BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off →
sHub-Log icon
Actively maintained Tested with WP 7.1 #1 in attack log

sHub-Log

Records suspicious login attempts, 404s, and malicious requests, then blocks IPs after repeated attempts.

Active installs10+10+ tier
Downloads · 30d98▼ -85.1% vs prev. 30d
Rating—0 reviews
Health score62/100Good
All-time downloads2.1KSince Apr 2025
Support resolved—No recent threads
RequiresWP 5.0PHP 7.2+
Downloads · 7d21▲ +75% week over week
Our verdict

Solid choice

sHub-Log is a solid plugin choice in 2026, with a few things worth checking first. It runs on 10+ sites and was last updated 1 month ago, and scores 62/100 on our health check.

  • Tested with the latest WordPress (7.1)
  • Small user base (10+ active installs)
  • Very few reviews so far

Daily downloads

193857Jul 9Aug 22Oct 6
Yesterday3
Daily average (1y)5
Peak day76Jul 18, 2026
Last 12 months2K

Download spikes usually follow a new release — each site that auto-updates counts as a download.

Rankings

Where sHub-Log stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
attack log #96 721 Best attack log plugins →
IP-blocking >100 1,162 Best IP-blocking plugins →
protection >100 5,643 Best protection plugins →
security >100 10,000 Best security plugins →

Version adoption

Share of active sites per release.

  • 1.3100.0%

About sHub-Log

From the official readme · v1.3.7

Description

sHub-Log strengthens WordPress site security.

Main features:

  • Login attempt logging
  • Category-based detection (config scans, backdoors, plugin vulnerability scans, admin hacking, spam, and more)
  • Optional detection for malicious queries, high-volume requests, and REST API abuse
  • Attack summary and detailed logs for a configurable period
  • Attack trend charts with selectable period and aggregation interval
  • CSV export and AJAX category filtering
  • Configurable attack log retention with WP-Cron cleanup
  • Attack spike email alerts with cooldown
  • Optional signed remote alert and scoring definitions from syn-c.jp
  • IP blocking after repeated failures
  • Configurable block duration and redirect URL
  • Admin dashboard for logs and IP management
  • Customizable rate-limit thresholds and windows
  • Optional attack-signal-only rate counting
  • Exclusion of logged-in users and verified search/AI bots from rate counting
  • Verified bot access logging (14-day retention, disabled by default)
  • Suspicious 404 flood detection
  • IP whitelist and trusted proxy support (auto-trust private proxies and Cloudflare)
  • Per-IP risk scoring (disabled by default)
  • Administrator IP memory to reduce self-lockouts
  • Optional paid license (offline signed code) for 90-day log retention and page-level analytics

Installation

  1. Upload or install the plugin
  2. Activate the plugin
  3. Configure settings from the sHub-Log admin menu

Frequently asked questions

How do I unblock an IP address?

Open sHub-Log → Security Trend, scroll to Protected IP, and unblock the address from the list.

Does the plugin make external requests?

When attack spike alerts are enabled, the plugin may fetch alert definitions and email templates from syn-c.jp. When remote scoring is enabled, it may fetch a signed score-config.json from syn-c.jp. When verified bot exclusion is enabled, it may fetch published IP range JSON from bot vendors (cached for 24 hours). License verification is performed entirely on the site (offline signed license codes) and does not contact syn-c.jp, except around expiry: during the renewal-warning window and the 14-day post-expiry grace, the plugin may request a signed renewal payload from syn-c.jp. If that…

What should I check after updating to 1.2.6?

If you saved settings from Basic Settings or Bot Logging Settings before the settings-group fix in 1.2.6, review Advanced Settings or use the Recommended settings button on Basic Settings to restore factory defaults. Recommended factory defaults: Setting Default Login attempt limit window 5 minutes Login attempt limit count 5 Block duration 60 minutes High-volume request threshold 90/minute 404 flood threshold 30/5 minutes Attack spike email alerts OFF Risk scoring OFF Bot access logging OFF (search bot logging ON / AI bot logging OFF when enabled) Auto-trust private proxies / Cloudflare ON…

Changelog

Adds a Dashboard, an Upgrade to Paid comparison screen, and REST Path Probe detection for short-window REST/install-path scans.

1.3.7

  • Added a Dashboard with 14-day Security, Search Bot, and AI Bot trend charts. Chart titles open the matching screens.
  • Added Upgrade to Paid in the left menu, with a Free vs Paid comparison and checkout link for free sites.
  • Added REST Path Probe detection for short-window scans that vary WordPress install locations and REST entry routes (including /batch/v1 variants). Legitimate /batch/v1 use is not blocked by path alone.

1.3.6

  • Added French, Spanish, German, Italian language packs (fr_FR, es_ES, de_DE, it_IT).
  • Around license expiry (renewal warning window through the 14-day grace), the plugin may fetch a signed renewal payload from syn-c.jp and apply a replacement license code when valid.
  • If the renewal request or signature check fails, the existing offline license remains in effect.
  • Purchase / issue URL default is https://syn-c.jp/payment/shub-log-annual-checkout/

1.3.5

  • Keep the sHub-Log admin menu open on Attack Log and Protected IP Addresses, and list both screens in the left menu.
  • Indent Attack Log and Protected IP Addresses in the left menu to read as children of Security Trend.
  • Add navigation buttons to move between Attack Log and Protected IP Addresses.
  • Translate remaining attack-category labels (Theme Vulnerability Scan, User Enumeration, Bot Impersonation, Scanner Tool) in ja, ko_KR, zh_CN, zh_TW, vi, and th.

1.3.4

  • Added offline signed license codes for paid features (90-day log retention and page-level logs). Verification stays on the site and does not contact syn-c.jp.
  • After expiry, paid UI stops immediately. 90-day log retention continues for 14 days so daily cleanup does not delete days 15-90 at once.
  • Renewal warnings: 7 days left for terms of 60 days or less (monthly), 30 days left for longer terms (annual).
  • License field on Basic Settings. The existing paid-preview switch remains for SyntaxCloud verification.
  • Fixed bot/attack summary cache keys so cache clears match the keys that are stored.
  • Attack log retention option now stays in sync with the derived paid/free value.

1.3.3

  • Aligned the admin header bar width with the trend chart panels.
  • Admin header titles now include /sHub-Log (e.g. Security Trend/sHub-Log).
  • Free Security Trend: attack summary category cards and labels no longer look like links.
  • Enlarged the admin header plugin icon by about 25%.

1.3.2

  • Added translations (ja, ko_KR, zh_CN, zh_TW, vi, th) for Security/Search/AI Bot page-access copy, table headers, and the Advanced Settings paid-preview switch.
  • Enlarged the admin header plugin icon by about 20%.

Full changelog on WordPress.org →

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.

Active installs badge Rating badge Health score badge

FAQ

sHub-Log: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org · checked Oct 7, 2026

Is sHub-Log free?

Yes. sHub-Log is free to download and use from the official WordPress.org plugin directory.

Is sHub-Log safe to use in 2026?

sHub-Log is a solid plugin choice in 2026, with a few things worth checking first. It runs on 10+ sites and was last updated 1 month ago, and scores 62/100 on our health check.

How many websites use sHub-Log?

sHub-Log is active on 10+ WordPress websites and has been downloaded 2,124 times since it launched in April 2025. It was downloaded 98 times in the last 30 days.

Does sHub-Log work with WordPress 7.1?

Yes. The developer has tested sHub-Log up to WordPress 7.1.3, the latest release. It requires WordPress 5.0 or newer.

What PHP version does sHub-Log need?

sHub-Log requires PHP 7.2 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was sHub-Log last updated?

The latest version, 1.3.7, was released on September 3, 2026 (1 month ago).

Who makes sHub-Log?

sHub-Log is developed and maintained by SyntaxCloud LLC.

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org — no credit card
Sarah is here to help!
Hi there! 👋 Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! 👋 Need help finding what you're looking for?

We'll use this to continue our conversation

Just now ✓ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.