Who Changed It? – Activity Log & Audit Trail
by Guido Schad 5 (4 reviews)

Who Changed It? – Activity Log & Audit Trail

Activity log and audit trail: see who changed what, and when — logins, users, plugins, themes, posts, settings. Tamper-proof. Stays on your site.

Who Changed It? ranks #16,990 among WordPress.org plugins with 90+ active installations, is #1,014 of 4,596 in the Security category, a 5/5 rating from 4 reviews, and was last updated Aug 12, 2026. Data from WordPress.org, refreshed twice daily — see methodology.

Tested up to WP 7.0.6 (Current: 7.1.2)
v0.9.0 Current Version v0.9.0
Updated 1 month ago Last Update on 12 Aug, 2026
Refreshed 7 hours ago Last Refreshed on
#1,014 of 4,596 in Security Top 25% by installs Downloads -45.1% this week
View on WordPress.org
Rank
#16,990
No change
Active Installs
90+
+125%
KW Avg Position
20.8
16.2 better
Downloads
443
+8 today
Support Resolved
0%
No change
Rating
100%
Review 5 out of 5
5 (4 reviews)

Next Milestone 100

Total Progress 10%
90+ 100+
4,510
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 9 more installs to reach 100+

Rank Changes

16,933 17,052 17,172 17,291 17,410 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
16,745 17,271 17,798 18,324 18,850 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
Current #16,990
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

0 10 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
0 10 20 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

5.0
4 reviews
Overall 100%
5
4 (100%)
4
0 (0%)
3
0 (0%)
2
0 (0%)
1
0 (0%)

Frequently Asked Questions

Common questions about Who Changed It? – Activity Log & Audit Trail

Open the Activity Log screen and search for the page title, or filter the event family to "content". Each edit shows the user, the time, the IP address, and a field-level diff of what actually changed — title, slug, excerpt, author, content length, password protection, parent.
Deletions are recorded like any other event, with the user who did it and the name of the thing that was deleted. Filter by the "content" family, or search the title of the missing item. A burst of deletions by one user is escalated to Dangerous automatically.
Filter the log by the "plugins" or "themes" family. Installs, updates, activations, deactivations and deletions are all recorded with the user who performed them. Use of the built-in theme and plugin file editor is classified Dangerous on sight, because that is how a compromised administrator account usually plants code.
Failed logins are recorded with the username tried and the originating IP. A burst of failures from one IP is escalated to Dangerous and triggers an email alert — throttled, so an attack sends you one message rather than hundreds.
It writes one row to its own database table when something happens, and nothing at all on ordinary page views by visitors. There are no external calls to wait on, and retention keeps the table from growing without limit. The reporting and diff work happens on the admin screen, not on the front end.
Three things. Every event is classified as Normal, Strange or Dangerous with a stated reason, so you are not scanning thousands of identical rows. The log is hash-chained, so an attacker who cleans up after themselves is detected instead of trusted. And exports are cryptographically signed, so what you hand an auditor or an insurer can be shown not to have been edited afterwards.
No. It records events as they happen, starting at activation.
3 months by default. Configure the retention window (or keep all data forever) on the settings screen; developers can additionally use the whochita_retention_days filter.
Yes. Events are grouped into families — authentication, users, content, plugins, themes, core, settings, WooCommerce, and a catch-all — and each family can keep the default window, use its own, or keep everything forever.
Yes — override the base severity of any event type with the whochita_base_severity_map filter, and extend the list of audited options with whochita_watched_options.

More plugins by Guido Schad

Sign In / Register

You need to sign in or register to use this feature.