Who Changed It/Compare/Simple History
Simple History is one of the best-loved plugins in the category: readable, zero-configuration and developer-friendly. Who Changed It takes a different angle, grading every event and chaining the log so it can be trusted later. Here is where each one fits.
Checked against Simple History's WordPress.org listing and Who Changed It 0.9.0 on 25 September 2026. Plugins change; if something here is out of date, tell us.
| Simple Historyby Pär Thernström | Who Changed It | |
|---|---|---|
| Active installs | 300,000+ | About 90 active installs — first released August 2026 |
| What it records | Posts and custom post types, attachments (including image edits), taxonomies, comments, menus, widgets, users, logins, plugins, themes, core and translation updates, settings, Site Health, privacy requests. Built-in support for ACF, Jetpack, Redirection, WP Crontrol, Beaver Builder and others. | 49 event types in ten families: logins, users and roles, content and media, plugins, themes, core and the file editor, a curated list of sensitive settings, WooCommerce, and Yoast SEO / ACF / Elementor. No comments, menus, widgets or taxonomies yet. |
| Reading the log | Written as plain sentences (“Updated page ‘About us’”) with before/after comparisons, a dashboard widget, an admin-bar dropdown and a command-palette entry. | Every event is graded normal, strange or dangerous, then escalated by context — a login at 03:00, an IP never seen for that user, five failed logins from one IP, a burst of deletions — with the reason written on the row. |
| Security checks | Core file integrity checks against WordPress.org's official checksums; failed logins split by wrong password and unknown username. | No file scanning: changes made by editing files over FTP or SSH bypass WordPress and are not seen. Use of the built-in theme and plugin file editor is always logged as dangerous. |
| Tamper evidence | Not described on its listing. The premium edition can forward events to syslog, Datadog, Splunk or webhooks, which keeps a copy off the server. | Hash-chained records (HMAC-SHA256). Editing or deleting a row outside the plugin shows up on verification; retention purges and GDPR erasure leave a recorded, verifiable gap. |
| Notifications | Free: a weekly email report. Instant alerts by email, Slack, Discord or Telegram are in the premium edition. | Free: immediate email on dangerous events, plus native Slack, Discord and Telegram forwarding, and an optional daily or weekly digest. |
| Developer access | WP-CLI commands, a REST API, a password-protected RSS feed and a logging API for your own events. | One action and eight filters. No REST API or WP-CLI commands, and no record of whether a change came from WP-CLI, REST or cron (such changes show as “no user”). |
| Privacy | IP addresses anonymised by default; logs privacy exports and erasure requests. | Four IP modes (full, masked, hashed, dropped), retention per event family, WordPress personal-data export and erasure (erasure redacts, so the chain still verifies). |
Simple History's great strength is that people actually read it. Events are written as sentences, timestamps are relative, and changes are shown as before/after comparisons rather than raw data. It needs no configuration, and it imports recent activity on install, so the log is not empty on day one. Its coverage of the everyday admin surface — comments, menus, widgets, taxonomies, media edits — is wide.
It is also the most developer-friendly plugin here: WP-CLI, a REST API, an RSS feed and a one-line logging API. And it does something no activity log strictly has to: core file integrity checks against WordPress.org's checksums, which catch the file tampering that a hook-based log cannot see. It has been actively developed for over a decade.
Simple History tells you what happened; Who Changed It also tells you which of it is odd. Every event is graded normal, strange or dangerous, and escalated by context — odd hours, an IP address new for that particular user, brute-force bursts, a run of deletions — with the reason stored on the row. Dangerous events alert you straight away in the free plugin, by email or natively in Slack, Discord or Telegram.
The second difference is what happens when someone wants to rewrite history. Who Changed It hash-chains every record, so deleting or editing rows in the database is detected, and its CSV and JSON exports are signed so a third party can check them without WordPress. If you might one day hand the log to a client, a host or an insurer, that is the point of it.
Not sure? Try the live demo on the homepage, which runs the plugin's timeline on sample data, or read how events are classified.