A WordPress activity log is a timestamped record of every action taken inside your website dashboard — who logged in, what they edited, which plugin was activated or removed, and when. Managing the ongoing website running costs for a South African business means knowing what is happening inside your site in real time, not discovering problems after the fact.
For any SA operation with more than one admin, a WooCommerce store, or client contact data held on site, a proper activity log is not a nice-to-have — it is basic governance, and it belongs in your website maintenance plan from the first day the site goes live.
Most WordPress installations ship without this visibility by default. You get posts, users, and settings — but no native record of who changed what and when. POPIA's security requirements create a legal obligation to demonstrate reasonable safeguards over personal data, and a retained, searchable activity record is one of the clearest ways to show you are meeting it.
This guide covers what an activity log captures, which WordPress audit log plugin fits your specific setup, and what to look for once you are running.
Quick Answer
A wordpress activity log records every user action and system event on your site — logins, content edits, plugin changes, and user role updates — in a searchable, timestamped record. The dominant free option is WP Activity Log by Melapress (300,000+ active installs, 4.7/5 stars), which covers WooCommerce and third-party plugin events out of the box with no additional configuration (standard WooCommerce product types; verify in the log viewer if you use custom post types). For South African businesses handling personal data, the log also provides documented evidence of the technical safeguards POPIA Section 19 requires.
In This Guide
Not Sure What's Happening Inside Your WordPress Site?
Share your admin setup and we will show you exactly which monitoring gaps are leaving you exposed — no obligation, response within 24 hours.
Get a Free Site ReviewWhat a WordPress Activity Log Records
A complete wordpress activity log captures every meaningful event across your site — not just logins, but content modifications, configuration changes, and system-level updates — so you can reconstruct exactly what happened and when. The leading free plugin, WP Activity Log by Melapress (300,000+ active installs, 4.7/5 stars, updated August 2026), tracks more than 300 distinct event types across WordPress core, themes, and popular third-party plugins.
Events fall into five categories:
| Category | Typical Events Logged |
|---|---|
| User activity | Logins, logouts, failed login attempts, password changes, role changes |
| Content changes | Post and page edits, status changes (draft → published), deletions, category updates |
| Plugin and theme | Installations, updates, activations, deactivations, deletions |
| WordPress settings | General settings, permalinks, reading and writing options, widget updates |
| WooCommerce | Product price changes, stock updates, order status edits, coupon changes |
Each event entry carries a timestamp, the username, the user's IP address, and the specific change made. WordPress user activity monitoring at this level means a multi-admin investigation — "who changed the product price?" — that used to take an hour now takes a five-second filter search. If your site sits behind Cloudflare or a similar proxy, enable reverse proxy support under Settings → Advanced so logged IP addresses reflect actual users rather than your proxy server.
Free Tier Coverage Is Broader Than Most Operators Expect
The free version of WP Activity Log includes pre-built sensors for WooCommerce, Gravity Forms, Yoast SEO, Advanced Custom Fields, MemberPress, and LearnDash. Your WooCommerce store's order and product activity is captured automatically for standard WooCommerce product types — no configuration required. If you use custom post types, do a test edit and verify the event appears in the log viewer before relying on it.
Why POPIA Makes Site Audit Trails a Business Requirement
South African businesses that process personal information on their WordPress site are legally required to implement and verify technical safeguards — and a WordPress security audit log is one of the most direct ways to demonstrate those safeguards are in place. POPIA Section 19(2) requires responsible parties to identify reasonably foreseeable risks to personal information, establish and maintain appropriate safeguards against those risks, regularly verify that those safeguards are effectively implemented, and continually update safeguards in response to new risks.
An activity log serves that fourfold obligation in three concrete ways:
- Access visibility: You can show exactly who accessed which part of your dashboard, and when — useful if the Information Regulator ever queries how personal data on your site was handled.
- Incident investigation: If a data security event occurs, a retained log narrows the cause to a specific event, user, and timestamp — rather than "sometime in the last three months."
- Ongoing verification: Regular log reviews demonstrate the active monitoring Section 19 requires, not just a one-time setup that is never revisited.
Log retention and POPIA: The free tier of WP Activity Log retains events for three months by default — configurable in Settings → Log Management. For sites processing significant personal data (contact forms, e-commerce orders, booking systems), extending retention to match your broader data retention policy is prudent. Document your chosen retention period in your privacy policy or internal data processing register. POPIA does not prescribe a specific retention window, but your decision should be deliberate and recorded.
POPIA does not mandate a specific technical standard, but the "appropriate and reasonable" test means being able to demonstrate proactive monitoring. A site with no activity record is harder to defend than one with a configured, reviewed audit trail. For a broader view of how activity logging fits alongside SSL, backups, and access controls, see our guide to website security for South African businesses.
Choosing the Right Plugin for Your SA Business
The right WordPress site monitoring tool depends on your team size, store setup, and compliance obligations — there is no single right answer, and the free options are genuinely capable for most small SA businesses. Use this table to match your situation to the recommended starting point:
| Your Setup | Best Starting Point | Why |
|---|---|---|
| Solo blogger, single admin | Simple History (free, 300,000+ installs) | Zero configuration; starts logging on activation; 4.9/5 stars |
| Small business, 2–5 admins | WP Activity Log — free tier | Deeper event coverage, IP logging, role-change tracking, WooCommerce support |
| WooCommerce store with staff | WP Activity Log — free tier | Built-in WooCommerce sensor captures product, order, and coupon changes without setup |
| Agency managing multiple sites | WP Activity Log — Premium | Multi-site licensing, scheduled email reports, Slack alerts per client site |
| POPIA compliance — database and reporting | WP Activity Log — Premium | External database storage, log mirroring to CloudWatch/Loggly, scheduled email reports |
| POPIA compliance — SIEM integration | WP Activity Log — Enterprise | SIEM ingestion (Splunk, AWS CloudWatch), long-term archiving, priority support |
| WordPress Multisite network | Stream (free, 90,000+ installs) | Free network-wide logging with no licence cost; no setup needed |
For premium licensing on WP Activity Log, visit melapress.com/wordpress-activity-log/pricing for current plan pricing and refund terms — pricing scales by number of sites on an annual subscription.
Good fit: A Johannesburg legal services firm runs WordPress with a contact form collecting client enquiries, two admins, and a POPIA privacy policy on site. They install WP Activity Log (free tier), extend retention to twelve months, and do a five-minute weekly log review. Every form submission handler, admin login, and settings change is logged. If asked to demonstrate POPIA Section 19 compliance, they have a timestamped, searchable record.
Poor fit: A solo content creator installs WP Activity Log Premium for a single-author blog with no client data, no e-commerce, and no third-party integrations. The free tier covers everything their setup needs — the premium licence adds scheduled reports and external database storage that are irrelevant for a single-admin personal blog.
Five Setup Steps for Your New Audit Trail
WordPress site activity tracking takes under ten minutes to configure — most of that time goes into the retention, access, and alert settings rather than the install step itself.
Step 1: Install and Activate
In your WordPress admin: Plugins → Add New → search "WP Activity Log" → Install → Activate. The plugin begins logging immediately on activation — there is no wizard-dependent delay, so you do not lose events during setup. For solo blogs, swap "WP Activity Log" for "Simple History" in the same search.
Step 2: Set Your Retention Period
Navigate to WP Activity Log → Settings → Log Management and configure your retention window. The free default is three months. For POPIA-relevant sites, extend this to match your data retention policy — six to twelve months is standard for professional services and e-commerce businesses. Set a calendar reminder to review the retention setting quarterly.
Step 3: Configure User Role Permissions
Decide which user roles can view the audit log. By default, only administrators see it. If you have a site manager or editor role who handles day-to-day operations, consider granting read-only log access so they can review events without requiring full admin credentials.
Step 4: Enable Alerts for Critical Events (Premium)
On the premium tier, set instant notifications for high-risk events: new administrator account created, existing admin deleted, core security plugin deactivated, or more than five failed login attempts from the same IP. These are the events that need same-day attention. On the free tier, a structured weekly log review is your fallback — schedule it.
Step 5: Test Before You Trust It
Log out, log back in, edit a test post, then open WP Activity Log → Audit Log Viewer. You should see your login event, the post edit, and any auto-save events. An empty log at this point usually means the plugin is conflicting with a server-side caching layer — check your cache exclusion rules and exclude the WP admin entirely.
The One Setting Most SA Sites Miss
Enable reverse proxy support under Settings → Advanced if your site sits behind Cloudflare, a CDN, or a load balancer. Without it, every logged IP address will be your proxy server's IP — which makes IP-based monitoring useless and undermines the forensic value of the log entirely.
Red Flags That Demand Immediate Action
A site audit trail is only useful if someone reviews it — these are the events that warrant immediate investigation, not a scheduled weekly check.
- New administrator account created outside your normal process. If you did not create it, your credentials or a vulnerable plugin may have been compromised. Immediately change all admin passwords and review recent plugin updates.
- Multiple failed login attempts from an unfamiliar IP. A brute-force attempt in progress. Add a login attempt limiter or two-factor authentication; change credentials for the targeted username.
- Security or core plugin deactivated without your instruction. Attackers commonly deactivate security plugins before exploiting a vulnerability. If you did not trigger the deactivation, treat it as a compromise and investigate immediately.
- Settings changes at unusual hours from an unfamiliar location. A modification to your site's general settings at 02:00 by an admin whose IP resolves to a country you do not operate in warrants immediate review.
- Bulk WooCommerce price changes you did not initiate. Legitimate price updates happen one at a time or through a planned import. Unexpected bulk changes are either a plugin error or unauthorised access — both require investigation.
Load-shedding creates a South Africa-specific edge case: a plugin update interrupted mid-process by a power failure can leave your site in an inconsistent state. Your wordpress activity log will show the update started but not completed — exactly the information your uptime monitoring alert cannot provide on its own. This is where the two tools are complementary rather than interchangeable.
Your Five-Minute Weekly Log Review
Once a week: scan for new user registrations you did not initiate, role changes, plugin status changes, any WordPress settings modifications, and login events from unusual locations. WP Activity Log's search and filter tools make this a five-minute task, not an hour-long investigation. Build it into your Monday morning routine alongside checking your scheduled post queue.
Running WordPress for a Client-Facing SA Business?
Tell us about your current setup and we will assess whether your monitoring, hosting, and security configuration match your actual risk level — no obligation, response within 24 hours.
Book a Free AssessmentWhy South African Businesses Choose Growth Pulse Media
Growth Pulse Media is run by Dirk van Greuning, who built and scaled a South African ecommerce business before founding the agency. That background means every recommendation — including how to configure web design deliverables in South Africa for long-term operability — comes from someone who has operated real sites, dealt with real incidents, and knows what breaks under SA conditions.
Activity log configuration is part of every site build handover we do, because a site without monitoring is a site that surprises you at the worst possible moment.
We keep a limited client load so every site we manage gets senior attention, not a junior running through a checklist. All work is executed in-house. If your WordPress build is heading to production and you have not yet addressed monitoring, security safeguards, or POPIA compliance, that is worth a conversation.
Who This Is NOT For
Sites with no personal data and a single admin. A personal portfolio or hobby blog with one author, no contact forms collecting personal information, and no e-commerce has minimal exposure. Simple History (free) covers the basics; a premium audit solution adds cost without proportionate benefit for this setup.
Businesses that will not review the logs. An activity log that nobody checks is not a safeguard — it is a false sense of security. If your team does not have the bandwidth to review logs weekly or configure alert rules, address that operational gap first. The plugin setup is the easy part.
Sites planning an imminent full rebuild. If your WordPress site is being migrated or rebuilt from scratch within the next 60 days, configuring detailed audit trails on the current site is low-value work. Focus instead on the security and monitoring posture of the new build.
Operators expecting a log to prevent incidents. A wordpress activity log is forensic, not preventive. It tells you what happened — it does not stop a brute-force attack, a plugin vulnerability exploit, or a compromised password. Pair it with a login limiter, two-factor authentication, and regular malware scanning for layered protection. The log is evidence; your security configuration is the defence.
Need Your WordPress Site Secured Before It Goes Live?
Send us your current plugin list and we will audit your security and monitoring setup — free, no obligation, within 24 hours.
Request a Free Security AuditFrequently Asked Questions
Do I need an activity log if I am the only person who accesses my WordPress site?
Even single-admin sites benefit from basic site activity monitoring. Third-party plugins run automated actions, WordPress core handles scheduled tasks, and bots continuously attempt logins — none of which are you. A free, lightweight option like Simple History catches these events with no performance cost and no configuration. It is a five-minute install that routinely clarifies what caused an unexpected site change.
How long should I keep my site's event records?
The free tier of WP Activity Log defaults to a three-month retention window, configurable in settings. For SA businesses processing personal data — contact forms, e-commerce orders, booking systems — matching your log retention to your broader data retention policy is the right approach, typically six to twelve months. Document your chosen retention period in your privacy policy or data processing register. POPIA does not prescribe a specific window, but your decision should be deliberate and recorded.
Will monitoring my site's activity affect page speed or performance?
No, provided you use a well-maintained plugin. WP Activity Log, Simple History, and Stream all write event records during admin-side actions only — front-end visitor performance is unaffected. Database size grows with retention, so on shared hosting with limited storage, set a sensible retention window and review it quarterly. The plugins themselves add no front-end overhead.
Does WooCommerce activity get tracked automatically?
Yes, with WP Activity Log. The plugin includes a built-in WooCommerce sensor that activates automatically when WooCommerce is detected, capturing product price changes, stock updates, order status edits, coupon modifications, and payment gateway setting changes without additional configuration. If your setup uses a heavily customised WooCommerce environment or non-standard product post types, do a test edit and verify the event appears in the log viewer before relying on it for compliance purposes.
What is the difference between an activity log and a security plugin?
An activity log is forensic — it records what happened and who did it. A security plugin is preventive — it actively blocks threats, scans for malware, and enforces login rules. They serve different functions and the best setups use both: the log is your CCTV footage, the security plugin is your alarm system. For SA businesses holding client data, both are worth running — neither replaces the other.
Get Your WordPress Site Properly Monitored
Growth Pulse Media builds and maintains WordPress sites for South African businesses that need real visibility into what is happening inside their dashboard. We configure activity logging, set retention periods aligned with your POPIA obligations, and set up alert rules so you know about critical events before your customers do. All work executed in-house, senior attention on every account, no obligation to proceed.
Talk to Us — Response Within 24 Hours

