WP Manifestindependent plugin directory
manifest / security / wp-admin-action-logger

Admin Action Logger

Logs administrative actions (logins, content saves, plugin/form/snippet changes) to a plain-text log file.

by Torwald45 · github.com/synchronicity-one/wp-admin-action-logger

★ 0stars
0forks

Install

No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:

wp plugin install https://github.com/synchronicity-one/wp-admin-action-logger/archive/refs/heads/main.zip

A lightweight WP must-use plugin that logs administrative actions to a plain-text file. Useful for tracking who logs in, from which IP, and what administrative changes are made on a site.

What it logs

  • Logins: successful logins, failed login attempts, logouts
  • Content: post/page saves (including custom post types)
  • Optional integrations (only active when the corresponding plugin is installed):
    • Code Snippets: snippet create/update, activate, deactivate
    • Formidable Forms: form definition updates (not form submissions)
    • Oxygen Builder: template saves (via the standard save_post hook)

Each log line records: timestamp, action type, WP login, and the real client IP.

Real client IP

The plugin resolves the real client IP in this order:

  1. CF-Connecting-IP (sites behind Cloudflare proxy)
  2. X-Forwarded-For (sites behind a reverse proxy, DNS-only)
  3. REMOTE_ADDR (direct connection)

Installation

As a must-use plugin, copy the file into your wp-content/mu-plugins/ directory:

wp-content/mu-plugins/admin-action-logger.php

Must-use plugins load automatically and cannot be deactivated from the admin panel.

Log file location

By default the log is written to /var/www/logs/wp-auth.log. Override it by defining a constant in wp-config.php before the plugin loads:

define('TORWALD45_ALOG_FILE', '/path/to/your/wp-auth.log');

The web server user (for example uid 82 in common Docker images) must have write permission to the target file.

Log format

[04/Jul/2026:10:05:42 +0000] LOGIN_OK user=admin ip=203.0.113.10 login=admin

Action types: LOGIN_OK, LOGIN_FAIL, LOGOUT, POST_SAVE, SNIPPET_UPDATE, SNIPPET_ACTIVATE, SNIPPET_DEACTIVATE, FORM_UPDATE.

Log rotation

The plugin appends to a single file. Use logrotate with copytruncate to rotate it, for example monthly with 12 kept copies.

License

GPL-2.0-or-later. See LICENSE.