1M Login Tracker
A simple plugin to track user logins for past 30 days. Uses ip-api for general location info. Do not use if you have a large membership system
Install
No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:
wp plugin install https://github.com/psm9640/1m-login-tracker/archive/refs/heads/main.zipA lean WordPress plugin that logs every successful login for the past 30 days and shows who logged in, from what IP address, and their approximate geographic location.
Built to be small, fast, and self-contained — one file, one database table, no dashboards to configure.
Features
- Records every successful login (
wp_loginhook) with user, IP, user agent, and UTC timestamp - Detects the real client IP behind proxies and Cloudflare (
CF-Connecting-IP,X-Forwarded-For,X-Real-IP,REMOTE_ADDR) - Reverse-geolocates the IP via ip-api.com and caches the result per IP for 7 days
- Skips lookups for private/reserved IPs (labelled
Local / Private) - Auto-purges log entries older than 30 days via a daily WP-Cron job
- Admin view under Users → Login Tracker (visible to users with
manage_options)
Installation
- Copy the
1m-login-trackerfolder intowp-content/plugins/. - In the WordPress admin, go to Plugins and activate 1M Login Tracker.
- Visit Users → Login Tracker to view the log.
Activation creates the {prefix}_login_tracker_log table and schedules the daily purge event. Deactivation clears the cron event; the table and stored data are left in place.
Requirements
- WordPress 5.0+
- PHP 7.2+
- Outbound HTTP access to
http://ip-api.com(only if you want location data)
Configuration
There are no settings pages — the plugin is designed to just work. Behavior is controlled by constants at the top of 1m-login-tracker.php:
| Constant | Default | Purpose |
|---|---|---|
LOGIN_TRACKER_RETENTION_DAYS |
30 |
Days of login history to keep before purging |
LOGIN_TRACKER_GEO_CACHE_TTL |
7 * DAY_IN_SECONDS |
How long to cache each IP's geolocation |
Notes on ip-api.com
- The free tier is HTTP-only and rate-limited to 45 requests/minute per source IP.
- Successful lookups are cached for 7 days per IP; failed lookups are cached for 1 hour to prevent retry storms.
- The lookup runs inline during the login request with a 3-second timeout, so a slow/unavailable geolocation service can't hang the login flow.
If you need HTTPS or higher rate limits, ip-api.com offers a paid tier — you'd swap the URL in login_tracker_lookup_location().
Data stored
Table: {prefix}_login_tracker_log
| Column | Type | Notes |
|---|---|---|
id |
BIGINT UNSIGNED |
Primary key |
user_id |
BIGINT UNSIGNED |
WP user ID |
user_login |
VARCHAR(60) |
Username at time of login |
ip_address |
VARCHAR(45) |
IPv4 or IPv6 |
user_agent |
VARCHAR(255) |
Truncated to 255 chars |
location |
VARCHAR(191) |
City, Region, Country — may be empty |
login_time |
DATETIME |
UTC |
Privacy
This plugin stores IP addresses and derived geolocation data about users who log in. Depending on jurisdiction (GDPR, etc.) you may need to disclose this in your site's privacy policy. Data is retained for 30 days, then automatically deleted.
The IP address of each login is transmitted to ip-api.com for geolocation. Review their privacy policy before deploying to production.
License
Released under the GNU General Public License v2.0 or later. See LICENSE for the full text, or https://www.gnu.org/licenses/gpl-2.0.html.
This is the standard license for WordPress plugins — WordPress core itself is GPLv2, and the "or later" clause keeps the plugin compatible with both GPLv2 and GPLv3 codebases.