Who Changed It/Compare/Stream

Who Changed It vs Stream

Stream is XWP's free, fully open-source audit trail, with alerts, webhooks and a multisite network view built in. Who Changed It grades every event and chains the log for evidence. Both are free, so the question is which one fits the way you work.

Checked against Stream's WordPress.org listing and Who Changed It 0.9.0 on 25 September 2026. Plugins change; if something here is out of date, tell us.

At a glance

Streamby XWPWho Changed It
Active installs70,000+About 90 active installs — first released August 2026
What it recordsPosts, pages, custom post types, users, themes, plugins, taxonomies, settings, menus, media, widgets, comments, the theme editor and core updates. Integrations: ACF, bbPress, BuddyPress, Easy Digital Downloads, Gravity Forms, Jetpack, Two Factor, User Switching, WooCommerce and Yoast SEO.49 event types in ten families: logins, users and roles, content and media, plugins, themes, core and the file editor, a curated list of sensitive settings, WooCommerce, and Yoast SEO / ACF / Elementor. No comments, menus, widgets or taxonomies yet.
Flagging what mattersEntries can be filtered by user, role, context, action or IP, and admins can highlight suspicious entries by hand.Every event is graded normal, strange or dangerous, then escalated by context — a login at 03:00, an IP never seen for that user, five failed logins from one IP, a burst of deletions — with the reason written on the row.
NotificationsFree: email alerts and webhooks (for Slack, IFTTT and others), configured in its settings.Free: immediate email on dangerous events, plus native Slack, Discord and Telegram forwarding, and an optional daily or weekly digest.
ExportCSV or JSON.Signed CSV and JSON evidence export with a manifest stating the filter used.
Tamper evidenceNot described on its listing.Hash-chained records (HMAC-SHA256). Editing or deleting a row outside the plugin shows up on verification; retention purges and GDPR erasure leave a recorded, verifiable gap.
MultisiteYes, with a network view of all activity.Not supported.
Developer accessWP-CLI command for querying records; its abilities are exposed through the WordPress Abilities API and MCP Adapter; developed in the open on GitHub.One action and eight filters. No REST API or WP-CLI commands, and no record of whether a change came from WP-CLI, REST or cron (such changes show as “no user”).

Where Stream is strong

Stream is free in the full sense: no premium tier, open source, developed in public on GitHub by an agency that builds large WordPress sites. It covers the core admin surface broadly, including comments, menus, widgets and taxonomies, and it integrates with a solid list of plugins from WooCommerce and Yoast to BuddyPress and Easy Digital Downloads.

It is also the most configurable of the free options: email alerts and webhooks that can reach Slack, IFTTT or anything else that accepts a POST, exclude rules to ignore noise, a multisite network view, WP-CLI access, and exposure through the WordPress Abilities API and MCP Adapter so AI tools can query the log.

Where Who Changed It is different

Stream gives you the tools to build your own alerting: you decide which contexts and actions notify whom. Who Changed It ships with the judgement built in. Every event is graded normal, strange or dangerous, context escalates it (odd hours, an IP new for that user, brute-force bursts, deletion runs), and the reason is written on the row. You still choose where alerts go and how high the bar is, but you don't start from a blank rule list.

The other difference is evidence. Who Changed It hash-chains every record and signs its CSV and JSON exports with a manifest of the filter that produced them, so a deleted row or an edited export can be detected later. Retention can be set per event family, and IP addresses can be stored in full, masked, hashed or not at all.

Which one fits you

Choose Stream if…

  • you want fully open-source software with public development;
  • you want webhooks and rule-based alerts you design yourself;
  • you run multisite or need a WP-CLI command for querying records;
  • you need comments, menus, widgets, taxonomies, BuddyPress or EDD in the log.

Choose Who Changed It if…

  • you want unusual events flagged with a reason without writing rules first;
  • you want native Slack, Discord and Telegram forwarding and a daily or weekly digest;
  • the log may need to stand up as tamper-evident evidence;
  • you want IP privacy modes and retention per event family.

Get it free on WordPress.org →

Not sure? Try the live demo on the homepage, which runs the plugin's timeline on sample data, or read how events are classified.

Common questions

Is Stream really free?
Yes. Stream has no paid edition listed on WordPress.org and is developed as open source on GitHub. Who Changed It is free too, so the choice between them is about fit, not cost.
Does Who Changed It support webhooks like Stream?
Not general webhooks. It forwards flagged events natively to Slack, Discord and Telegram and sends email alerts and an optional digest. If you need to POST events to an arbitrary endpoint, Stream's webhooks are the better fit.
Can Stream's log be verified as untouched?
Its WordPress.org listing does not describe tamper detection. Who Changed It chains every record with an HMAC, so deleting or editing rows outside the plugin shows up as broken links on verification.
Can I migrate my Stream history?
No. Who Changed It has no importer. Run both side by side for your retention period, or export Stream's log to CSV or JSON before removing it.