Now you know exactly who, when, and what.
Who Changed It is a free activity log and audit trail plugin for WordPress. It records every action on your site — field-level post diffs, logins, plugin flips, settings and file changes, orders, new users — and classifies every one of them normal, strange or dangerous, with the reason written out. Fast, light, and CSV export is never paywalled. AI-assisted analysis of your log is what we are building next.
This is the plugin's screen, running on sample data. Every row is scored against the actor's own baseline — normal, unusual, dangerous. Filter it, or open a row for the diff and the reasoning. The Ask AI tab previews a feature still in development — everything else here ships today.
Sample data. Your log stays on your server.
Around 90 event types out of the box, grouped into eight families. Third-party plugins can register their own with a single hook.
Free plugin · no feature held hostage
Records are append-only and hash-chained, so tampering is detectable. Retention, redaction and export are yours to configure — nothing leaves your server unless you send it.
Read how the hash chain works →"A client swore they never touched the checkout page. The diff showed the exact block, the exact minute, and the exact person. That conversation lasted eight seconds."
"We replaced a log plugin that added 400ms to every admin page. This one we cannot feel, and it tells us more."
"Our auditor asked for six months of change history in a readable format. Two clicks, one CSV, no upsell screen."
Who Changed It is built and maintained by G. Schad, an independent WordPress and Linux web-server security specialist working as WP Server Guard — nine years of WordPress security audits, malware remediation and server hardening, across more than two hundred engagements.
The plugin exists because incident work kept hitting the same wall. By the time anyone calls, the site itself remembers almost nothing: no record of which plugin was switched off before things broke, which account signed in from where, or what the settings looked like last week. Reconstructing that from backups and access logs is slow, expensive and often inconclusive — so the useful thing is to have been recording all along. That is the whole design brief, and it is why the evidence side of the plugin (hash chain, exports, scoped access) got as much attention as the timeline.
Need the human version — a site audited, a compromise cleaned up, a host hardened? That is what WP Server Guard does. The plugin stays free, self-hosted and unrelated to it either way.