Who Changed It/Compare/Stream
Stream is XWP's free, fully open-source audit trail, with alerts, webhooks and a multisite network view built in. Who Changed It grades every event and chains the log for evidence. Both are free, so the question is which one fits the way you work.
Checked against Stream's WordPress.org listing and Who Changed It 0.9.0 on 25 September 2026. Plugins change; if something here is out of date, tell us.
| Streamby XWP | Who Changed It | |
|---|---|---|
| Active installs | 70,000+ | About 90 active installs — first released August 2026 |
| What it records | Posts, pages, custom post types, users, themes, plugins, taxonomies, settings, menus, media, widgets, comments, the theme editor and core updates. Integrations: ACF, bbPress, BuddyPress, Easy Digital Downloads, Gravity Forms, Jetpack, Two Factor, User Switching, WooCommerce and Yoast SEO. | 49 event types in ten families: logins, users and roles, content and media, plugins, themes, core and the file editor, a curated list of sensitive settings, WooCommerce, and Yoast SEO / ACF / Elementor. No comments, menus, widgets or taxonomies yet. |
| Flagging what matters | Entries can be filtered by user, role, context, action or IP, and admins can highlight suspicious entries by hand. | Every event is graded normal, strange or dangerous, then escalated by context — a login at 03:00, an IP never seen for that user, five failed logins from one IP, a burst of deletions — with the reason written on the row. |
| Notifications | Free: email alerts and webhooks (for Slack, IFTTT and others), configured in its settings. | Free: immediate email on dangerous events, plus native Slack, Discord and Telegram forwarding, and an optional daily or weekly digest. |
| Export | CSV or JSON. | Signed CSV and JSON evidence export with a manifest stating the filter used. |
| Tamper evidence | Not described on its listing. | Hash-chained records (HMAC-SHA256). Editing or deleting a row outside the plugin shows up on verification; retention purges and GDPR erasure leave a recorded, verifiable gap. |
| Multisite | Yes, with a network view of all activity. | Not supported. |
| Developer access | WP-CLI command for querying records; its abilities are exposed through the WordPress Abilities API and MCP Adapter; developed in the open on GitHub. | One action and eight filters. No REST API or WP-CLI commands, and no record of whether a change came from WP-CLI, REST or cron (such changes show as “no user”). |
Stream is free in the full sense: no premium tier, open source, developed in public on GitHub by an agency that builds large WordPress sites. It covers the core admin surface broadly, including comments, menus, widgets and taxonomies, and it integrates with a solid list of plugins from WooCommerce and Yoast to BuddyPress and Easy Digital Downloads.
It is also the most configurable of the free options: email alerts and webhooks that can reach Slack, IFTTT or anything else that accepts a POST, exclude rules to ignore noise, a multisite network view, WP-CLI access, and exposure through the WordPress Abilities API and MCP Adapter so AI tools can query the log.
Stream gives you the tools to build your own alerting: you decide which contexts and actions notify whom. Who Changed It ships with the judgement built in. Every event is graded normal, strange or dangerous, context escalates it (odd hours, an IP new for that user, brute-force bursts, deletion runs), and the reason is written on the row. You still choose where alerts go and how high the bar is, but you don't start from a blank rule list.
The other difference is evidence. Who Changed It hash-chains every record and signs its CSV and JSON exports with a manifest of the filter that produced them, so a deleted row or an edited export can be detected later. Retention can be set per event family, and IP addresses can be stored in full, masked, hashed or not at all.
Not sure? Try the live demo on the homepage, which runs the plugin's timeline on sample data, or read how events are classified.