WP Activity Log version 4 changelog

WP Activity Log changelog for all version 4 builds and releases.

4.6.4 (2024-02-14)

Bug fixes

  • Fixed: Undefined array warning shown on websiteโ€™s front-end when running Gravity Forms in certain setups.
  • Exception handling added for when uploading a PDF as a WooCommerce product image.
  • Fixed: fatal error in third step of install wizard when plugin is installed on a vanilla WordPress.

4.6.3 (2024-02-08)

Plugin & features improvement

  • Added support to the new plans and prices (February 2024 change).
  • Upgraded the Freemius SDK to 2.6.2.
  • Updated a number of links in the plugin (links used in help text etc).
  • Removed hardcoding of post types and post statuses in search filters.
  • Continued code refactoring – code removed from main plugin file, created new classes etc.

Bug fixes

  • Option for event ID 5709 was not showing when filtering the list of event IDs in the Enable/Disable events section.
  • Fixed error generated when duplicating forms on Gravity Forms.
  • Fixed: plugin keeping a log of forms submission even when the option to keep a log by website visitors was disabled.
  • Added event ID check when extracting the last occurrence from the database.
  • Addressed a number of PHP errors generated when running the plugin on PHP 8.2
  • Fixed a server error generated when exporting search results.

4.6.2 (2024-01-09)

Plugin & features improvement

  • Fixed a number of broken links in the UI (search filters) and Enable/Disable events section.

Security fix

  • Fixes an XSS in the activity log viewer. Identified by NamGyu Kang.

Bug fixes

  • Extension update notice introduced in 4.6.0 cannot be dismissed in certain situations.
  • Fixed: Fatal error in WP_Content_sensor triggered in some edge cases.
  • Fixed: Error in MirrorLogger.php triggered by a bad / broken migration of activity log events.
  • Fixed: Fatal error on multisite network when upgrading from 4.5.2 to >4.6.0.
  • Addressed a Composer error triggered when installing Premium over Free edition of the plugin in certain versions.

4.6.1 (2023-11-02) – Free edition only

Plugin & features improvement

  • Migrated more of the plugin’s code to WordPress coding standard.
  • Cleaned the code from a number of redundant and wrong logic.
  • Improved text on certain buttons & other UI sections.
  • Removed all code previously used by the obsolete extensions.

Bug fixes

  • Fixed error / crash encountered when using the Grid View and upgrading to 4.6.X.
  • Fixed: Events cannot be deactivated from the Enable/Disable page in the plugin.

4.6.0 (2023-10-18)

New activity log event ID

  • Event ID 6061: With this event ID the plugin keeps a log of when an email is sent from the website.
  • Event ID 9123: A WooCommerce coupon was moved to trash.
  • Event ID 9124: A WooCommerce coupon was permanently deleted.
  • Event ID 9125: The visibility of a WooCommerce coupon was changed.
  • Event ID 9126: The published date of a WordPress coupon was changed.
  • Event ID 9127: A WooCommerce coupon was restored from trash.

Refer to the list of activity log event IDs in WordPress for a complete list and more details about what the plugin can keep a log of.

New features

  • Free text search included in the free edition of the plugin.
  • Support for the wildcard “*” in the search filters (Premium edition).
  • Added a setting in the external database module so the plugin writes the activity log directly to the external database rather than using the Action Scheduler buffer.
  • Added new option in the Delete activity log tool to delete activity log data of a specific day.
  • Added a new search filter for “user email” in the activity log search.
  • Added support for WP CLI: a number of plugin options can be configured via WP CLI post plugin activation.

Plugin & features improvements

  • Continued the second phase of the major plugin core refactoring, including reviewing, refactoring and documenting the sensors loading, classification process etc.
  • Rewritten all the MySQL connection & database communication classes.
  • Moved all third party plugins extensions (such as those for WooCommerce and Yoast SEO) to the plugin core, meaning extensions are no longer required.
  • Code cleanup: removed redundant old code and a number of obsolete files.
  • Activity log viewer is now using all the standard WordPress UI features (screen options, bulk options etc) for a more seemless experience.
  • Improved support / activity log coverage for Yoast SEO, WPForms, Gravity Forms, and Memberpress.
  • Improved coverage for WooCommerce and also supporting the latest version of WooCommerce: 8.X.
  • Switched the default activity log viewer view mode to pagination.
  • Rebranded the developer / ads / text etc – WP White Security is now Melapress.
  • Improved the activity log data inspector view – now data inspector is within the activity log viewer.
  • Removed the plugin setting to select which columns to show in the activity log viewer. Now the plugin uses the standard WordPress screen options.
  • Removed the Grid view completely.
  • Added the database info to the system info file (useful for support / troubleshooting).
  • Updated the column titles used in the activity log reports.
  • Applied several minor improvements to the Archiving setup screen.
  • Removed all meta related classes and switchd to a universal entity class / switch to arrays instead of objects.
  • Removed redundant “Next” button from the last step of the Connection wizard.
  • Added error & notification messages in the Connections wizard for when invalid database table prefixes are used.
  • Added the timezone / time format information in the reports header.
  • Updated the Freemius SDK to 2.5.12.

Bug fixes

  • Fixed: Reports auto pruning was removing all reports regardless of the configured setting.
  • Fixed: In some cases built-in notifications for critical events were not being fired.
  • Fixed: Grouping of specific notifications criteria were not working. For example event IDs + Not from IP address; the second criterion was ignored.
  • Plugin now deleted the flag “archiving-cron-started” when the “Excute Archiving Now” button is clicked to unblock potential clogged archives.
  • Fixed: Plugin failed to retrieve site URLs in some cases on a multisite network.
  • Fixed: No events reported in the daily email report in some edge cases.
  • Fixed: Reported number of logins for admin users in statistics reports not reported correctly.
  • Fixed: Filtering of logged in users was not correct in the Logged in users section on a multisite network.
  • Fixed: Users and Roles were not counted correctly in the overview of logged-in users page on a multisite network.
  • Fixed: Multiple email notifications sent at ones if the built-in notifications are all enabled at the same time.
  • Fixed: A number of PHP Warnings generated when the Export/Import setting was used on multisite networks.
  • Fixed: Deleting activity log data for a specific user was not deleting Event ID 1000’s on multisite networks.
  • Fixed: Plugin failed to find user in the User filter when generating a Report based on ‘user’ criteria on multisite networks.
  • Fixed: Activity log view of Archived events was not accessible when the Archived connection was linked to the site on a multisite network.
  • Fixed: Terminate all sessions erroneously reporting Event ID 1003 on multisite networks.
  • Fixed: Deleting data upon uninstallation was generating WordPress database errors and PHP warnings in the free edition.
  • Fixed: The date column from the Activity Log viewer could not be filtered if the Archiving or External connection was active.
  • Fixed: Archiving data could have caused a loss of metadata and events from the current day in some edge cases.
  • Fixed: Prevented PHP Warnings / Notices when a Custom Template was used in creating custom notifications.
  • Fixed: In some edge cases, archived activity log data was not included in the reports.
  • Fixed: Deleting data for a specific Event ID from the Archived database not working in some cases.
  • Fixed: Entire list of Event IDs was not fetched when trying to delete data based on specific Event ID.
  • Fixed: Problem with multiple Archive/External connections being created out of a single declared connection.
  • Fixed: Data from external database not being indexed in plugin’s Search.
  • Fixed: Erroneous plugin behavior when the “only me” Setting for Admins to access plugin settings is enabled.
  • Fixed: Fatal error in some cases when Report was generated in .CSV format.
  • Fixed: Fatal error generated in some edge cases when plugin was deleting data in local database when switching back from external to local database.
  • Fixed: Custom “From Email Address” not showing up properly in plugin’s mail recipients.
  • Fixed: Extended logic in default email templates preventing IP Addresses from being displayed in a number of edge cases.
  • Fixed: Events generated on-site’s front end not reaching the Syslog server during mirroring.
  • Fixed: The Custom User field in the Exclude Objects tab was not saving values properly.

4.5.3 (2023-07-05)

Bug fixes

  • Fixed issue causing pruning of reports to remove all stored reports.
  • Fixed issue which could cause a memory issue when migrating from older versions.
  • Fixed error which could cause ‘Excluded custom user fields’ to not save when updating.
  • Fixed issue which cause cause a fatal error when saving pages via the Oxygen Builder plugin.
  • Other improvements
  • Updated Freemius SDK to the latest version (addressing a security issue).

4.5.2 (2023-05-11)

Plugin improvements

  • Improved PHP 8.2 compatability.
  • Replaced the elipsis icon used for the Event data viewer with a “More details” button in the activity log viewer.
  • Updated a number of hooks (better interoperability) used in custom sensors.
  • Improved the “installed plugin” check to only show one extension notification when both the free and premium edition of a plugin are installed at the same time.
  • Activity log data is also automatically deleted from the archive database when using the logs data deletion tool.

Security updates

Fixed a number of CSRFs, missing authorization & missing capabilities checks discovered by Marco from Wordfence.

Bug fixes

  • Fixed: Fatal error reported when cloning a site on a multisite network with the NS Cloner plugin.
  • Fixed: Plugin was not retrieving the correct IP address when using a reverse proxy since update 4.5.0.
  • Addressed a number of PHP Warnings reported when using the WP Rocket plugin to purge the cache.
  • Fixed: PHP warning when saving Exclude Objects settings.
    Setting up a mirroring connection and configuring the mirror of logs was not being reported in the logs.
  • Fixed: Fatal error when using the User Switching plugin to switch a user’s session.
  • Fixed: Logins from non-native login forms (such as those from WooCommerce) were not captured correctly since update 4.5.0.
  • Fixed: Plugin not terminating existing user session when the seting to “overwrite existing session” was enabled.

4.5.1 (2023-04-25)

Plugin improvements

  • Replaced the elipsis icon used to launch the event details viewer with a “More details” button.

Bug fixes

  • Fixed: IP was not extracted properly from HTTP header when a proxy was in use.
  • Fixed: Fatal error in user-switching.php sensor when switching logged in users with a user switching plugin.
  • Fixed: Logins from WooCommerce not captured properly even when plugin is configured to capture logins from all login forms.
  • Fixed: option to “override current logged in session” (Session management module) was not terminating sessions when users log in via the WooCommerce login page.
  • Fixed: PHP fatal error in the login and logout log sensor.
  • Fixed: PHP notice in settings helper class when switching off the reverse proxy settings.

4.5.0 (2023-04-12)

Release notes: Update 4.5: refactored core & improved performance

New features and functionality

  • Automatic activation of license key in NOFS edition of the plugin if key is declared on file.
  • Added events’ severity filter in the Report module.
  • Added a new option to remove report metadata, such as the filters used for the reports from activity logs reports.

Plugin and features improvements:

  • Refactoring the pluginโ€™s core code phase 1 โ€“ improved performance, reliability and maintainability.
  • Better support for PHP8 – addressed all reported warnings and fatal errors.
  • Event ID 2002 is now reported when a user changes something in a post for which the plugin does not have a specific event ID.
  • Added a link to the Saved Reports tab in all reports’ emails to allow easy access of all generated reports.
  • Set the Filters and Save Changes button top bar to “sticky” (always floats at the top of the screen) when enabling / disabling events (better UX).
  • Applied multiple tiny UI improvements in the Reports and User Sessions Management pages.
  • Improved the UI of the filters in the activity log viewer – now all the filters are displayed in full and are no longer truncated.
  • Added checks to the excluded objects placeholders to ensure users do not specify wrong objects in the wrong setting.
  • Replaced technical term severity labels with friendly ones. For example WSAL_HIGH is now High severity.
  • Added some new help text and improved existing help text in some pages throughout the plugin.
  • Improved support for RTL setups in the activity log viewer.
  • Deleted obsolete upgrade code that was checking for AWS connections during upgrade.
  • Removed code related to the migration of events when using an external database from the Free edition of the plugin.
  • Improved the way the database table changes are detected by the plugin – all event IDs used for database changes monitoring are now enabled by default.
  • Option to “List only IP addresses used during login” for the IP addresses statistics report is grayed out unless the report is chosen.
  • Improved the sensor that detects page changes (page created, deleted or changed) done automatically via plugins.
  • UI/UX improvements in the reports page and the settings for the periodic reports.

Bug fixes

  • Fixed: Intermittent fatal error in UserSessionsTracking.php when log gin in from custom login pages (like WooCommerce).
  • Fixed: Event ID 7009 (user changed the maximum upload file size for a site on a multisite network) was wrongly logged instead event ID 7011(user changed the maximum upload file size for the network).
  • Fixed: Renaming a menu was not reported correctly, event ID 2085 (Changed menu items order) was reported instead.
  • Fixed: Error reported in the message of event ID 6060 (Changed the status of an event ID).
  • Fixed: WP Activity Log now keeps a log when it is activated or deactivated.
  • Fixed: Deleting events with “Informational” severity delets all events in the log.
  • Fixed: Fatal error in class-alert-manager.php when excluding a user and its role at the same time.
  • Fixed: Super Admin role added to Admin user in logs on a single site.
  • Fixed: PHP warning in /classes/Sensors/Multisite.php on a multisite network when running NOFS edition of the plugin on some specific multisite network setup.
  • Fixed: Plugin version update notice still shown in the NOFS edition of the plugin even when the plugin is up to date.
  • Fixed: When objets are excluded from the activity log.
  • Fixed: Event ID 6052 (Changed activity log retention settings) was not reported if the setting is already on “delete events older than” and the user changes the number of months or years.
  • Fixed: Event IDs 6053 – 6058, used to keep a log of when objects are excluded from the activity log are not reported in a multisite network environment.
  • Fixed: HTML code was shown instead of characters in some drop down menus in the Reports module pages.
  • Fixed: Site title change not reported (Event ID 6059).
  • Fixed: The daily summary email was not reporting file changes reported in the website through the Website File Changes Monitor plugin.
  • Fixed: Tags and Mirror identifier settings removed from Syslog and Slack mirroring settings – these are only used by third parties such as Amazon Cloudwatch and Papertrail.
  • Fixed: Report for number of published posts by user contained duplicate entries.
  • Fixed: Event ID 6034 (Purged activity log) also reported along site event ID 6006 when resetting plugin settings to default.
  • Date filters in reports were not applied correctly; plugin also including events that happened within 24 hours before the start date.

4.4.3.2 (2023-02-09)

New features

  • Added a new option to keep a log of non mirrored events in a log file in case of failure.
  • Added support to send syslog files over a TCP connection (previously it was only possible on UDP).

Plugin & features improvements

  • Updated some of the settings text in the mirroring wizards.
  • Old non_mirrored_events.log files no longer converted to php.

Bug fixes

  • Fixed a broken link in the first-install wizard.
  • Fixed: plugin created the file non_mirrored_events.log even when no mirrors were configured.
  • Fixed: Logger path was wrong (in some cases it was generating a log file in /wp-admin/)

4.4.3.1 (2023-01-12)

Plugin & features improvements

  • Better support for the Nextend Social Login and Register plugin – plugin keeps a log of all logged in sessions, including those signing in via third parties services such as Google and Facebook.
  • All search filters now have the “add filter” button, replacing the client side scripts to improve cross-browser support.
  • Improved the placement and text of some notices & error messages in the activity log mirroring wizard.
  • Added additional checks for the plugin setting “write directly to mirror” to address a number of PHP warnings.

Bug fixes

  • Fixed: Error reported when trying to edit a revision of a post on some particular setups.
  • Fixed: All plugin log files had the .php extension, instead of only the non mirrored logs log file.
  • Fixed a PHP notice triggered whenever accessing the Integrations section in the plugin.
  • Fixed a number of PHP warnings which were being reported when the plugin is run in an environment using PHP8.
  • Fixed: Clicking the “Archive now” button was not triggering the archiving of the activity log, but only the Cron job was triggering the archiving.
  • Fixed: Uncaught error in “FS_Admin_Notices” reported in some cases when plugin is used with MainWP child.
  • Fixed: PHP fatal error reported on some membership based websites when users try to log in.
  • Fixed: Incorrect username is shown in the daily email summary in some multisite network installs.

4.4.3 (2022-12-08)

Release notes: WP Activity Log 4.4.3

New activity log event IDs

  • 6060: an event ID was enabled or disabled.

New features & functionality

  • MemberPress activity log extension – keep a log of the changes that happen on your MemberPress powered website.
  • Support for syslog connections over TLS connection.
  • Setting to write activity logs directly to a log file (completely bypassing the Action Scheduler).
  • Sessions policies for super admins on a multisite network.
  • Button to terminate only the displayed sessions in the Logged-In users view.
  • New setting to show only the logged in users who have multiple sessions.
  • New {user_email} tag available for custom notifications.
  • Plugin can now read v4 IP addresses that are mapped to v6.

Plugin & features improvements

  • Reports are now generated in the background and an email is sent to the user upon completion, allowing users to navigate away from the page without interrupting the process.
  • Non mirrored logs are now stored in a php file instead of a log file – more secure implementation.
  • User email address is now available as a tag that can be used in email templates.
  • Major database queries improvements to optimize the reading of activity log events from the database.
  • Improved display of extension events (as well as special sub-options) within the Enable/Disable events view.
  • Adjusted CSS for a more responsive activity log viewer.
  • Improved login sensor to improve compatibilty with most custom login forms.
  • Improved logic handling when creating custom notifications.
  • Activity Log events sorted by event ID in Enable/Disable Events section.
  • UI improvements to the Enable/Disable events view.
  • Activity log event metadata is now consistently an array for efficiency and better data management.
  • Added new options in the “Terminate all sessions” feature to terminate all but the admin’s sessions.
  • Silencing admin notices in the activity log viewer page.
  • New selection checkbox to individually select sessions from the logged in users view.
  • Various UI and UX improvements to the Users Sessions view.
  • Event data inspector styling improvements.
  • Removed the Freemius SDK from the free edition of the plugin.
  • Plugin now displays the user role name instead of the slug.
  • Improved the plugins internal logging class/system.
  • Applied several new checks and improvements to improve the reliability of the archiving connection module.
  • Limited external connection usage to single use (to avoid conflicts and speed up the process).
  • Removed Freemius from the Free edition of the plugin.
  • Improved the logic of event ID 1000 (user login) to avoid duplicate events when a user logs in via WooCommerce.
  • Improved the “ordering and organizing” of the event ID lists in the Enabled / Disable Events section.
  • Updated the Freemius SDK to version 2.4.5.
  • Improved compatability with the MemberPress plugin (addresses a number of errors etc).

Bug fixes

  • Fixed: PHP error when creating or deleting sites on a multisite network.
  • Fixed: Action Scheduler library used when writing events to local database.
  • Fixed: Error generated during logging in when using WP Defender.
  • Fixed: Automatic update emails from WordPress not being sent in the correct languange when WP Activity Log is activated in specific scenarios.
  • Fixed: Some of the “hover over info panels” in the activity log not working due to a broken JS dependency.
  • Fixed: Grouping in custom notifications not working in certain scenarios.
  • Fixed: An issue that causes the ‘update available’ email to disregard the site’s language.
  • Fixed: Pagination links in list of logged in users was being overridden by other components.
  • Fixed: Cannot save multiple email addresses for the daily activity log notification.

4.4.2.2 – Premium only (2022-07-27)

New functionality

  • New setting to not send the daily notification if there are no events to report.

Improvements

  • Post titles in Daily summary email now link to post directly.
  • Improved support for custom user roles in notifications.
  • Applied a number of UI changes and improvements to the “Logged In Users” section.
  • Added version number to Search JS scripts so they are not cached by browsers.

Bug fixes

  • Fixed: Search of logged in sessions by user role not returning correct results.
  • Fixed: A number of PHP notices were reported whe nthe WSAL_cleanup cron job is fired.
  • Fixed: Daily email summary cannot be disabled.
  • Fixed: Cannot change the daily summary notification email address.

4.4.2.1 (2022-07-06)

Bug fixes

  • Fixed: Fatal error when a WooCommerce file download is triggered.
  • Fixed: Only users with administrator role shown as logged in on a multisite network.
  • Fixed: Event IDs 5010 – 5018 wrongly enabled by default.
  • Fixed: A number of upgrade errors caused because of possibly outdated files.
  • Fixed: Disabled event IDs disabled at multisite network level were activated back when accessing child sites.
  • Fixed: Upgrade notice shown on a multisite network even when it is a new install.
  • Fixed: Fatal error triggered due to incorrectly named files (wrong capilitazion).
  • Fixed: Error in Alert formatter triggered during the upgrade process.

4.4.2 (2022-06-23)

Release notes: WP Activity Log 4.4.2

New activity log event IDs

  • ID 2133: user taken over a post from another user.

New features & functionality

  • A number of new activity log statistics reports such as number of newly created users, user profile changes, password changes and password resets, page views, and more.
  • Added a number of new whitelabeling options in the activity log reports. Users can now add the business name, contact details, business logo and more in the reports.
  • Users can now change the report title, add comments etc.
  • Tags for Loggly & AWS Cloudwatch: add tags to the WordPress activity logs mirrored to your logs management system

Plugin & features improvements

  • Users can now specify the number of hours when configuring a timeout for idle sessions.
  • Automatic plugin and theme updates are now detected and reported in the activity log (event ID: 5004).
  • Improved the logic of event ID 4029 – the user triggering the password reset request is now reported as the user who did the action.
  • Added the format of the generated report in the periodic reports list.
  • Draft posts can also be included in reports criteria.
  • The function to import / export plugin settings replaced with our own library (to be used in other plugins).
  • Plugin now uses the hook ‘deleted_theme’ to detect deletion of installed themes.
  • Removed the multisite tab from built-in notifications when installed on single site.
  • Added a check so the name of a mirroring connection cannot be empty.
  • Plugin now checks if there is an existing mirroring connection with the same name so not to overwrite existing ones.
  • Removed redundant “Save” button from the “Delete activity log data” page.
  • Improved the Integrations wizard – catered for a number of conflicts with other plugins and themes such as Divi.
  • Reviewed and improved the text in the WordPress users’ sessions management module.
  • Reports generation errors now contain details of why reports failed instead of generic errors, helping the user identify what the issue might be.
  • When deleting data about an IP address or a user from the logs, the user is now asked if they want to delete the events about the user / where the IP address is mentioned, or events generated from that user or IP address.
  •  Optimized the way licensing data is stored on a multisite network.
  • Premium plugin advert in activity log viewer is now fixed – it does not interrupt user.
  • Added a new filter to specify which long data fields should be truncated in the activity log viewer.
  • “Email Notifications” section renamed to “Email & SMS Notifications”.
  • Reviewed and rewritten the help text in the Sessions module to advise users to terminate current sessions before restricting sessions.
  • Applied a number of UI/UX tweakts to the Enable/Disable events section making it neater and easier to use.
  • Post titles are now reported and linked to the post in the daily update email.

Bug fixes

  • When user changes multiple plugin settings the plugin now is reporting all the changes and not just one.
  • Fatal error reported when running certain activity log searches.
  • Event ID 6310 no longer incorrectly reported with every plugin setting change.
  • Fixed: activity log retention settings deleted and rewritten to database on page reloads.
  • Fixed: some premium features such as the “link to view all users activity” available in the free edition.
  • Fixed: New notification help text shows HTML code rather than formatted message.
  • Fixed: Clicking the expand data in activity log viewer resets the view and redirects the user to top of the activity log.
  • Fixed: Reports filter “Post type” was not finding events about posts with some custom post types.
  • Fixed: Changes in activity log retention settings not correctly reported in event ID 6052.
  • Fixed: When a user changes a post’s title and content, only the title change is reported.
  • Fixed: Deleting of activity log events by severity is not deleting the events.
  • Fixed: Excape characters in password cause authentication with third party services to fail.
  • Fixed: The setting “Cleanup expired session data” cannot be disabled.
  • Fixed: Step 2 in the integrations wizard is not “scrollable” if you go back to it while configuring a connection.
  • Fixed: changes in built-in email notifications are not saved in some specific scenarios.

4.4.1.1 (2022-04-06)

Bug fix

  • Fixed: Search broken due to changes in the code format.

4.4.1 (2022-03-23)

Release notes: Out now: Activity Log for MainWP 2.0 & WP Activity Log 4.4.1

Improvements & changes

  • All of the plugin’s code is now using the WordPress coding standards.
  • Removed the reporting and search code from the free edition plugin that was used by the MainWP extension.

Bug fixes

  • Fixed: Reports filter “By post title(s)” not working.
  • Fixed: Users couldn’t set up a MySQL connection because of “unknown connection type” error.
  • Fixed: The daily activity log summary email cannot be enabled again after disabled.
  • Fixed: PHP fatal error when index.php file is saved in the custom sensors directory.

4.4.0 (2022-02-28)

Release notes: New Reports engine with more criteria, reports management & more

IMPORTANT – NEW HELPER PLUGIN

  • Third party libraries are now available through a helper plugin. If you are mirroring events or sending SMS messages, you will be prompted to install this helper plugin.

New activity log event IDs

  • ID 6059: Changed the site’s title.
  • ID 4021: Changed the website URL in the user profile.
  • ID 4013: User has been activated on a multisite network.

New features & functionality

  • Reports for WordPress: we developed an all new reporting engine, with more criteria.
  • Reports management module: see all generated reports, redownload or delete them etc.
  • Reports white labelling: users can now change the logo and links on the reports. More to come in upcoming updates.
  • New template for reports with new title page for reports.
  • Reports settings page: making a number of reports configuration settings available, giving the user more options to work with.
  • Setting to configure the plugin to “always” send an email for scheduled reports, even when no events match the criteria.
  • Hooks to allow users to change the columns in reports or ad value from non-default columns. Refer to the list of hooks in WP Activity Log for more information.
  • New naming format for all the reports: [yyyymmdd]-[report_number].[extension].
  • Specific reports can now be generated in PDF and JSON formats.
  • New UI for “Enable/Disable event IDs” with search and filtering functionality.
  • Table with numbers of how many users are logged in with specific roles + filters.
  • Added the user role next to each user in the list of logged in users.
  • Removed obsolete code used for advertorial events in the activity log viewer.
  • New “See user’s activity” link for each user in the users’ page to see a user’s activity with just a click.
  • New filter that allows user to add metadata to user information popup. Refer to the list of hooks in WP Activity Log for more information.
  • The new Activity Log for TablePress extension.

Improvements

  • Changed the database schema for improved storing of data, and faster writing and reading. After the upgrade the plugin will launch the upgrade process which might take some time to complete, depending on the amount of data in the activity log.
  • Activity log events from local database can be merged into an extising activity log in an external database.
  • Improved the coverage of changes done to a website via REST API.
  • Improved the format of the statistics reports. More statistics reports will be available in the upcoming version update.
  • Date and time are now two separate objects in CSV reports.
  • Updated the search module to read from new database schema.
  • All plugin settings now have the wsal_ prefix automatically added to them.
  • Added the URL metadata in CSV reports.
  • Rewritten some of the settings help text in the plugin to better explain the settings.
  • Updated the notifications module to read from new database schema.
  • Updated the integrations module for better backward compatability with older versions of WordPress.
  • Removed obsolete settings & code of the old file integrity scanner (now part of Website File Changes Monitor plugin).
  • Removed obsolete reference to the old file changes scanner in the daily summary email.
  • Made a number of JS strings available for translation.
  • Removed a number of plugin settings from autoload for improved performance.
  • Improved the plugin’s metadata and added the licensing information.
  • Long URL strings in activity log events are now automatically truncated. Full URL can be seen with just a click.
  • Removed forced database table collation: plugin now uses the default WordPress table collation.
  • Updated the “Help & Contact Us” page; improved text and added more relevant information.
  • Improved several UI sections in the Third Party Connections module.
  • Improved the check for writing activity log to external database; now it is less restrictive and faster.

Security fix

  • Upgraded the Freemius SDK to version 2.4.3.

Bug fixes

  • * Fixed: Database error when trying to log in with a non-existing user and a login notification is enabled.
  • * Fixed: In some edge cases the plugin was creating an empty “external database” connection string.
  • * Fixed a number of typos in the text of activity log events.
  • * Fixed: Auto complete in the Delete activity log data section was not returning the correct list of objects.
  • * Fixed: Wrong object reported for event ID 5029.
  • * Fixed: Event ID 4000 not reported when front-end sensor is disabled.
  • * Fixed: “Unknown connection type” reported back setting up a third party connection on specific versions of WordPress.
  • * Fixed: Event ID 6320 (added / removed connection) reported instead of event ID 6321 (modified connection).
  • * Plugin settings and view privileges no longer imported when using the configuration import tools. User is not prompted to choose whether to import them or not.
  • * Fixed: Function that was running on “add_filter” instead of “add_action” – Support ticket.
  • * Fixed: Deletion of events from the activity log based on severity not working.
  • * Fixed: Plugin fails to delete specific events from activity log with an error when using the Logs management module.
  • * Old reports are now properly and automatically deleted from the /uploads/ directory.
  • * Fixed: PHP warning about OPCacheUtils.php in specific setups.
  • * Fixed: Edge case in which other plugins couldn’t be installed or updated when WP Activity Log was activated.
  • Automatic termination of idle sessions was not triggering properly on some setups.

4.3.3 (2021-10-13)

Release notes: WP Activity Log 4.3.3: Plugin setting importer & exporter & support for REST API

New activity log event IDs

  • ID 5028: Enabled or disabled automatic updates for a plugin.
  • ID 5029: Enabled or disabled automatic updates for a theme.

New activity log event IDs for notifications in the plugin

  • ID 6310: Changed the status of the “Daily activity log summary email”.
  • ID 6311: Modified the list of recepients of the “Daily activity log summary email”.
  • ID 6312: Changed the status of a built in notification.
  • ID 6313: Changed the recepient(s) of a built in notification.
  • ID 6314: Added a new custom notification.
  • ID 6315: Modified a custom notification.
  • ID 6316: Changed the status of a custom notification.
  • ID 6317: Deleted a custom notification.
  • ID 6318: Modified the default notification template.

New activity log event IDs for integrations & activity log mirrors

  • ID 6320: Added a new integration connection.
  • ID 6321: Modified an integration connection.
  • ID 6322: Deleted an integration connection.
  • ID 6323: Added a new activity log mirror.
  • ID 6324: Modified an activity log mirror.
  • ID 6325: Changed the status of an activity log mirror (disabled/enabled).
  • ID 6326: Deleted an activity log mirror.
  • ID 6327: Changed the statues of the setting “Logging events to database”.

New features

  • Plugin settings exporter & importer: easily export and import the plugin’s settings configuration for backups, migration etc.
  • Options to delete specific data from the activity log, such as all events about a user, or an IP address.
  • Plugin keeps log of authenticated user changes done to the website via the REST API.
  • New button to only terminate the users’ sessions that match the search criteria in Logged in users’ session.
  • Added the new {first_name} and {last_name} tags to the custom notifications template.
  • New hook to edit the activity log event data before it is sent to mirrors.

Improvements

  • Logs from subsites on multisite networks can be mirrored to AWS Cloudwatch as individual log streams.
  • Activity log retention policy can now be specified by the number of days.
  • Plugin now reports user role changes done via the “Members” plugin (by Memberpress).
  • Event ID 2010 (user uploaded a file) now includes a link to the uploaded attachment.
  • Added “Blog ID” and “Site URL” to mirrored activity log events.
  • Hover over prompt for users entries in activity log viewer now displays more information about the user.
  • Improved the handling of post meta changes.
  • Renamed menu entry “DB & Integrations” to “Integrations” to better reflect its purpose.
  • Contact us link in install wizard now points to contact us page on website instead of homepage.
  • Auto complete filters in Reports now check up to 100 records.
  • Added additional database checks to ensure all data is removed from database upon uninstall on a multisite network.
  • Improved coverage for the Members plugin – plugin now reports user role changes done via the Members plugin.
  • Updated the “Help” link in the first time install wizard.
  • change the “wsal_inactive_sessions_test” database override to a filter.
  • Improved in-context help messages in plugin settings and ensured all titles are uniform.

Bug fixes

  • Fixed a PHP warning which happened when visiting the plugin’s settings pages (support ticket).
  • Fixed PHP notice which happened when visiting an archive page (support ticket).
  • Event IDs for “integration connections” changes wrongly reported for changes in “activity log mirroring connection” changes.
  • Fixed: Activity log retention policies appearing twice in some scenarios.
  • Fixed: Activity log retention settings and archive settings popup logic.
  • Added the missing argument in a multisite network that were creating a PHP error during plugin uninstall.
  • Setting the setting “Remove all data on uninstall” to “No” no longer leaves no option selected.

4.3.2 (2021-08-03)

Release notes: New external database module, plugin logging, and other exciting features

New event IDs for WP Activity Log plugin settings changes

  • ID 6046: Changed the status of the Login Page Notification.
  • ID 6047: changed the text of the Login Page Notification.
  • ID 6048: changed the status of the Reverse proxy / firewall option.
  • ID 6049: changed the Restriction Access setting.
  • ID 6050: changed the list of users that can view the activity log.
  • ID 6051: enabled / disabled the Hide plugin in plugins page setting.
  • ID 6052: changed the activity log retention policies.
  • ID 6053: excluded / included back a user in the activity log.
  • ID 6054: excluded / included back a user role in the activity log.
  • ID 6055: excluded / included back an IP address in the activity log.
  • ID 6056: excluded / included back a post type in the activity log.
  • ID 6057: excluded / included back a custom field in the activity log.
  • ID 6058: excluded / included back a user profile custom field in the activity log.

New features

  • A completely new external database module (with full backward compatibility support).
  • Activity log can now be stored on external MySQL databases on Microsoft Azure.
  • A new sensor to keep a log of WP Activity Log plugin settings changes.
  • New setting to “not write activity log to database” when mirroring the activity log to a third party service.
  • The “all except from” criterion in the reports, allowing users to easily exclude specific object from a report criteria.
  • Plugin database version: the plugin’s database is now versioned, making it much easier to upgrade the database structured when required.
  • Custom fields in user profiles can be excluded from the activity log from the “Exclude Objects” settings section.
  • The filter “wsal_event_metadata_definition” which allows users to add additional meta data to an event in the activity log. Refer to the list of hooks in WP Activity Log for more information.
  • Added events severity level filter in the mirroring connection, allowing users to filter which events should be mirrored by severity level.

Plugin improvements

  • Replaced the old external database buffer system with the Action Scheduler library to improve reliability and performance.
  • Redesigned the reports download functionality so it works on any type of WordPress web hosting.
  • Replaced the old activity log events migration module with WP Background processing, for a more reliable migration process.
  • Full support for PHP 8.
  • Detection of third party plugins activity & recommendations for activity log extensions.
  • Added a number of checks to the external database module for an improved database connection setup UX.
  • Activity log plugin extensions are also hidden when the WP Activity Log plugin is hidden from the plugins page.
  • Removed all the code that was previously used for migration of events between the WordPress and external database.
  • Remove code that is no longer required in the free edition of the plugin.
  • Better support for plugins that still use old methods (old use of the lostpassword_post filter) to allow users to reset their password without an error.
  • All database events have been moved under the “WordPress & System” tab in the Enable/Disable events section.
  • Improved the text of the plugin’s install wizard.
  • Live notifications in Admin toolbar are now disabled by default (performance enhancement).
  • Amazon AWS library is disabled by default. Users will be alerted to initialize it from wp-config.php if required.
  • Added the “;” as separator in the meta data section in CSV reports.
  • Removed the event ID 4-digits limit to allow users to declare event IDs with 5+ digits.
  • CSV reports now show the right username & display name, as configured in the plugin settings.

Bug fixes

  • Plugin was not capturing user logouts from Ultimate Member plugin profile page.
  • Plugin was reporting wrong directory name in URL in event ID 2101 on a multisite environment.
  • In specific scenarios the plugin reported a custom field name as NULL in event ID 2054.
  • Fixed the broken link to user profile page in event ID 4001.
  • Event ID 4029 (user sent a password request) had the wrong Event Type.

4.3.1.1 (2021-06-28)

Note: this update is only for the premium edition of the plugin.

Bug fix

  • Fixed an issue in which scheduled reports could not be saved, resulting in a critical error.

4.3.1 (2021-06-03)

Improvements

  • Minimum version of PHP required now is 7.0.
  • Added a custom prefix to libraries and dependencies used in the plugin to ensure there are no conflicts.

Bug fixes

  • Corrected logic in code to ensure all sessions are handled and checked when destroying idle sessions.
  • Fixed an issue causing create/expired times in the โ€œLogged in usersโ€ view to appear incorrectly.
  • Implemented a missing function without with events were not retreived from the MainWP extension.

4.3.0 (2021-05-20)

Release notes: WP Activity Log 4.3: The new mirroring module & integrations

New features

The new WordPress activity log mirroring module: mirror your website’s activity log in real-time to AWS CloudWatch, Loggly, a log file and several other services.

Improvements

  • The activity log is mirrored to third party services in real-time.
  • Event metadata is included in the CSV reports.
  • The severity levels of the activity log have been mapped to the standard severity levels documented in the RFC.
  • The event metadata in the mirrored activity log events is in JSON format.
  • Event type and Object metadata is included in the mirrored activity log events.
  • Changes by third party plugins for which an extension is available are no longer muted when extension is not installed.
  • Removed border from the first time install wizard (minor UI improvement).
  • Support for X-ORIGINAL-FORWARDED-FOR HTTP header (more info in [support for WAFS & reverse proxies](https://melapress.com/support/kb/wp-activity-log-support-reverse-proxies-web-application-firewalls/))
  • Plugin now is using the new in-plugin pricing page.
  • A much improved default SMS alert and email notification template.
  • Revamped the connections and mirroring wizards and included connectivity tests in them.
  • Improved the external db connection (now it is a persistent connection).

Bug fixes

  • Critical error was being reported when the failed logins notification was triggered.
  • Fixed an unhandled exception which occurred when the free edition was activated on a site where the premium edition was already activated.
  • Events time stamp in emails was not always the same as in the activity log.
  • Event ID 2065 (modified content) was reported unnecessarily after adding a custom field to a post.
  • Event ID 1010 (user requested password reset) was not reported when the password reset was requested from a custom user profile page.
  • In some cases, archiving of the activity log could not be disabled.

4.2.1 (2021-03-16)

Release notes: WP Activity Log 4.2.1: Improved coverage & foundation work for 4.3

Improved activity log coverage

  • ID 6045: User changed the site language
  • ID 4029: Admin initatiated a user password reset

Improvements

  • Improved events definition (prep work for version 4.3).
  • Added the {meta} and {links} tags in email and SMS notifications.
  • Plugin reports email address used in failed login attempt instead of System.
  • Added nonce to daily email notification trigger to prevent possible CSRF issues.
  • Updated some plugin settings so they can be centrally managed from the Activity Log for MainWP extension.
  • Added more user privileges checks in the plugin (better restricted access to users who has read only access to the activity log).
  • Activity log extensions name is now displayed in admin notices.
  • Sorted the activity log extensions in alphabetical order in the plugin UI.
  • Improved the Search filters labels.

Bug fixes

  • Dates in reports were not being translated.
  • Some cron job data was left behind during uninstall.
  • A database entry was left behind during uninstall.
  • Site administrators could see some plugin pages on a multisite network (help and about).
  • Fixed some formatting issues with some of the event IDs.

4.2.0.1 (2021-02-12)

Bug fix

  • Menus sensor causing fatal error when there are changes in a menu (support tickets 1 & 2).

4.2.0 (2021-02-11)

Release notes: WP Activity Log 4.2: Support for all date & time formats & other major updates

New features

  • New date & time module that supports any type of date and time format that WordPress supports.
  • An all new activity log dashboard widget.
  • Added activity log coverage for several new WordPress settings, including automatic updates settings, date and time settings and application passwords.

Improved activity log coverage

New event IDs for changes in posts

  • ID 2129: User added / changed / removed a post’s excerpt
  • ID 2130: User added / changed / removed a post’s featured image

New event IDs for changes in WordPress settings

  • ID 6035: Changed the “Your homepage displays” WordPress setting
  • ID 6036: Changed the homepage in the WordPress setting
  • ID 6037: Changed the posts page in the WordPress settings
  • ID 6040: Changed the Timezone in the WordPress settings
  • ID 6041: Changed the Date format in the WordPress settings
  • ID 6042: Changed the Time format in the WordPress settings
  • ID 6044: User changed the WordPress automatic update settings

New event IDs for application passwords

  • ID 4025: User added / removed application password from own profile
  • ID 4026: User added / removed application password from another user’s profile
  • ID 4027: User revoked all application passwords from own profile
  • ID 4028: User revoked all application passwords from another user’s profile

New event IDs for multisite network settings

  • ID 7007: Enabled / disabled the setting “Allow site administrators to add new users to their site”
  • ID 7008: Changed the value of the Site upload space setting
  • ID 7009: Changed the value of the file size allowed in the site upload space setting
  • ID 7010: Changed the list of allowed file types on the network
  • ID 7011: Changed the value of the maximum upload file size network setting

Other new event IDs

  • ID 1010: User requested a password reset.

Improvements

  • Improved coverage of users logins, logout and failed logins activity on custom login pages.
  • Standardized the text, format and metadata formatting of all the activity log events.
  • Drastically improved the coverage of the activity logs sensors with a number of new event IDs.
  • Redesigned the activity logs extension UI.
  • Support for URL rewrites and page names (correct page title reported even if the page is a URL rewrite).
  • Default activity log SMS notifications template updated.
  • Plugins version numbers are now reported in the activity log (for example when a plugin is updated).
  • Users who hide the plugin from plugins page now get a notification when a plugin update is available.
  • Consolidated the code that generates the activity log messages.
  • Merged the Help and Contact us pages in the plugin menu.
  • Improved the Reports filters queries to address timeout issues on very big websites.
  • Replaced the “SHOW TABLES” queries for much better plugin performance.
  • Removed the “/uploads/wp-activity-log/” directory in the free edition. This is only required in premium edition.
  • Support for CloudFlare HTTP headers – plugin reports correct IP when behind CloudFlare CDN or firewall (more info on firewalls support).
  • Reports, Email & SMS notifications and other modules now fully support metadata which contains the space character. For example the user role Shop Manager.
  • Remove support for custom sensors. Custom event IDs in activity log now only supported via activity log extension plugin.
  • Completely removed the code of the old promotional events (stopped using them in 2017).
  • Removed the request log file setting. The request log file can now be enabled via a filter.
  • Removed the working directory location setting from plugin settings. Instead introduced a new wp-config.php constant: WSAL_WORKING_DIR_PATH
  • Plugin now using WP_CONTENT_DIR instead of ABSPATH were applicable (better supported by WordPress specific web hosts).
  • Added event text to event IDs 1001 and 1001.
  • The system information file now also includes all of the plugin’s settings saved in the wp_options table.
  • Simplified the process that retrieves filnames.
  • Several under the hood performance improvements (removed obsolete code, improved sensors etc.)

Breaking Change

Bug fixes

  • Event ID 1000 (user login) still logged when IP address is excluded.
  • Change in page template was not being logged with event ID 2048.
  • Event ID 2002 was not always reported in some edge cases.
  • Plugin’s directory in uploads was not being created when website was hosted on Flywheel and WordPress.com.
  • Date & time were missing in CSV reports when using some specific date and time formats in WordPress.
  • Super admin role was also shown for administrators on single site setup.
  • Plugin was not showing the correct total of sessions when deleting all sessions.
  • Plugin was generating a PHP error when a network site was deleted.
  • No event was being reported when installing activity log extensions for third party plugins.
  • Plugin installation was not running correctly when installed alongside the Website File Changes Monitor plugin.
  • The setting to configure the number of failed logins to keep a log of was reset to default each time the settings page was saved.
  • Wrong variable was used in licensing notifications, resulting in misleading error responses when license failed to activate.

4.1.5.2 (2021-01-21)

Improvement

  • Replaced Swipebox with Simple Lightbox (compatible with WordPress 5.6)

4.1.5.1 (20201123)

Improvements

  • Updated the Freemius SDK to the latest version
  • Updated the Twilio SDK to the latest version

Bug fix

  • In some edge cases, the time in the reports was incorrect.

4.1.5 (20201104)

Release notes: WP Activity Log 4.1.5: Support for new MainWP settings module & improved coverage

New features

New event ID

  • ID 7012: user changed the network’s users and sites registration settings.

Security fix

  • SQL Injection in external database module reported by WP deeply. Thank you for the responsible disclosure.

Breaking change

  • Removed detection and logging of requests to non-existing URLs (404s). Event ID 6007 and 6023 no longer used in the plugin. This breaking change resulted in a major performance improvement.

Improvements

  • Added Event Type and Object in the activity log reports.
  • Improved the coverage of the login / logout detection sensor.
  • Improved format of “hover over pop-ups” used in the activity log viewer (such as the one to exclude a specific event ID).
  • Moved almost all of the remaining WooCommerce sensor code to the activity log for WooCommerce extension.
  • Improved UX for the front-end sensors settings – options now are available underneath the relevant event ID.
  • Removed redundant code that is now in the WordPress activity log extensions.

Bug fixes

  • Sorting of activity log events not retained in following pages when in pagination mode.
  • Users sessions table was not being created when upgrading from the free to the premium editions of the plugin.
  • Link to exclude custom field in event was broken / not adding the custom field to the exclusion list.
  • Changing the category of a post was not being reported (Event ID 2016).
  • Unkown object was reported in event ID 6034 (purged activity log).
  • Changing password via the WooCommerce account page caused session to remain once user logs out.
  • Users could add multiple identical search filters causing a crash.
  • Users not redirected to the correct list of event IDs after installing the activity log for Yoast SEO extension.
  • Install Extension button in events was broken and not triggering the extension installer.

4.1.4 (20201007)

Release notes: WP Activity Log 4.1.4: New activity log for Yoast SEO extension & improved coverage

New features

New Yoast SEO activity log event IDs

  • 8826: user has enabled / disabled the Redirect Attachment URLs in the Yoast SEO plugin.
  • 8827: Usage tracking has been enabled / disabled.
  • 8828: The REST API: head endpoint setting was enabled / disabled.
  • 8829: The social profile URL was added / modified / deleted.
  • 8830: User changed the taxonomies settings to show in search results.
  • 8831: Changed the SEO title template for a taxonomy type.
  • 8832: Changed the meta description template for a taxonomy type.
  • 8833: Enabled or disabled the display of Author or Date archives.
  • 8834: Configured the plugin to show the Author or Date archived in the search results.
  • 8835: Changed the SEO title template for the Author or Date archive pages.
  • 8836: Changed the Meta description template for the Author or Date archive pages.
  • 8837: Enabled / disabled the setting to show SEO settings for specific taxonomy types.

Refer to the complete list of activity log event IDs for more detailed information.

Improvements

  • Improved the overall coverage and how events of changes in Yoast SEO plugin and YoastSEO metabox are reported.
  • Implemented a single email class that is now used by all email features in the plugin.
  • Updated Freemius SDK to the latest version (2.4.0).
  • Improved the detection mechanism of installed third party plugins used for the activity log extensions notifications.
  • Consolidated all activity log extensions code – now all third party plugins extensions use the same code.
  • Improved the plugin’s activation process on multisite network.
  • Plugin only shows file changes notifications if the Website File Changes Monitor plugin is installed.
  • Plugin prompts user to save unsaved changes in settings page before switching pages.
  • Improved plugin & activity log permissions on multisite network.
  • System information file updated to retrieve settings from the wp_options table.
  • Removed all the obsolete event IDs from the Enable/Disable events section.
  • Updated a number of filters/hooks calls that were calling deprecated ones.
  • Removed all the obsolete code which was used for the old wp_wsal_options table.
  • The handling of disabled event IDs is now done more efficiently, via filters.
  • Improved the session db adaptor which was causing errors in specific edge cases.
  • Branded the notifications for third party plugins extensions and improved the text.
  • Improved the first-time install wizard CSS to correctly display the list of required extensions for third party plugins.
  • Removed event ID 2106 (plugin updated post) and ID 8823 (Yoast SEO date snippet) because they were made redundant.
  • Moved all remaining bbPress code to the Activity Log for bbPress extension.
  • Added check to prevent identical search filters from being saved.

Security fix

  • Improper validation of nonce in plugin. Issue reported by Lenon Leite.

Bug fixes

  • Removed the old version check from the wp_wsal_options table.
  • Reset plugin settings was not deleting all the settings.
  • Reports UI was not loading in a mixed content environment.
  • Unkown object was reported in event ID 6034 (user purged activity log).
  • Custom login page message was not shown in specific edge cases.
  • Addressed a number of errors that were appearing during WooCommerce setup.
  • List of IP addresses in event ID 1005 (users has multiple logged in sessions) was incorrect.
  • Plugin was generating an error when changing the WooCommerce store address on a multisite network.
  • Event ID 1000 reported twice on websites using the OptimizeMember plugin.
  • Third party plugins detection was not detecting all plugins on multisite network.
  • Built-in email notifications couldn’t be disabled after they were enabled.
  • Notifications to install third party plugin extensions were shown in sub sites on a multisite network.
  • Event ID 1000 (user login) was reported even when user was excluded from the logs.
  • Data picker obscured by autocomplete in notifications.
  • Fixed conflict with MyCred plugin; widget sensor was killing ongoing widget requests (support ticket).

4.1.3.2 (20200814)

Improvement

Bug fixes

  • The orders details in WooCommerce were not being added to the order (Support ticket).
  • An empty space was added to the top of the WordPress admin menu.
  • Third party plugins extensions notification not showing in the activity log viewer.
  • Third party plugins extension help text was shown on the wrong pages.

4.1.3 (20200711)

Release notes: New extension for WooCommerce & other updates BREAKING CHANGE: Only update from 4.1.2 to 4.1.3 . If you are using an older version of the plugin, upgrade to 4.1.2 before upgrading to this version.

New features

New activity log event IDs

  • ID 2131: Added relationships in a custom field.
  • ID 2132: Removed relationships from a custom field.
  • ID 9101: Created new product tag in WooCommerce.
  • ID 9102: Deleted a product tag in WooCommerce.
  • ID 9103: Renamed a product tag in WooCommerce.
  • ID 9104: Changed the slug of a product tag in WooCommerce.

Refer to the complete list of activity log event IDs for more detailed information.

Improvements

  • Improved the plugin’s coverage of WooCommerce stores, products, orders etc by adding new events, and updating the current sensor.
  • Plugin now uses the default WordPress options table to store settings (performance enhancement).
  • Refactored all settings in the database so they all use yes/no values.
  • Restricted the plugin’s and activity log settings to the network dashboard only on a multisite network.
  • Change in wp_wsal_sessions table structure: now plugin uses session ID as unique identifier in table.
  • Plugin keeps the ID of the sites a user is logged in to on a multisite network.
  • Removed the Import/Export plugin settings functionality (a much better utility will be designed and launched as a replacement).
  • File changes detected by the Website File Changes Monitor plugin are now reported in the daily summary email.
  • Log files working directory in uploads directory renamed to wp-activity-log.
  • If no path is specified for the log files working directory, the default path is used.
  • Improved activity log privileges – on multisite super admin can restrict site admins from seeing their own site’s activity logs.
  • WooCommerce front end sensor is automatically enabled if admin enables events to track purchases of non-logged in users.
  • Improved the text of the third party plugins extensions notifications.
  • Updated the format of event IDs 9070 and 4020 to matches the standard template.
  • Coverage of WooCommerce coupon changes has been improved andplugin can now keep a log of usage restriction changes in coupons.
  • IP address in list of logged in users is now linked to WhatIsMyIPAddress.com.
  • Added a message for when no sessions are shown in the Logged In users section.
  • Minor changes in the plugin’s settings pages.
  • Updated some notifications used by the third party plugins extensions.
  • Third party plugins extensions are now automatically activated on multsite network when installed.
  • Removed all code that was used for file scanning. Now plugin is fully integrated with Website File Changes Monitor.

Bug fixes

  • Extensions notifications were wrongly shown to sub sites admins on multisite.
  • Event 1002 (failed user login) was wrongly reported when a user session is blocked.
  • When the setting Delete data on uninstall was enabled the plugin was not deleting all the data from the database.
  • Event ID 1002 (failed user login) incorrectly links to log file.
  • Plugin does not send logs to Activity Log for MainWP extension when child site uses a non-default admin URL.
  • Error when loading user session tokens from usermeta table in some cases.
  • Users sessions table was moved to external database when activity log is stored in an external database.
  • Plugin was reporting event ID 1000 (login) when user changes own password in user profile page.
  • Plugin’s log files working directory was hardcoded (uploads directory).
  • When super admins changed the plugin’s settings on a child site, the settings were not applied globally.
  • Users who are allowed to view the activity log can also see who is logged in.
  • The old plugin name was shown on the daily summary email template.
  • Plugin created working directory in wrong location when site address is different than WordPress address.
  • Setup wizard shows all the extensions for third party plugins instead of those for the installed plugins.
  • Wrong anchor text “view post in editor” used for WooCommerce products.
  • Unknown object reported instead of actual Object in some of the WPForms activity log events.
  • Event ID 2080 not reported when the last item was removed from the site menu.
  • Plugin logo missing from license activation screen.
  • Website File Changes Monitor custom posts type changes were reported (these are ignored by default).

4.1.2 (20200624)

Release notes: WP Activity Log fully integrated with Website File Changes Monitor

New feature

Improvements

  • Event ID 6033 now reports when [file integrity monitoring](https://melapress.com/wordpress-file-integrity-scanning-site/) scans start and stop.
  • File changes events in the activity log link directly to the changes reported in Website File Changes Monitor.
  • Log files custom path setting reverts to default path if left empty.

Bug fix

  • Plugin creating the log files outside website directory if Website URL is different than WordPress URL.

4.1.1 (20200611)

Note: this is a premium edition update only

Bug fix

4.1.0 (20200526)

Release notes: New session policies per user roles & other improvements

BREAKING CHANGE

  • The new users sessions management module uses the plugin’s own data. Therefore it will not show the users who have been logged in before the plugin was updated as logged in. They will be shown once they logout and log back in and the new session is created.

New features

Plugin improvements

  • Activity log reports now support user roles which have the space character in the name.
  • Removed more legacy code from the plugin (the check for encryption method).
  • Removed old update scripts (for when updating from versions prior to 3.5.2).
  • Moved 10 more plugin settings from the custom table to the wp_options table (performance improvement).
  • Standardized the format of all placeholders in the UI (now they are all using default WordPress format).
  • Removed premium only code from free edition.

Bug fixes

  • Scheduled daily reports included data of the last 24 hours instead of the previous day.
  • Resaving the activity logs archiving settings generated errors (didnโ€™t check if connection was already setup).
  • Issue with the plugin when installed on MainWP child sites (support ticket).
  • Plugin adding Menu entry with no title (used by the wizard).

4.0.4 (20200520)

WP Security Audit Log renamed to WP Activity Log (read the announcement).

4.0.3 (20200416)

Release notes: Update 4.0.3 – Support for WooCommerce 4.0 & new bbPress add-on

BREAKING CHANGE

  • The old individual add-ons are no longer supported.

New features

New activity log event IDs

  • 9105: The stock quantity of a product was changed due to an order.
  • 9085: The WooCommerce setting “Selling location(s)” was changed.
  • 9086: List of excluded countries to sell to in WooCommerce was changed.
  • 9087: List of countries to sell to in WooCommerce was changed.
  • 9088: The WooCommerce setting “Shipping location(s)” was changed.
  • 9090: The WooCommerce setting “Default custom location” was changed.
  • 9091: The “Cart page” in the WooCommerce settings was changed.
  • 9092: The “Checkout page” in the WooCommerce settings was changed.
  • 9093: The “My Account page” in the WooCommerce settings was changed.
  • 9094: The “Terms & conditions page” in the WooCommerce settings was changed.

Improvements

  • Improved the coverage of the WooCommerce activity log sensor.
  • WooCommerce sensor now detects changes done from the new WooCommerce Admin interface.
  • Event 9029 (WooCommerce store base location change) now reports both the old and new address.
  • Updated WooCommerce sensor to detect all the changes in tax options (event IDs 9078 – 9081).
  • Changed the event type from Modified to Renamed in the events where in which the object is renamed.
  • “Plugins” is reported instead of a username when a change is done automatically by a plugin.
  • Improved the activity logs external database connection test during connection setup.
  • Removed obsolete code which was only used in previous versions from the defaults.php file.
  • Improved event ID 2055 (deleted custom field) so it is not reported when a custom field is deleted autoamtically due to the post being deleted.
  • Removed redundant filters wsal_event_type_text and wsal_event_object_text.
  • Moved 10 plugin settings to the WordPress options table as part of the plugin improvement project.
  • External database connector now reports actual MySQL error for improved troubleshooting.
  • All the changes done to a bbPress forum or topic are reported, even when done at the same time.

Bug fixes

  • Event ID 8808 not firing when Cornerstone article setting is enabled or disabled in a post.
  • Event ID 9066 not firing when the expiry date of a WooCommerce coupon is changed.
  • Plugin reporting event ID 2001 instead of 5019 when a plugin automatically creates posts.
  • Fixed a minor compatibility issue in the Hide plugin functionality (support ticket).
  • Event ID 9063 reported instead of event ID 9071 when reporting a WooCommerce coupon change.
  • Events ID 1005 (multiple sessions detected) and 1007 (user terminated another user’s session) were only working when front-end sensor was enabled.
  • Activity logs view buttons link to first site on network instead of network dashboard on multisite network.
  • Error reported when the role property was undefined.
  • Fixed a PHP 7.3 compatibility issue (support ticket).

4.0.2 (20200228)

Security fix

  • Added authentication check for the first-time install wizard. This addresses an edge case in which if the wizard was never completed by the user, unauthenticated users could run the wizard and give access to the plugin settings to WordPress users.

Improvements

  • Removed the setting / functionality to allow access to users with non-admin role to the plugin settings. Now users who require access to the plugin settings need to have the admin role.
  • Removed the โ€œactivity log view accessโ€ and the โ€œexclude objectsโ€ steps from the install wizard. These are advanced settings.
  • Check the role of users trying to import settings file and deny if it does not have admin role.

4.0.1 (20200213)

Release notes: Announcing activity logs for WPForms & add-ons in 4.0.1

New features

Improvements

  • Updated event IDs 2123, 2062, 2084, 9077 and 9071 so they now use the “Renamed” event type.
  • Updated the activity log severity levels definitions in defaults.php.
  • Updated / improved some of the help text messages.
  • Plugin does not automatically retrieve the IP addresses and latest change of logged in users if there are 100+ sessions (performance improvement).
  • Localized text in JS files.
  • Started removing obsolete code.

Bug fixes

  • Only the path of the added, modified or deleted file was reported in daily summary email.

4.0.0 (20200108)

Release notes: The all new more comprehensive, yet easier to read WordPress activity log

New features

Improvements

  • Updated the severity levels of all activity log events.
  • Updated the Freemius SDK to version 2.3.2.
  • Included the two new metadata types in the email notification templates (event type and object metadata).
  • Added a notification to refresh search when the filters change.
  • Added several new reference links in the plugin’s help text.

Bug fixes

  • Addressed a warning message in the logs generated by the connector when using PHP 7.4.
  • Fixed an issue which was triggered when using the User Switching filter hook.
  • Few spelling mistakes in the plugin’s UI and settings pages.

Back to latest changelog

Close the CTA
Were you able to find what you were looking for?