Skip to content

See what happened on a site

Read the activity log of one site and its WordPress logins: who did what, when, from where, and whether it worked. Search, filter, and export it.

The User activity tab is the audit log of one site. Every change to the site is recorded with the person or key that made it. Open your site, then User activity, to read it.

Open it

  1. Open your site.
  2. Choose User activity.

Each row shows who did something, what they did, when, and whether it worked. A failed action shows as failed, so you can see attempts as well as results.

Search and filter the list

Search for words in the action, such as a plugin name. Then narrow the list by:

  • person, to see one teammate's actions,
  • API key, to see what one key did,
  • action type: logins and access, users, plugins and themes, files and backups, code and deploys, domains and security, or settings and tools, and
  • date range: the last 24 hours, 7 days, 30 days, or 90 days.

Use the refresh button to load new rows.

AI agents show the client name and the key they used, such as Claude Desktop via your key, so you can tell an agent's action from your own.

WordPress logins

The WordPress logins tab lists sign-ins on WordPress itself for the environment you are looking at: logins with a password, one-click logins from Avaloi, and wrong passwords. The Avaloi MU plugin keeps the last 200 attempts. Filter by result or date range, or search a username or IP address. You need the WordPress users permission to see this tab.

IP addresses and export

Owners and admins see the IP address of each row and can choose Export CSV to download the rows that match the filters (up to 2,000 rows of dashboard activity).

Go back further

The tab shows the newest rows first. Use the numbered pages to go back further. Through the API, the list is paged like every other list. See Pagination.

What gets recorded

Every change that runs as a job is recorded, and so are credential reveals. The row for a reveal names who revealed the secret and when. Reads that change nothing, such as opening a tab, are not listed.

Company-wide activity

User activity covers one site. For every site and for company changes such as members, API keys, and SSO, read the company activity log from your company settings.

Quick answers

Who deployed the last release? Set the action type to code and deploys. The row names the person or the key.

Why does a row name an AI agent? Someone connected an agent such as Claude Desktop with their API key. The row shows the client and the key it used.

Can I see what an API key did across all my sites? On one site, filter by API key. For every site, use the company activity log.

How do I see attempts that failed? Each row shows whether it worked. Failed attempts stay in the list.

API

  • GET /v1/sites/{id}/activity with actor, category, q, from, and to
  • GET /v1/environments/{id}/wp-login-events
  • GET /v1/companies/me/activity

Still stuck?

Email [email protected] with your site name and what you tried, or send us a message.