C\u002Fstrong> This plugin only reads your site configuration. It does not scan files, block traffic, or make any changes to your WordPress installation.\u003C\u002Fp>\n\u003Ch4>What You Get\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Security Check Report\u003C\u002Fstrong> — See your site’s security status: PHP version, WordPress updates, user settings, HTTPS, and 30+ configuration checks\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Clear Explanations\u003C\u002Fstrong> — Every finding explains “why this matters” and “what to do about it” in plain language\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Prioritized Risks\u003C\u002Fstrong> — Top risks ranked by impact so you know what to fix first\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Printable Report\u003C\u002Fstrong> — Professional HTML report you can view, print, or share directly from WordPress admin\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>What This Plugin Does NOT Do (100% Safe)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>No file scanning\u003C\u002Fstrong> — Does not scan your files or look for malware\u003C\u002Fli>\n\u003Cli>\u003Cstrong>No traffic blocking\u003C\u002Fstrong> — Does not act as a firewall or block visitors\u003C\u002Fli>\n\u003Cli>\u003Cstrong>No site changes\u003C\u002Fstrong> — Does not modify settings, files, or database\u003C\u002Fli>\n\u003Cli>\u003Cstrong>No active testing\u003C\u002Fstrong> — Does not simulate attacks or run security scans\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Read-only analysis\u003C\u002Fstrong> — Only reads your configuration, never writes or changes anything\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Who Is It For?\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Site owners\u003C\u002Fstrong> — Understand your security risks without technical expertise\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Freelancers & agencies\u003C\u002Fstrong> — Generate client-ready reports in minutes\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Developers\u003C\u002Fstrong> — Quick baseline check before or after deployments\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Teams\u003C\u002Fstrong> — Consistent security reporting across multiple WordPress sites\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Free Security Check (No Account Required)\u003C\u002Fh4>\n\u003Cp>Run a complete security and readiness check instantly — 100% local, no data sent anywhere:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Overall Risk Level\u003C\u002Fstrong> — Clear Low\u002FMedium\u002FHigh rating with explanation of what it means\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Top Risks First\u003C\u002Fstrong> — See your biggest security issues ranked by impact\u003C\u002Fli>\n\u003Cli>\u003Cstrong>30+ Configuration Checks\u003C\u002Fstrong> — WordPress updates, PHP version, HTTPS, user permissions, backups, 2FA, debug mode, and more\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Action Plan\u003C\u002Fstrong> — Every issue includes “why it matters” and “how to fix it”\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Professional Report\u003C\u002Fstrong> — Printable HTML report you can view in WordPress admin or share with your team\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>What you’ll learn:\u003C\u002Fstrong> “Is my site at risk?” and “What should I fix first?”\u003C\u002Fp>\n\u003Cp>\u003Cstrong>100% Private:\u003C\u002Fstrong> All checks run on your server. Nothing is sent externally. No account or email required.\u003C\u002Fp>\n\u003Ch4>Optional: Web Dashboard\u003C\u002Fh4>\n\u003Cp>Connect the plugin to the \u003Ca href=\"https:\u002F\u002Fboonrisk.com\u002F\" rel=\"nofollow ugc\">BoonRisk web dashboard\u003C\u002Fa> for additional capabilities (optional, requires free account):\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fboonrisk.com\u002Fscanner\u002F\" rel=\"nofollow ugc\">Surface Scan\u003C\u002Fa>\u003C\u002Fstrong> — External scan of your site’s public-facing security headers, SSL configuration, and exposed services\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Vulnerability Intelligence\u003C\u002Fstrong> — Known CVEs matched to your installed plugins and themes with severity ratings\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Continuous Monitoring\u003C\u002Fstrong> — Automatic daily checks with alerts when your security posture changes\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Track Over Time\u003C\u002Fstrong> — See how your site security improves (or changes) month over month\u003C\u002Fli>\n\u003Cli>\u003Cstrong>PDF Reports\u003C\u002Fstrong> — Download professional reports to share with clients or management\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong> The local security check is fully functional on its own. The web dashboard is completely optional.\u003C\u002Fp>\n\u003Cp>Learn more at \u003Ca href=\"https:\u002F\u002Fboonrisk.com\u002F\" rel=\"nofollow ugc\">boonrisk.com\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>How It Works\u003C\u002Fh3>\n\u003Ch4>Local Assessment (Default)\u003C\u002Fh4>\n\u003Col>\n\u003Cli>Install and activate the plugin\u003C\u002Fli>\n\u003Cli>Go to \u003Cstrong>BoonRisk\u003C\u002Fstrong> \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> \u003Cstrong>Local Assessment\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Click \u003Cstrong>Run Assessment Now\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>View your Security Posture Summary and Top Risks\u003C\u002Fli>\n\u003Cli>Click \u003Cstrong>View Full Report\u003C\u002Fstrong> for a printable HTML report\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>All analysis happens on your server. Nothing is sent externally.\u003C\u002Fp>\n\u003Ch4>Web Dashboard (Optional)\u003C\u002Fh4>\n\u003Col>\n\u003Cli>Create a free account at \u003Ca href=\"https:\u002F\u002Fboonrisk.com\u002F\" rel=\"nofollow ugc\">boonrisk.com\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Go to \u003Cstrong>BoonRisk\u003C\u002Fstrong> \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> \u003Cstrong>Connect (Optional)\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Enter your API key\u003C\u002Fli>\n\u003Cli>Send your assessment to the dashboard for vulnerability intelligence, surface scan, and monitoring\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>External API calls only happen when you explicitly request them.\u003C\u002Fp>\n\u003Ch3>Data Usage\u003C\u002Fh3>\n\u003Ch4>Local Assessment\u003C\u002Fh4>\n\u003Cp>In local mode, \u003Cstrong>no data is sent externally\u003C\u002Fstrong>. All checks run inside WordPress.\u003C\u002Fp>\n\u003Ch4>Web Dashboard (Optional)\u003C\u002Fh4>\n\u003Cp>When you send data to the dashboard, the following is transmitted:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>PHP and WordPress versions\u003C\u002Fli>\n\u003Cli>Active plugin and theme names\u002Fversions\u003C\u002Fli>\n\u003Cli>Configuration flags (debug mode, file editor status, etc.)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>What you get in return:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Known vulnerability data for your installed plugins and themes\u003C\u002Fli>\n\u003Cli>Surface scan results for public-facing security\u003C\u002Fli>\n\u003Cli>Severity context for identified risks\u003C\u002Fli>\n\u003Cli>Historical trend data and monitoring alerts\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>What is never collected:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>User data or personal information\u003C\u002Fli>\n\u003Cli>Passwords or credentials\u003C\u002Fli>\n\u003Cli>Post\u002Fpage content\u003C\u002Fli>\n\u003Cli>Database contents\u003C\u002Fli>\n\u003Cli>File contents\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Data is sent \u003Cstrong>only when you click\u003C\u002Fstrong> Send to Dashboard or enable automatic daily sync. No personal data is collected.\u003C\u002Fp>\n\u003Ch3>Privacy Policy\u003C\u002Fh3>\n\u003Cp>Read our full privacy policy at https:\u002F\u002Fboonrisk.com\u002Fprivacy\u003C\u002Fp>\n","Security posture report for WordPress — 30+ checks, prioritized risks, and a printable report. Get a clear picture in minutes.",171,"2026-02-16T17:38:00.000Z","6.9.4","5.0",[18,51,21,22,52],"hardening","vulnerability","https:\u002F\u002Fboonrisk.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fboonrisk-site-security-check-report.1.0.2.zip","2026-04-16T10:56:18.058Z",{"slug":57,"name":58,"version":59,"author":60,"author_profile":61,"description":62,"short_description":63,"active_installs":11,"downloaded":64,"rating":11,"num_ratings":11,"last_updated":65,"tested_up_to":66,"requires_at_least":15,"requires_php":16,"tags":67,"homepage":71,"download_link":72,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"healthspark","HealthSpark Site Health Dashboard","1.0.6","Pluginjoy","https:\u002F\u002Fprofiles.wordpress.org\u002Faacers\u002F","\u003Cp>\u003Cstrong>HealthSpark\u003C\u002Fstrong> gives you a complete health overview of your WordPress site in one beautiful dashboard. Stop juggling multiple plugins and tools — HealthSpark checks everything that matters and lets you fix issues with one click.\u003C\u002Fp>\n\u003Ch4>Five Vital Scans in One Dashboard\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Accessibility (WCAG)\u003C\u002Fstrong> — Missing alt text, heading hierarchy, skip links, theme accessibility, form labels, viewport zoom\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Performance\u003C\u002Fstrong> — Oversized images, page caching, PHP version, plugin count, post revisions, object cache\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Security\u003C\u002Fstrong> — WordPress updates, SSL, debug mode, file editor, admin username, database prefix, XML-RPC, plugin updates, file permissions\u003C\u002Fli>\n\u003Cli>\u003Cstrong>SEO Health\u003C\u002Fstrong> — Search visibility, SEO plugin detection, XML sitemaps, permalinks, meta descriptions, thin content\u003C\u002Fli>\n\u003Cli>\u003Cstrong>EU Compliance\u003C\u002Fstrong> — Privacy policy, cookie consent, data export tools, comment consent, data retention\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>One-Click Auto-Fixes\u003C\u002Fh4>\n\u003Cp>HealthSpark does not just find problems — it fixes them! Available auto-fixes include:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Generate alt text for images from filenames\u003C\u002Fli>\n\u003Cli>Enable search engine visibility\u003C\u002Fli>\n\u003Cli>Disable debug display for visitors\u003C\u002Fli>\n\u003Cli>Enable comment cookie consent\u003C\u002Fli>\n\u003Cli>Clean up spam and trash comments\u003C\u002Fli>\n\u003Cli>Clean up old post revisions\u003C\u002Fli>\n\u003Cli>Set SEO-friendly permalinks\u003C\u002Fli>\n\u003Cli>Disable XML-RPC\u003C\u002Fli>\n\u003Cli>Disable the file editor\u003C\u002Fli>\n\u003Cli>Create a privacy policy page\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Key Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>One-click scanning\u003C\u002Fstrong> — Run all five scans with a single button\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Beautiful dashboard\u003C\u002Fstrong> — Clean, modern interface with color-coded scores\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Actionable fixes\u003C\u002Fstrong> — Direct links and auto-fix buttons for every issue\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Score tracking\u003C\u002Fstrong> — See your overall site health at a glance\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Lightweight\u003C\u002Fstrong> — No bloat, no external API calls in the free version\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Translation ready\u003C\u002Fstrong> — Fully prepared for localization\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Smart detection\u003C\u002Fstrong> — Recognizes any SEO, security, or cookie consent plugin\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Pro Features\u003C\u002Fh4>\n\u003Cp>Unlock the full power of HealthSpark with Pro at \u003Ca href=\"https:\u002F\u002Fpluginjoy.com\" rel=\"nofollow ugc\">pluginjoy.com\u003C\u002Fa>:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Unlimited page scanning (free version: 5 pages)\u003C\u002Fli>\n\u003Cli>Auto-fix accessibility issues\u003C\u002Fli>\n\u003Cli>Cookie consent & GDPR compliance tools\u003C\u002Fli>\n\u003Cli>PDF compliance reports\u003C\u002Fli>\n\u003Cli>Scheduled automated scans\u003C\u002Fli>\n\u003Cli>Email alerts when scores drop\u003C\u002Fli>\n\u003Cli>White-label for agencies\u003C\u002Fli>\n\u003Cli>CRA (Cyber Resilience Act) readiness checks\u003C\u002Fli>\n\u003Cli>EAA (European Accessibility Act) audit\u003C\u002Fli>\n\u003Cli>Priority support\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Links\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fpluginjoy.com\" rel=\"nofollow ugc\">Plugin Homepage\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fpluginjoy.com\" rel=\"nofollow ugc\">Documentation\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Fplugin\u002Fhealthspark\u002F\" rel=\"ugc\">Support\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n","Your site's vital signs — all in one dashboard. Monitor accessibility, performance, security, SEO health, and EU compliance.",181,"2026-05-05T18:38:00.000Z","6.9.5",[68,69,21,70,22],"accessibility","performance","seo-audit","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fhealthspark\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fhealthspark.1.0.6.zip",{"slug":74,"name":75,"version":76,"author":77,"author_profile":78,"description":79,"short_description":80,"active_installs":11,"downloaded":81,"rating":11,"num_ratings":11,"last_updated":82,"tested_up_to":14,"requires_at_least":15,"requires_php":16,"tags":83,"homepage":86,"download_link":87,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"scinorx-site-risk-snapshot","Scinorx Site Risk Snapshot","1.0.0","Scinorx Technologies Inc","https:\u002F\u002Fprofiles.wordpress.org\u002Fscinorxtechnologies\u002F","\u003Cp>Scinorx Site Risk Snapshot helps WordPress administrators review practical plugin-maintenance risk signals from inside WordPress.\u003C\u002Fp>\n\u003Cp>The plugin creates a local snapshot covering:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Installed, active, and inactive plugins\u003C\u002Fli>\n\u003Cli>Plugin updates visible in the cached WordPress update data\u003C\u002Fli>\n\u003Cli>Writable plugin main files\u003C\u002Fli>\n\u003Cli>Missing plugin compatibility headers\u003C\u002Fli>\n\u003Cli>Administrator account count\u003C\u002Fli>\n\u003Cli>Whether the built-in theme and plugin file editor is disabled\u003C\u002Fli>\n\u003Cli>Must-use plugins and drop-ins for review awareness\u003C\u002Fli>\n\u003Cli>A copyable plain-text report for developers, hosts, or internal review\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>This plugin is intentionally diagnostic. It does not update plugins, delete plugins, modify files, change users, disable editors, or automatically apply hardening changes.\u003C\u002Fp>\n\u003Cp>Scinorx Site Risk Snapshot is useful before a maintenance pass, after a website handoff, during a plugin cleanup review, or when a business owner wants a simple summary of site risk signals.\u003C\u002Fp>\n\u003Ch4>Privacy\u003C\u002Fh4>\n\u003Cp>The plugin does not send data to Scinorx Technologies or any third party.\u003C\u002Fp>\n\u003Cp>It does not use telemetry, tracking, analytics, hidden remote API calls, or background reporting.\u003C\u002Fp>\n\u003Cp>The snapshot is generated locally in WordPress admin from WordPress\u002Fplugin metadata and current site state. The report can be copied manually by an administrator if they choose to share it with a developer, host, or Scinorx.\u003C\u002Fp>\n\u003Ch4>External Services\u003C\u002Fh4>\n\u003Cp>This plugin does not contact external services.\u003C\u002Fp>\n\u003Cp>WordPress itself may already maintain plugin update data through its normal update system. Scinorx Site Risk Snapshot reads the local cached update data when available; it does not trigger its own remote update check.\u003C\u002Fp>\n","Review WordPress maintenance risk signals, inactive extensions, update visibility, admin count, and hardening basics.",62,"2026-07-05T14:31:00.000Z",[84,18,85,21,22],"admin","maintenance","https:\u002F\u002Fscinorx.com\u002Ftools\u002Fsite-risk-snapshot-by-scinorx\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fscinorx-site-risk-snapshot.1.0.0.zip",{"slug":89,"name":90,"version":91,"author":92,"author_profile":93,"description":94,"short_description":95,"active_installs":96,"downloaded":97,"rating":98,"num_ratings":99,"last_updated":100,"tested_up_to":14,"requires_at_least":15,"requires_php":101,"tags":102,"homepage":107,"download_link":108,"security_score":109,"vuln_count":110,"unpatched_count":11,"last_vuln_date":111,"fetched_at":27},"aryo-activity-log","Activity Log – Monitor & Record User Changes","2.11.2","Elementor","https:\u002F\u002Fprofiles.wordpress.org\u002Felemntor\u002F","\u003Cp>\u003Cstrong>AN EASY TO USE & FULLY SUPPORTED WORDPRESS ACTIVITY LOG PLUGIN\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Want to monitor and track your WordPress website activity? Find out exactly who does what on your WordPress website with this plugin. Activity Log is like an airplane’s black box that logs every action in the WordPress admin, and lets you see exactly what users are doing on your WordPress website.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>If someone is trying to hack your site\u003C\u002Fli>\n\u003Cli>When a post was published, and who published it\u003C\u002Fli>\n\u003Cli>If a plugin\u002Ftheme was activated\u002Fdeactivated\u003C\u002Fli>\n\u003Cli>Suspicious admin activity\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>It’s so essential; you’ll wonder how you ever managed your website without it. The plugin is also lightning fast and works behind the scenes, so it doesn\\’t affect site and admin performance. For optimal performance, we built the plugin so that it runs on a separate table in the database.\u003C\u002Fp>\n\u003Cp>If you have more than a handful of users, keeping track of who did what is virtually impossible. This plugin solves that issue by tracking what actions were initiated by which users, and displaying it in an easy-to-use and easy-to-filter view on the dashboard of your WordPress site.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>New! Introducing Email Logging\u003C\u002Fstrong> – Capture all emails sent from your WordPress site for streamlined debugging and compliance. Gain better visibility into email communication, aiding both troubleshooting and record-keeping. This is particularly beneficial for WooCommerce stores, allowing you to easily track sent emails alongside other critical site events.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Export to CSV\u003C\u002Fstrong> – Export your Activity Log data records to CSV. Developers can easily add support for custom data formats with our new dedicated Export API.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Data Privacy and GDPR Compliance\u003C\u002Fstrong> – We provide the tools to help you adhere to GDPR compliance standards, including Export\u002FErasure of data via the WordPress Privacy Tools.\u003C\u002Fp>\n\u003Ch3>With the Activity Log you can record:\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>WordPress\u003C\u002Fstrong> – Core updates\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Posts\u003C\u002Fstrong> – Created, updated, deleted\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Pages\u003C\u002Fstrong> – Created, updated, deleted\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom Post Type\u003C\u002Fstrong> – Created, updated, deleted\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Tags\u003C\u002Fstrong> – Created, updated, deleted\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Categories\u003C\u002Fstrong> – Created, updated, deleted\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Taxonomies\u003C\u002Fstrong> – Created, updated, deleted\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Menus\u003C\u002Fstrong> – Created, updated, deleted\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Media\u003C\u002Fstrong> – Created, updated, deleted\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Comments\u003C\u002Fstrong> – Created, approved, unapproved, trashed, untrashed, spammed, unspammed, deleted\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Users\u003C\u002Fstrong> – Login, logout, login failed, update profile, registered, deleted\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Plugins\u003C\u002Fstrong> – Installed, updated, activated, deactivated, changed\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Themes\u003C\u002Fstrong> – Installed, updated, deleted, activated, changed (Editor and Customizer)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Widgets\u003C\u002Fstrong> – Added to sidebar, deleted from sidebar, order widgets\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Setting\u003C\u002Fstrong> – General, writing, reading, discussion, media, permalinks\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Options\u003C\u002Fstrong> – Extended custom settings for 3rd party plugins\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Export\u003C\u002Fstrong> – Exported activity log file\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WooCommerce\u003C\u002Fstrong> – Track products, orders, customers, and more\u003C\u002Fli>\n\u003Cli>\u003Cstrong>bbPress\u003C\u002Fstrong> – Forums, topics, replies, taxonomies, and other actions\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Emails sent from WordPress site\u003C\u002Fstrong> – Sending successful, sending failed\u003C\u002Fli>\n\u003Cli>There’s more, of course, but you get the point…\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>For each event recorded by the activity log, the following details are also logged:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Date and time of occurrence\u003C\u002Fli>\n\u003Cli>User and user role responsible for the change\u003C\u002Fli>\n\u003Cli>Source IP address from which the change originated\u003C\u002Fli>\n\u003Cli>Affected object where the change occurred\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>The plugin doesn\\’t require any kind of setup; it works right out of the box (just another reason people love it)!\u003C\u002Fp>\n\u003Ch3>Data Storage and Performance Optimization\u003C\u002Fh3>\n\u003Cp>In order to ensure optimal performance of your website, all events and logs data are stored in a dedicated custom table within your WordPress database. This approach significantly reduces the impact on your website’s performance, ensuring seamless operation even during peak traffic periods.\u003C\u002Fp>\n\u003Ch3>Uninstall Clean-up\u003C\u002Fh3>\n\u003Cp>We understand the importance of maintaining a clean and efficient database environment. That’s why our plugin features an uninstall hook that seamlessly removes all traces of its presence from your website when uninstalling. This meticulous clean-up process ensures that your database remains lean and clutter-free even after our plugin has been removed.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>With our optimized data storage, thorough logging, and meticulous clean-up process, you can trust that our plugin will enhance the functionality and security of your WordPress site without compromising its performance.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Ch3>What users have to say\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cem>“Its tools, particularly for data privacy and GDPR compliance, make it indispensable for websites operating within European Union boundaries or dealing with EU citizens’ data”\u003C\u002Fem> – \u003Ca href=\"https:\u002F\u002Fblog.hubspot.com\u002Fwebsite\u002F8-best-plugins-tracking-user-activity-wordpress\" rel=\"nofollow ugc\">HubSpot.com\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cem>“If you’re after a competent WP security audit log plugin with all the basic features you need, Activity Log is it!”\u003C\u002Fem> – \u003Ca href=\"https:\u002F\u002Fwpastra.com\u002Fplugins\u002Fwordpress-activity-log-plugins\u002F\" rel=\"nofollow ugc\">WPAstra.com\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cem>“Activity Log features a remarkably straightforward dashboard interface, providing administrators with an at-a-glance understanding of site interactions”\u003C\u002Fem> – \u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Fwordpress-activity-log\u002F\" rel=\"nofollow ugc\">Malcare.com\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cem>“Best 10 Free WordPress Plugins of the Month: Keeping tabs on what your users do with their access to the Dashboard”\u003C\u002Fem> – \u003Ca href=\"https:\u002F\u002Fmanagewp.com\u002Fbest-free-wordpress-plugins-july-2014\" rel=\"nofollow ugc\">ManageWP.com\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cem>“Thanks to this step, we’ve discovered that our site was undergoing a brute force attack”\u003C\u002Fem> – \u003Ca href=\"https:\u002F\u002Fartdriver.com\u002Fblog\u002Fwordpress-site-hacked-solution-time\" rel=\"nofollow ugc\">Artdriver.com\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cem>“Optimized code – The plugin itself is blazing fast and leaves almost no footprint on the server”\u003C\u002Fem> – \u003Ca href=\"https:\u002F\u002Fwww.freshtechtips.com\u002F2014\u002F01\u002Fbest-audit-trail-plugins-for-wordpress.html\" rel=\"nofollow ugc\">FreshTechTips.com\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cem>“Activity Log lets you track a huge range of activities. Overall, very easy to use and setup”\u003C\u002Fem> – \u003Ca href=\"https:\u002F\u002Fwww.elegantthemes.com\u002Fblog\u002Ftips-tricks\u002F5-best-ways-to-monitor-wordpress-activity-via-the-dashboard\" rel=\"nofollow ugc\">ElegantThemes.com\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Contributions:\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>Would you like to contribute to this plugin?\u003C\u002Fstrong> You’re more than welcome to submit your pull requests on the \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fpojome\u002Factivity-log\" rel=\"nofollow ugc\">GitHub repo\u003C\u002Fa>. And, if you have any notes about the code, please open a ticket on the issue tracker.\u003C\u002Fp>\n","This top rated Activity Log plugin helps you monitor & log all changes and actions on your WordPress site, so you can remain secure and organized.",200000,4041821,86,74,"2026-06-07T11:49:00.000Z","7.0",[103,104,105,21,106],"activity-log","audit-log","email-log","user-log","https:\u002F\u002Factivitylog.io\u002F?utm_source=wp-plugins&utm_campaign=plugin-uri&utm_medium=wp-dash","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Faryo-activity-log.2.11.2.zip",93,9,"2024-11-20 17:10:23",{"slug":113,"name":114,"version":115,"author":116,"author_profile":117,"description":118,"short_description":119,"active_installs":120,"downloaded":121,"rating":98,"num_ratings":35,"last_updated":122,"tested_up_to":14,"requires_at_least":123,"requires_php":124,"tags":125,"homepage":128,"download_link":129,"security_score":109,"vuln_count":130,"unpatched_count":11,"last_vuln_date":131,"fetched_at":27},"stream","Stream – Activity Log & Audit Trail","4.3.0","XWP","https:\u002F\u002Fprofiles.wordpress.org\u002Fxwp\u002F","\u003Cp>Stream is a complete activity log and audit trail for your WordPress site: see what changed, who changed it, and when. From plugin activations to post edits, login attempts to new user creation, every user and system action is recorded in an audit log built for debugging, security monitoring, and compliance.\u003C\u002Fp>\n\u003Cp>Every logged action is displayed in an activity stream and organized for easy filtering by User, Role, Context, Action or IP address. Admins can highlight entries in the activity log—such as suspicious user activity—to investigate what’s happening in real time. Stream also lets you configure email alerts and webhooks for integrations like Slack and IFTTT, so your team knows the moment something goes wrong.\u003C\u002Fp>\n\u003Cp>Stream keeps its own logs healthy too: records are automatically purged on the retention schedule you choose, with batched deletion and orphaned-data cleanup that stay reliable even on very large sites.\u003C\u002Fp>\n\u003Cp>Stream is also AI-ready: its abilities are exposed through the WordPress Abilities API and MCP Adapter, so AI assistants and other tools can securely query your site’s activity records.\u003C\u002Fp>\n\u003Cp>For advanced users, Stream supports a network view of all activity records on your Multisite, exclude rules to ignore certain kinds of user activity, and a WP-CLI command for querying records.\u003C\u002Fp>\n\u003Cp>Stream is free and fully open source — development happens in the open \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fxwp\u002Fstream\" rel=\"nofollow ugc\">on GitHub\u003C\u002Fa>, maintained by \u003Ca href=\"https:\u002F\u002Fxwp.co\" rel=\"nofollow ugc\">XWP\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>With Stream’s powerful activity logging, you’ll have the information you need to responsibly manage your WordPress sites.\u003C\u002Fp>\n\u003Ch4>Built-In Tracking Integrations For Popular Plugins:\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Advanced Custom Fields\u003C\u002Fli>\n\u003Cli>bbPress\u003C\u002Fli>\n\u003Cli>BuddyPress\u003C\u002Fli>\n\u003Cli>Easy Digital Downloads\u003C\u002Fli>\n\u003Cli>Gravity Forms\u003C\u002Fli>\n\u003Cli>Jetpack\u003C\u002Fli>\n\u003Cli>Two Factor\u003C\u002Fli>\n\u003Cli>User Switching\u003C\u002Fli>\n\u003Cli>WooCommerce\u003C\u002Fli>\n\u003Cli>Yoast SEO\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Built-In Tracking For Core Actions:\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Posts\u003C\u002Fli>\n\u003Cli>Pages\u003C\u002Fli>\n\u003Cli>Custom Post Types\u003C\u002Fli>\n\u003Cli>Users\u003C\u002Fli>\n\u003Cli>Themes\u003C\u002Fli>\n\u003Cli>Plugins\u003C\u002Fli>\n\u003Cli>Tags\u003C\u002Fli>\n\u003Cli>Categories\u003C\u002Fli>\n\u003Cli>Custom Taxonomies\u003C\u002Fli>\n\u003Cli>Settings\u003C\u002Fli>\n\u003Cli>Custom Backgrounds\u003C\u002Fli>\n\u003Cli>Custom Headers\u003C\u002Fli>\n\u003Cli>Menus\u003C\u002Fli>\n\u003Cli>Media Library\u003C\u002Fli>\n\u003Cli>Widgets\u003C\u002Fli>\n\u003Cli>Comments\u003C\u002Fli>\n\u003Cli>Theme Editor\u003C\u002Fli>\n\u003Cli>WordPress Core Updates\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Other Noteworthy Features:\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Multisite view of all activity records on a network\u003C\u002Fli>\n\u003Cli>Limit who can view user activity records by user role\u003C\u002Fli>\n\u003Cli>Set exclude rules to ignore certain kinds of user activity\u003C\u002Fli>\n\u003Cli>Live updates of user activity records in the Stream\u003C\u002Fli>\n\u003Cli>Export your Activity Stream as a CSV or JSON file\u003C\u002Fli>\n\u003Cli>WP-CLI command for querying records\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Configuration\u003C\u002Fh3>\n\u003Cp>Most of the plugin configuration is available under the “Stream” \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> “Settings” page in the WordPress dashboard.\u003C\u002Fp>\n\u003Ch4>Request IP Address\u003C\u002Fh4>\n\u003Cp>The plugin expects the \u003Ccode>$_SERVER['REMOTE_ADDR']\u003C\u002Fcode> variable to contain the verified IP address of the current request. On hosting environments with PHP processing behind reverse proxies or CDNs the actual client IP is passed to PHP through request HTTP headers such as \u003Ccode>X-Forwarded-For\u003C\u002Fcode> and \u003Ccode>True-Client-IP\u003C\u002Fcode> which can’t be trusted without an additional layer of validation. Update your server configuration to set the \u003Ccode>$_SERVER['REMOTE_ADDR']\u003C\u002Fcode> variable to the verified client IP address.\u003C\u002Fp>\n\u003Cp>As a workaround, you can use the \u003Ccode>wp_stream_client_ip_address\u003C\u002Fcode> filter to adapt the IP address:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>add_filter(\n    'wp_stream_client_ip_address',\n    function( $client_ip ) {\n        \u002F\u002F Trust the first IP in the X-Forwarded-For header.\n        \u002F\u002F ⚠️ Note: This is inherently insecure and can easily be spoofed!\n        if ( ! empty( $_SERVER['HTTP_X_FORWARDED_FOR'] ) ) {\n            $forwarded_ips = explode( ',' $_SERVER['HTTP_X_FORWARDED_FOR'] );\n\n            if ( filter_var( $forwarded_ips[0], FILTER_VALIDATE_IP ) ) {\n                return $forwarded_ips[0];\n            }\n        }\n\n        return $client_ip;\n    }\n);\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>⚠️ \u003Cstrong>WARNING:\u003C\u002Fstrong> The above is an insecure workaround that you should only use when you fully understand what this implies. Relying on any variable with the \u003Ccode>HTTP_*\u003C\u002Fcode> prefix is prone to spoofing and cannot be trusted!\u003C\u002Fp>\n\u003Ch3>Known Issues\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>We have temporarily disabled the data removal feature through plugin uninstallation, starting with version 3.9.3. We identified a few edge cases that did not behave as expected and we decided that a temporary removal is preferable at this time for such an impactful and irreversible operation. Our team is actively working on refining this feature to ensure it performs optimally and securely. We plan to reintroduce it in a future update with enhanced safeguards.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Contribute\u003C\u002Fh3>\n\u003Cp>There are several ways you can get involved to help make Stream better:\u003C\u002Fp>\n\u003Col>\n\u003Cli>\n\u003Cp>\u003Cstrong>Report Bugs:\u003C\u002Fstrong> If you find a bug, error or other problem, please report it! You can do this by \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Fplugin\u002Fstream\" rel=\"ugc\">creating a new topic\u003C\u002Fa> in the plugin forum. Once a developer can verify the bug by reproducing it, they will create an official bug report in GitHub where the bug will be worked on.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Translate into Your Language:\u003C\u002Fstrong> Use the official plugin translation tool to \u003Ca href=\"https:\u002F\u002Ftranslate.wordpress.org\u002Fprojects\u002Fwp-plugins\u002Fstream\u002F\" rel=\"nofollow ugc\">translate Stream into your language\u003C\u002Fa>.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Suggest New Features:\u003C\u002Fstrong> Have an awesome idea? Please share it! Simply \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Fplugin\u002Fstream\" rel=\"ugc\">create a new topic\u003C\u002Fa> in the plugin forum to express your thoughts on why the feature should be included and get a discussion going around your idea.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Issue Pull Requests:\u003C\u002Fstrong> If you’re a developer, the easiest way to get involved is to help out on \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fx-team\u002Fwp-stream\u002Fissues\" rel=\"nofollow ugc\">issues already reported\u003C\u002Fa> in GitHub. Be sure to check out the \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fx-team\u002Fwp-stream\u002Fblob\u002Fmaster\u002Fcontributing.md\" rel=\"nofollow ugc\">contributing guide\u003C\u002Fa> for developers.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>Thank you for wanting to make Stream better for everyone!\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fxwp\u002Fstream\u002Fgraphs\u002Fcontributors\" rel=\"nofollow ugc\">View contributors here.\u003C\u002Fa>\u003C\u002Fp>\n","Real-time activity log and audit log for WordPress. Track every user action — logins, edits, plugin & settings changes — and get alerts.",80000,2379425,"2026-07-22T05:04:00.000Z","4.6","",[103,104,126,21,127],"event-log","user-tracking","https:\u002F\u002Fxwp.co\u002Fwork\u002Fstream\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fstream.4.3.0.zip",7,"2025-02-14 00:00:00",{"error":133,"url":134,"statusCode":135,"statusMessage":136,"message":136},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fvideowhisper-security-audit\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":138,"versions":139},1,[140],{"version":141,"download_url":142,"svn_tag_url":143,"released_at":26,"has_diff":144,"diff_files_changed":145,"diff_lines":26,"trac_diff_url":26,"vulnerabilities":146,"is_current":144},"0.1.0","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fvideowhisper-security-audit.0.1.0.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fvideowhisper-security-audit\u002Ftags\u002F0.1.0\u002F",false,[],[]]