Posts edited, plugins installed, users logging in from new places — your site changes all day. MalCare's Activity Log records every change with a who, a when, and a where-from — so the one change you didn't make is impossible to miss.
A breach is never one dramatic moment. It's a sequence of small, ordinary-looking changes — a login, a new user, a plugin, an edited post. Each one, alone, looks like a Tuesday. A scanner reads your code. The log watches your changes. Together, nothing happens quietly.
Read: no single event here would alarm anyone. The sequence is unmistakable — and a sequence is exactly what a log shows you.
From an IP never seen before.
THE ENTRY"support_tmp" · administrator — you didn't create it.
THE ACCOMPLICE"wp-compat" — exists in no repository.
THE BACKDOOR"Home" · +40 links, visible only to Google.
THE DAMAGE.htaccess — mobile visitors now redirect.
THE PAYOFFA log doesn't block anything by itself — it's the visibility layer that makes every other layer accountable. Detection tells you that something's wrong. The log tells you who, when, and how.
Everything that changes on a WordPress site, tracked as an event — content, people, code, and commerce.
post updated · "About" · +2 ¶
every article change, tracked
page edited · "Checkout"
every page edit, every time
login · daniel · new location
logins with where-from and when, plus account changes
comment approved · id 8812
an event for every comment
plugin installed · v2.3.1
installs, updates, activations
theme edited · footer.php
theme changes at granular level
file changed · .htaccess
file-level changes — including outside wp-admin
order placed · #4412 · $86
orders, items, and store events
Note: file-level tracking matters most — it records the changes attackers make outside WordPress's UI, where no other audit trail exists.
Every event carries its full context — the account, the role, the timestamp, the IP. It's what turns "I think something's off" into "at 03:12, this account, from this IP, did this."
The event, as it appears in the stream
Read: the plugin install isn't suspicious. A plugin installed by an 8-minute-old admin account from a first-seen IP at 3 a.m. — that's a verdict.
Once inside, attackers use WordPress like a user — installing a backdoor plugin, creating an admin, editing posts to carry spam. To a scanner, that's new code to analyze. To the log, it's four timestamped events attributed to an account and an IP.
Read: after an incident, these are the questions that matter — and without a record, nobody can answer them.
The login that started it — access revoked, credentials rotated.
CLOSEDThe rogue admin account — deleted.
DELETEDThe backdoor plugin — removed.
REMOVEDPost and .htaccess — restored.
RESTOREDThe log tells removal where to look — and proves the door is closed. How removal works →
More people can change your site than you think — teammates, freelancers, an agency, that contractor from last year whose account still works. Most incidents here aren't malice. They're mistakes and over-permissioned accounts. The log gives every account a track record — trust, verified.
Read: the firewall handles the one attacker outside. The log covers the five keys already inside — including the one that hasn't been used in 14 months.
The risk you think about.
BLOCKED AT THE WALLFive keys already inside the wall — every action they take, recorded.
ON THE RECORDAdmin key, unused for 14 months — the quiet risk the log makes visible.
THE QUIET RISKOne filter: three edits by freelancer_amy at 13:42 — reverted in minutes, no argument, no mystery.
FIXED FASTcontractor_dave · role: administrator · last login: 14 months ago — still active, still invisible without a log.
TIME TO REVOKEOne "admin" account, four people using it. The log is how you notice — and why role-per-person wins.
MADE VISIBLEWhich plugin update broke checkout? The record answers before the weekend does.
FIXED FASTFilter by user, event type, and date. Search across everything. The questions you'll actually ask:
plugins installed · last 30 days · all events · user: contractor_dave · logins · new locations only · changes to checkout · this week
Read: the suspicious install doesn't hide in eight thousand events — it hides in four. Filtering is what makes a log an instrument instead of an archive.
A busy site generates millions of log events. Stored locally, they bloat your WordPress database and slow every query. MalCare stores the record in your MalCare account, off your server — full history, zero weight.
Read: off-site storage is a performance decision that turns out to be a security decision — covering tracks requires reaching the tracks.
Millions of event rows bloating it — every query wades through the pile.
SLOWS YOUR SITEFull searchable history, zero weight — and beyond an attacker's reach.
ZERO LOADOrders, items, refunds — store events tracked alongside everything else.
TRACKEDOne record across the entire network — shared users, shared files, one log.
SUPPORTEDA complete, timestamped history of changes — the kind auditors and clients ask for.
ON THE RECORDThe activity log isn't a standalone product — it's the accountability layer of MalCare's 7-layer security, sharing one dashboard with the scanner, firewall, and one-click removal.
Watches traffic — blocks attacks before they reach WordPress.
THE PERIMETERWatches code — finds what slipped through, wherever it hides.
THE SEARCHLIGHTWatches changes and people — the who, when, and how behind every event.
THE RECORDActs on all three — surgical cleanup, guided by the record.
THE FIXDetection tells you that. The log tells you who, when, and how — and together, nothing on your site happens quietly.
Real customers — quotes from our reviews and case studies.
Eagle-eye vision & time travel! I was so fascinated to discover this! I can track any activity & locate issues so easily… this has literally saved me hours of headaches in troubleshooting issues.
I had been running iThemes, WordFence & Sucuri, but they kept getting hacked. Then I installed MalCare, which quickly found the malware and cleaned up the entire site.
Adam SilverConciergeWP · FounderI was on the beach with my family when MalCare notified me of a plugin vulnerability across 50 of my sites. With one click on my smartphone, all sites were fixed within minutes.
Paul LaceyWordPress ExpertThey watch different things. The scanner reads your code; the log watches your changes and people. A rogue admin logging in and editing a post is invisible to a code scan until damage exists — the log sees it as it happens. Together, nothing happens quietly.
No. Events are stored in your MalCare account, off your server — nothing accumulates in your WordPress database. Busy sites generate millions of events; yours carries none of that weight.
Yes — filter by user and date, and every change they made is listed with timestamps: pages, posts, plugins, menus, files. It resolves "who changed this?" in one query, without an argument.
The record isn't on your server, so compromising your site doesn't reach it. Covering tracks requires reaching the tracks.
Yes. Store events — orders, items, refunds — are tracked alongside everything else, and on a multisite network one record covers the whole setup.
Yes — the full history is searchable and filterable by user, event type, and date range, from your MalCare dashboard.
No — it records changes to the site, not keystrokes or screens. It's the same accountability a shared codebase gets from version control: who changed what, when. Most teams find it protects people ("it wasn't me" is provable) as much as the site.
The activity log comes built into MalCare's 7-layer security — with the scanner, firewall, and one-click removal beside it.
Included with MalCare · zero site load · works on any host