Dragon Activity Log – Audit Log, User Activity Tracking & Security Audit Trail
A tamper-evident activity log for WordPress. See who changed what, when, and from where, with field-level before/after detail.
Solid choice
Dragon Activity Log is a solid plugin choice in 2026, with a few things worth checking first. Was last updated 6 days ago, and scores 64/100 on our health check.
- Actively developed — last update 6 days ago
- Tested with the latest WordPress (7.1)
- Small user base (<10 active installs)
- Very few reviews so far
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where Dragon Activity Log stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| Activity Log | >100 |
| audit log | >100 |
| audit trail | #76 |
| security | >100 |
| user activity | >100 |
About Dragon Activity Log
From the official readme · v1.0.21Description
Dragon Activity Log records what happens on your WordPress site in a fast, searchable audit trail that lives in its own database table. Unlike a plain event list, it shows the field-level change for the fields listed below (the old role and the new role, the old setting value and the new one, a renamed title or slug), and it links every event to the one before it with a SHA-256 hash so that a later edit or deletion of the log can be detected.
Everything in this plugin is free and fully functional: every event type, no cap on the number of events stored, any retention window including “keep forever”, all filters and search, live updates, integrity verification, and the WP-CLI commands. (Individual values in the change detail are shortened at 500 characters.)
Why Dragon Activity Log
- Field-level change detail – before and after values for post title, slug and excerpt, user email, display name, URL and roles, media title, caption and alt text, and single-value settings (array settings show their item count; post bodies are flagged as changed, not stored)
- Tamper-evident hash chain – every event is chained to the previous one; one click checks the chain (up to 25 seconds in the browser; the WP-CLI command checks a log of any size end to end) and reports the first event whose link no longer matches
- Off-site anchor – email (and optionally post to a signed webhook) the chain head daily or weekly, then compare the log against any anchor later: proof that the log was not rewritten, even by someone with database access
- Site Health – an integrity test and an anchor test on the Site Health screen, plus a debug-information section
- Fast and lean – events live in their own indexed table, never in your posts table, and are pruned automatically on the retention window you choose
- Live activity stream – new activity appears on the log screen as it happens
- Privacy controls – capture, anonymize or skip IP addresses, and exclude trusted roles from logging
- Privacy tools integration – events caused by a user, events about their account, failed logins against their username or email, and events about comments they wrote (guests included) are covered by WordPress personal data export and erasure requests
- WP-CLI –
wp dragon-activity-log list,prune,anchorandverify
What gets logged
- Logins – successful logins, logouts, failed logins, password resets
- Users – registration, profile changes, role changes, deletion, and on multisite removal from a site and super admin grants and revocations
- Content – posts, pages and custom post types: create, edit, status change, trash, restore, delete
- Plugins and themes – activate, deactivate, install, update (and a failed single update), delete, switch
- Settings – WordPress and plugin option changes and deletions, with secret-shaped values redacted (option writes made by background cron tasks are skipped unless they touch core settings)
- Media – uploads, title, caption and alt text edits, deletions
- Taxonomies – term create, edit and delete for categories, tags, menus and custom taxonomies
- Comments – submitted, approved, unapproved, spam, trashed, deleted
- Core – WordPress core updates and content exports
WP-CLI
wp dragon-activity-log list [--limit=<n>] [--event=<code>]wp dragon-activity-log prunewp dragon-activity-log anchor– send an off-site anchor nowwp dragon-activity-log verify [--anchor=<reference>]
Dragon Activity Log Pro
Dragon Activity Log Pro is a separate paid add-on that adds rich content diffs and one-click rollback, security alerts, streaming to Slack and signed webhooks, session management, reports with CSV and JSON export, and WooCommerce events. None of that code ships in this plugin, and nothing here is limited or locked without it.
External services
This plugin does not connect to any external service of ours or of any third party. All logging, hashing and verification runs on your own server.
The optional off-site anchor sends the chain head (an event number, a hash, your site URL and a timestamp; never any event data) to a destination you configure: by email through your site’s normal mail delivery, and, only if you enter a webhook URL, by an HTTPS POST to that URL. Nothing is sent unless you turn the anchor on.
Credits
The WordPress.org listing icon is drawn with glyphs from Lucide (https://lucide.dev), ISC License. Copyright (c) for portions of Lucide are held by Cole Bemis 2013-2022 as part of Feather (https://feathericons.com, MIT License). All other copyright (c) for Lucide are held by Lucide Contributors 2022. The plugin itself does not include these icons.
Privacy Policy
Dragon Activity Log stores activity data locally in your WordPress database, including usernames, IP addresses (unless disabled or anonymized), and details of changes made on your site. It does not send any data to third parties. IP capture can be disabled or anonymized in the settings. WordPress personal data export and erasure requests are matched by email address and cover events caused by the user, events about their account, failed logins against their username or email, and events about comments written with that email (so guest commenters are covered too). Events about comments that have since been deleted can no longer be matched to an email address.
Installation
- Upload the
dragon-activity-logfolder to/wp-content/plugins/, or install it from the Plugins screen. - Activate the plugin through the Plugins screen in WordPress.
- Go to Tools > Activity Log. Events start recording immediately; the Settings tab holds retention and privacy options.
Frequently asked questions
Does this slow down my site?
Logging is a single indexed database write per action. The tamper-evidence hashing runs separately: an hourly WP-Cron job, plus a short end-of-request pass on roughly one request in twenty (capped at 200 events and two seconds) after the page has been generated.
How does the tamper-evidence work?
Each event stores a SHA-256 hash computed over its own contents plus the previous event’s hash, forming a chain. Editing or deleting any event breaks the chain from that point on, and the integrity check reports the first broken link. This is tamper evidence: it detects edits and deletions made outside the plugin, it does not prevent someone with database access from making them. Use it alongside normal access control and backups.
What can the integrity check not catch?
Two things, by design. First, events are hashed into the chain by a background pass (hourly, plus a short end-of-request pass), so a row deleted before it is sealed leaves no trace; on a quiet site without WP-Cron traffic that window can be up to an hour. Second, someone with write access to your database who also recomputes every later hash and the stored chain head can hide an edit from the self-check. That is what the off-site anchor is for: compare the log against an anchor you received earlier and such a rewrite is caught. Clearing the log or erasing someone’s data rebuilds the chain…
How does the off-site anchor work?
On the Settings tab, choose daily or weekly. On that schedule the plugin seals the chain and emails the chain head (an event number and a hash, never any event data) to the address you choose; ideally one outside this site. You can also have it posted to an https webhook you control, signed with a per-site secret. Keep those messages. At any time, paste an anchor reference into Integrity > “Compare with an anchor” (or run wp dragon-activity-log verify --anchor=): the plugin recomputes the chain up to that event and confirms it still produces the anchored hash. “Send anchor now” takes one…
Does the plugin send data anywhere?
Not to us or to any third party. Events are stored in a dedicated wp_dal_events table in your own database. The only thing that ever leaves your site is the optional off-site anchor described above (an event number and a hash), and only to the email address and webhook you configure.
Which IP address is recorded?
By default the connecting address (REMOTE_ADDR). Proxy headers such as X-Forwarded-For are ignored unless you enable “Trust proxy headers”, because visitors can forge them. You can also anonymize IP addresses or turn capture off entirely.
Can I keep events forever?
Yes. Set the retention to 0 days on the Settings tab.
What is not logged?
Editor autosaves, background (cron) option writes other than core settings, the plugin’s own bookkeeping options, first/last name, nickname and biography changes (email, display name, URL, password and roles are covered), network-wide (multisite) settings, and the success of each package in a bulk plugin or theme update (the update run is recorded per requested package). Settings that plugins use for their own bookkeeping are skipped too: names containing _cache or _last_, or ending in _version, db_version or _lock, the options WordPress writes during a theme switch, and the routine re-checks…
What is redacted?
Option and field names that look like secrets are recorded as “[redacted]” and their values are never read by the plugin: anything containing password, pass, pwd, secret, token, auth, nonce, salt, private, api, license, licence or credential, or containing _key. Password changes are recorded as “(changed)”, never the hash. Post bodies are never stored, only the fact that the content changed. Settings stored as JSON or serialized text are summarised like arrays. Before a change is handed to an add-on such as Dragon Activity Log Pro, nested keys with a secret-shaped name segment (for example…
Changelog
Closes a way to hide an edited event from the integrity check and the off-site anchor. Retention cleanup now checks the chain first and pauses if it is broken. Recommended for everyone.
1.0.21
- Fixed: someone with database access could hide an edited event from both the integrity check and the off-site anchor by changing one setting. The chain now refuses that, and anchors whose events were removed are only explained by a matching event recorded in the sealed log itself.
- Retention cleanup checks the chain before it deletes anything, records every cleanup that removes events as an event, and never removes events that are not sealed yet. If the chain is broken, cleanup pauses and the Settings tab and Site Health say so.
- An anchor that can no longer be checked says why and names the event that explains it; it is never shown as a match. The command line exits with 2 in that case and with 1 for a failed or busy check. “Beyond the current chain” is gone: a truncated log now reads as broken.
- A database read error during a check is reported as such, not as tampering or a timeout. A check that finished on its last batch no longer reads as out of time.
- The anchor webhook signing secret is stored encrypted, redirects are not followed, and the last anchor shows whether it was delivered.
- Logging: failed single plugin and theme updates, removal from a network site and super admin grants are recorded; settings saved without a real change, a theme switch’s own bookkeeping and Dragon Pro licence re-checks no longer add rows; a role grant before a role change is kept; settings changed late in a request are recorded.
- Secrets: credentials inside serialized settings are no longer stored, and nested secret keys are redacted before a change reaches an add-on. The anchor webhook address is recorded as its host only.
- Settings: an invalid retention, anchor email or trusted proxy entry is rejected with a message and the previous value is kept, and a setting that could not be saved is reported.
- Privacy export: events about a person that someone else caused no longer include that other person’s IP address or username.
- Uninstall deletes data only when the opt-in is clearly on (1, true, yes or on), not for “false” or “no”.
- Fixed: a search for “0” filtered nothing, very long role names lost the event,
list --format=idsprinted “Array”, and a proxy that appends a port recorded its own address. - Each admin action checks its own security token and your permission, and every submitted value goes through WordPress’s own sanitizers.
- A plugin update is logged under the plugin’s new name even when the plugin list was read earlier in the same request.
- Fixed: saving settings with a malformed webhook field no longer writes a PHP warning to the debug log.
1.0.20
- Fixed: since 1.0.11, a change to a setting that holds a secret (an API key, token, licence key or password) was not logged at all. It is now logged as “Changed (value hidden)”, and the secret itself is never stored.
- Setting a secret and then setting it back in the same request is not logged, as there was no net change.
1.0.19
- Anchor checks only accept a clear or privacy erasure recorded inside the sealed log itself, so a gap cannot be hidden by editing a setting. Rewrites still show as a mismatch.
- An anchor due while the log is being resealed is retried 15 minutes later instead of being skipped.
- Anchors made before a Clear log or an erasure report the events as rebuilt or erased, not rewritten.
- Sites upgrading straight from 1.0.0 keep their retention and exclusion settings.
1.0.18
- Anchor checks now say when older events were removed by retention cleanup or a privacy erasure, instead of reporting a broken chain.
- Clear, rebuild and erasure events show readable details.
- Settings that other Dragon plugins use for their own bookkeeping are no longer logged as setting changes.
- Log times follow your site’s date format.
1.0.17
- Every screen, email and alert is now translatable, so community translations from translate.wordpress.org cover the whole plugin. Counts use proper plural forms, and numbers and dates follow your site’s language.
- Clear, rebuild and privacy-erasure events show readable details in the log and the live stream.
- The personal-data export lists changes as readable lines instead of raw data.
- Log times follow your site’s date format.
1.0.16
- Fixed: when one of this plugin’s scheduled tasks needed re-creating, it was scheduled before WordPress had finished loading, which made WordPress log “translation loading was triggered too early” notices that named other plugins. Scheduling now waits until WordPress is ready. The notices only appeared with debug logging switched on.
Screenshots
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
Best Dragon Activity Log alternatives
All Activity Log plugins →FAQ
Dragon Activity Log: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Oct 8, 2026
Is Dragon Activity Log free?
Yes. Dragon Activity Log is free to download and use from the official WordPress.org plugin directory.
Is Dragon Activity Log safe to use in 2026?
Dragon Activity Log is a solid plugin choice in 2026, with a few things worth checking first. Was last updated 6 days ago, and scores 64/100 on our health check.
How many websites use Dragon Activity Log?
Dragon Activity Log is active on <10 WordPress websites and has been downloaded 416 times since it launched in September 2026. It was downloaded 422 times in the last 30 days.
Does Dragon Activity Log work with WordPress 7.1?
Yes. The developer has tested Dragon Activity Log up to WordPress 7.1.3, the latest release. It requires WordPress 6.2 or newer.
What PHP version does Dragon Activity Log need?
Dragon Activity Log requires PHP 8.0 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was Dragon Activity Log last updated?
The latest version, 1.0.21, was released on October 2, 2026 (6 days ago).
Who makes Dragon Activity Log?
Dragon Activity Log is developed and maintained by Dragon Core.
What are the best alternatives to Dragon Activity Log?
The most popular alternatives to Dragon Activity Log are WP Activity Log (300K+ installs), Activity Log (200K+ installs) and Stream (70K+ installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card