Who Changed It/Compare/Activity Log
Activity Log, the plugin with the literal name, is a long-running and easy-to-use activity log that now records where every change came from: the admin, the REST API, WP-CLI or cron. Who Changed It focuses on grading events and making the log trustworthy. Here is how they compare.
Checked against Activity Log's WordPress.org listing and Who Changed It 0.9.0 on 25 September 2026. Plugins change; if something here is out of date, tell us.
| Activity Logby activitylog.io | Who Changed It | |
|---|---|---|
| Active installs | 200,000+ | About 90 active installs — first released August 2026 |
| What it records | Core updates, posts, pages, custom post types, taxonomies, menus, media, comments, users, plugins, themes (including the editor and Customizer), widgets, settings, third-party options, WooCommerce, bbPress, and every email the site sends. | 49 event types in ten families: logins, users and roles, content and media, plugins, themes, core and the file editor, a curated list of sensitive settings, WooCommerce, and Yoast SEO / ACF / Elementor. No comments, menus, widgets or taxonomies yet. |
| Where a change came from | Request source on every event: WP Admin, REST API, WP-CLI, WP-Cron, XML-RPC or the Abilities API, including the name of the Application Password used. | Not recorded. Changes with no logged-in user are shown as “no user”, which separates automation from people but not one kind of automation from another. |
| Flagging what matters | Filterable by user, role, source and object. | Every event is graded normal, strange or dangerous, then escalated by context — a login at 03:00, an IP never seen for that user, five failed logins from one IP, a burst of deletions — with the reason written on the row. |
| Tamper evidence | Not described on its listing. | Hash-chained records (HMAC-SHA256). Editing or deleting a row outside the plugin shows up on verification; retention purges and GDPR erasure leave a recorded, verifiable gap. |
| Export | CSV, plus an Export API for your own formats. | Signed CSV and JSON evidence export with a manifest stating the filter used. |
| Privacy | Log data can be exported or erased through WordPress's privacy tools. Uninstalling removes all of its data. | Four IP modes (full, masked, hashed, dropped), retention per event family, WordPress personal-data export and erasure (erasure redacts, so the chain still verifies). |
Activity Log has been a straightforward, set-and-forget activity log for many years, and its recent releases added something genuinely useful: request source tracking. Every event says whether it came through the WordPress admin, the REST API, WP-CLI, WP-Cron, XML-RPC or the Abilities API — and when an Application Password was used, which one. On a site with deploy scripts, integrations and AI agents all making changes, that answers “was it a person or a machine, and which machine?” directly.
It also logs every email the site sends, which is a real help when a WooCommerce order email goes missing, and its coverage of the admin surface — comments, menus, widgets, the Customizer — is broad.
Who Changed It does not record the request source. What it does instead is judge each event: a base severity, escalated by context — a login at an unusual hour, an IP address never seen for that user, repeated failed logins, a burst of deletions — with the reason written on the row. Dangerous events alert you straight away by email, Slack, Discord or Telegram, and a daily or weekly digest reports totals and the state of the log.
That state matters because every record is hash-chained: rows deleted or edited in the database are detected, and exports are signed so they can be checked without WordPress. Privacy is handled at the point of recording too, with four IP storage modes and retention per event family.
Not sure? Try the live demo on the homepage, which runs the plugin's timeline on sample data, or read how events are classified.