Linux 软件免费装
Banner图

Orbilog Activity Monitor

开发者 yeasinarafathridoy
更新时间 2026年9月17日 15:09
PHP版本: 7.4 及以上
WordPress版本: 7.1
版权: GPLv2 or later
版权网址: 版权信息

标签

security activity log audit log user activity event log

下载

详情介绍:

Something changed on your site and nobody remembers doing it. Orbilog keeps a plain, readable record so you can find out. Every entry answers four questions: who did it, what they did, when, and from where.
John Smith (Editor) updated the page "About Us" — 8 September 2026 at 10:30, from 203.0.113.0
What it records Built to be trustworthy Finding things Search by user, activity, content title, event ID, or IP address. Filter by date range, user, role, activity type, and severity. Export whatever you are looking at to CSV — with spreadsheet formula injection blocked. Keeping it tidy Choose how long to keep entries: 30, 60, 90, 180, or 365 days, or forever. The default is 90 days, and old entries are cleared once a day automatically. You can exclude specific users, roles, or IP addresses from being recorded at all. Permissions Four separate permissions — view, export, change settings, and delete — can each be granted per role. Administrators always keep all four. An editor can be given read-only access to the log without gaining anything else. Privacy Orbilog registers with the built-in WordPress personal data tools. An export includes a person's own entries. An erase request keeps the entries as a security record but removes the login name and IP address from them.

安装:

  1. Upload the orbilog-activity-monitor folder to /wp-content/plugins/, or install it through Plugins → Add New.
  2. Activate the plugin through the Plugins screen.
  3. Open Orbilog in the admin menu. Recording starts immediately.
  4. Visit Orbilog → Settings to choose a retention period and how IP addresses are handled.

升级注意事项:

1.0.0 First release.

常见问题:

Does this send my data anywhere?

No. Orbilog makes no outbound requests. Everything is stored in a table in your own database.

Are passwords ever stored?

No. Password changes are recorded as events, but no password — plain or hashed — is ever written to the log. Reset links, activation keys, cookies, session tokens, and API keys are stripped as well.

Will it slow my site down?

Entries are written only when something actually changes, which in practice means admin requests rather than visitor page views. The log table is indexed on every column you can filter by.

What happens if logging fails?

Nothing visible. Every write is wrapped so that a database problem cannot stop someone signing in, publishing a post, or updating a plugin.

Is my log deleted when I remove the plugin?

Only if you ask for it. Deactivating never deletes anything. Uninstalling deletes data only when you have turned that on under Privacy and tools.

Why is an action missing from the log?

Check whether that activity type is switched off in Settings, whether the user, role, or IP is on an exclusion list, and whether the entry is older than your retention period. Changes made directly in the database are invisible to any activity log.

Does it work on multisite?

Each site keeps its own log. A network-wide view is planned for a future release.

更新日志:

1.0.0