Who Changed It/Compare/Activity Log

Who Changed It vs Activity Log

Activity Log, the plugin with the literal name, is a long-running and easy-to-use activity log that now records where every change came from: the admin, the REST API, WP-CLI or cron. Who Changed It focuses on grading events and making the log trustworthy. Here is how they compare.

Checked against Activity Log's WordPress.org listing and Who Changed It 0.9.0 on 25 September 2026. Plugins change; if something here is out of date, tell us.

At a glance

Activity Logby activitylog.ioWho Changed It
Active installs200,000+About 90 active installs — first released August 2026
What it recordsCore updates, posts, pages, custom post types, taxonomies, menus, media, comments, users, plugins, themes (including the editor and Customizer), widgets, settings, third-party options, WooCommerce, bbPress, and every email the site sends.49 event types in ten families: logins, users and roles, content and media, plugins, themes, core and the file editor, a curated list of sensitive settings, WooCommerce, and Yoast SEO / ACF / Elementor. No comments, menus, widgets or taxonomies yet.
Where a change came fromRequest source on every event: WP Admin, REST API, WP-CLI, WP-Cron, XML-RPC or the Abilities API, including the name of the Application Password used.Not recorded. Changes with no logged-in user are shown as “no user”, which separates automation from people but not one kind of automation from another.
Flagging what mattersFilterable by user, role, source and object.Every event is graded normal, strange or dangerous, then escalated by context — a login at 03:00, an IP never seen for that user, five failed logins from one IP, a burst of deletions — with the reason written on the row.
Tamper evidenceNot described on its listing.Hash-chained records (HMAC-SHA256). Editing or deleting a row outside the plugin shows up on verification; retention purges and GDPR erasure leave a recorded, verifiable gap.
ExportCSV, plus an Export API for your own formats.Signed CSV and JSON evidence export with a manifest stating the filter used.
PrivacyLog data can be exported or erased through WordPress's privacy tools. Uninstalling removes all of its data.Four IP modes (full, masked, hashed, dropped), retention per event family, WordPress personal-data export and erasure (erasure redacts, so the chain still verifies).

Where Activity Log is strong

Activity Log has been a straightforward, set-and-forget activity log for many years, and its recent releases added something genuinely useful: request source tracking. Every event says whether it came through the WordPress admin, the REST API, WP-CLI, WP-Cron, XML-RPC or the Abilities API — and when an Application Password was used, which one. On a site with deploy scripts, integrations and AI agents all making changes, that answers “was it a person or a machine, and which machine?” directly.

It also logs every email the site sends, which is a real help when a WooCommerce order email goes missing, and its coverage of the admin surface — comments, menus, widgets, the Customizer — is broad.

Where Who Changed It is different

Who Changed It does not record the request source. What it does instead is judge each event: a base severity, escalated by context — a login at an unusual hour, an IP address never seen for that user, repeated failed logins, a burst of deletions — with the reason written on the row. Dangerous events alert you straight away by email, Slack, Discord or Telegram, and a daily or weekly digest reports totals and the state of the log.

That state matters because every record is hash-chained: rows deleted or edited in the database are detected, and exports are signed so they can be checked without WordPress. Privacy is handled at the point of recording too, with four IP storage modes and retention per event family.

Which one fits you

Choose Activity Log if…

  • you need to know whether a change came from the admin, REST API, WP-CLI or cron, and which Application Password was used;
  • you want outgoing emails logged alongside site changes;
  • you need comments, menus, widgets or Customizer changes in the log;
  • you want an Export API to build your own formats.

Choose Who Changed It if…

  • you want unusual events flagged with a reason and alerts straight away;
  • you want native Slack, Discord and Telegram alerts and a scheduled digest;
  • the log may need to stand up as tamper-evident evidence;
  • you want to control how IP addresses are stored.

Get it free on WordPress.org →

Not sure? Try the live demo on the homepage, which runs the plugin's timeline on sample data, or read how events are classified.

Common questions

Which plugin is “Activity Log”?
The WordPress.org plugin whose slug is aryo-activity-log, now titled “Activity Log – Monitor User and Agent Changes”, with its home page at activitylog.io. It is not WP Activity Log, which is a different plugin by Melapress.
Does Who Changed It show whether a change came from WP-CLI or the REST API?
No. A change made with no logged-in user is recorded as “no user”, which tells you it was automation, but not which kind. If that distinction matters to you, Activity Log's request source tracking answers it directly.
Can I use both?
Yes. They store their logs separately and do not interfere. Running both gives you request sources and email logging from one, grading, alerts and a verifiable chain from the other.