0+
May 31, 2026
May 30, 2026
ActivityPilot is an activity log and audit-trail plugin for developers, agencies, and security-conscious site owners. Meaningful changes on your site — logins, content edits, plugin and theme operations, role changes, high-impact options, integrations, and more — are stored in a dedicated database table and shown in a modern admin timeline.
ip-api.com) is disabled by default (enable_geo = 0).{prefix}apwpm_activity_logs (not post meta) with indexes for fast queries.activitypilot/v1), hooks, custom event registry, and PSR-3 adapter.wp apwpm list|count|verify|prune|purge|export|digest|scan-filesLog custom events from your code:
APWPM_Logger::log( array( 'action_type' => 'my_event', 'description' => 'Something happened' ) );
Filter hooks include apwpm_skip_log, apwpm_pre_insert_row, and apwpm_register_event_types. The shorter ap_* hook names from earlier builds are still fired for backward compatibility.
This plugin can connect to third-party services only when you enable the related feature and, for webhooks, when you provide URLs.
When Enable geolocation is on, the plugin may send the visitor IP address to ip-api.com to resolve country and city. No API key is required. Results are cached in WordPress transients (about 24 hours). See the ip-api privacy policy for their terms.
When webhooks are enabled and URLs are saved in settings, the plugin sends HTTP POST requests to your endpoints (for example Slack, Discord, Microsoft Teams, or a custom URL) when qualifying events occur.
Webhook delivery is fully optional and disabled by default. No webhook requests are sent until you enable webhooks and provide at least one destination URL.
The plugin does not include bundled third-party API keys. Geolocation and webhooks are optional and disabled by default until configured by a site administrator.
activitypilot folder to /wp-content/plugins/.On multisite, network-activate for a shared log table under the network prefix.
Writes go to an indexed custom table. Heavy hooks are limited to admin and logged-in contexts where possible. Optional async batching groups writes at shutdown.
In {prefix}apwpm_activity_logs, with optional companion tables {prefix}apwpm_comments and {prefix}apwpm_views. Data is not stored in wp_postmeta.
Yes. Export from the admin UI or REST API. Prune by age via settings, cron, or wp apwpm prune. Full purge requires confirmation and sudo mode when enabled.
Yes. Events are tagged with blog_id, and network admins get a network overview.
Yes. Call APWPM_Logger::log() or register types on apwpm_register_event_types. Use apwpm_skip_log to skip events and apwpm_pre_insert_row to adjust rows before insert.
When hash-chain mode is enabled, each row includes an HMAC chain. Run integrity checks from Site Health or wp apwpm verify. Append-only mode can block deletions for compliance use cases.
activitypilot/v1).