Backtrail is not a full activity-log plugin. It's a minimal debugging tool
that answers one question: "What happened right before the site broke?"
It logs:
- Plugin activation / deactivation / updates
- Theme switches, theme updates and Customizer changes
- Post/page creation, edits, deletions and trash/restore
- PHP fatal errors (the actual "site broke" moment)
- Permalink structure changes (a common, silent cause of sudden 404s)
Each logged change is tagged with a rough risk level (High / Medium / Low), based on
how likely that type of change is to be the actual cause when something breaks.
Code changes like plugin/theme updates rank higher than a content edit.
If a burst of changes happens in a short window, the "Backtrail" page in wp-admin
(and a small indicator in the admin bar, visible everywhere) shows a warning, so an
admin can quickly see whether something was recently changed before starting to debug.
You can also mark the exact moment something broke ("Mark as incident"), and the
plugin highlights everything that happened in the hour before it. You can also
filter by type, search, copy a plain-text summary to paste into a support ticket,
or export the log as CSV.
If wp-admin itself becomes unreachable, the log is still readable via WP-CLI:
wp backtrail list.