Who Changed It? — WordPress Security Plugin
Who Changed It? – Activity Log & Audit Trail
by Guido Schad · WordPress.org page · Website
Who Changed It? has 60+ active installs on WordPress.org and 354 downloads all time. We have tracked it since September 4, 2026; download trends appear after 30 days of data. The last update was on August 12, 2026, tested up to WordPress 7.0.4.
Who Changed It? at a glance
Is Who Changed It? well maintained?
Features
The feature list from the plugin's own readme on WordPress.org, trimmed to the essentials.
- Color-coded log screen with severity icons and per-severity count chips, free-text search, and filters for severity, event family, event type, user and date…
- Field-level change diffs shown inline: see exactly what changed in a post, a profile, or a setting
- Immediate email alerts for dangerous events, throttled so a brute-force attack sends one email, not hundreds
- A weekly or daily digest. One email covering the period: totals by severity, every flagged event with the reason it was flagged, the most frequent event types…
- Append-only and hash-chained. Each record hashes the one before it. Deleted or altered rows are detected and flagged on the log screen
- Stays on your server. No telemetry, no third-party log store. The only thing that ever leaves your site is a notification you switched on yourself
- Alerts where you already work. Forward flagged events to email, Slack, Discord or Telegram. Every channel is off until you paste in a destination, and a burst…
- Retention and redaction. Per-family retention windows; mask, hash, or drop IP addresses; redact personal data to satisfy GDPR requests without breaking the…
- Scoped access. Reading the log is its own capability. Even administrators can be excluded from it
- Evidence you can hand over. Export a signed, time-bounded record set as CSV or JSON for auditors and incident reports
- Answers WordPress’s own Export/Erase Personal Data tools
- Mute individual event types to keep the log signal-heavy (events about the plugin itself can never be muted)
Who Changed It? reviews and ratings
3 reviews on WordPress.org, with the most recent ones as their authors posted them.
3 reviews
- 5★
-
3
- 4★
-
0
- 3★
-
0
- 2★
-
0
- 1★
-
0
-
Excellent Trailing and Auditing Plugin, small and fast
Excellent Trailing and Wordpress Auditing Plugin, small and fast - you see immediately who did what and when and best you can export it for free.
ttpainos -
Excellent acitivty log for wordpress
Excellent alternative for the big oversized wordpress activity log plugins, small, lightweight but does everything you need - plus you can export the log any time and the support answered me within minutes. 10/10.
jervais -
Finally, an activity log that doesn't slow things down
Who Changed it plugin does exactly what it promises - a lightweight, field-level activity log that actually tells you what changed and who did it, not just that something did. The before/after diffs on posts and settings are a huge time-saver, and having every event automatically flagged as normal, unusual, or dangerous makes it easy to spot suspicious activity. Very nice that CSV/JSON export isn't locked behind a premium tier. Setup was genuinely just activate-and-go, no config headaches. Highly recommended!
michaelseri
Details
Activity log and audit trail: see who changed what, and when — logins, users, plugins, themes, posts, settings. Tamper-proof. Stays on your site.
The full description, screenshots and every review live on the WordPress.org page.
Rankings Who Changed It? competes in
Tags
- Activity Log
- audit log
- audit trail
- security
- user activity
More from Guido Schad
-
Lockora Security Audit 200+ installs -
WPSecureOps Connector 60+ installs
- Version
- 0.9.0
- Last updated
- Aug 12, 2026
- First published
- Aug 4, 2026
- Requires WordPress
- 6.0
- Tested up to
- 7.0.4
- Requires PHP
- 7.4
- Pricing
- Free on WordPress.org
Who Changed It? FAQ
What does Who Changed It? do?
According to its WordPress.org readme, Who Changed It? offers Color-coded log screen with severity icons and per-severity count chips, free-text search, and filters for severity, event family, event type, user and date, Field-level change diffs shown inline: see exactly what changed in a post, a profile, or a setting, Immediate email alerts for dangerous events, throttled so a brute-force attack sends one email, not hundreds, A weekly or daily digest. One email covering the period: totals by severity, every flagged event with the reason it was flagged, the most frequent event types and Append-only and hash-chained. Each record hashes the one before it. Deleted or altered rows are detected and flagged on the log screen.
How many active installs does Who Changed It? have?
WordPress.org reports 60+ active installs for Who Changed It? as of September 7, 2026.
Is Who Changed It? still maintained?
Yes. The last release was on August 12, 2026 and it is tested up to WordPress 7.0.4.
Is Who Changed It? free?
Who Changed It? is free to install from WordPress.org. Many plugins also sell a paid version or add-ons.