Skip to main content
← Back to help

Using the WordPress activity log

See what the Destiny Manage connector records, where new events appear, and how to search and filter activity across client websites.

6 min read

1

Install connector 1.6.0 or newer

The WordPress activity log is included on Free and paid plans. Activity is captured by the Destiny Manage connector plugin. Open Websites -> WordPress Plugin to download the current ZIP, then install or update it on each client site. Once the connected site reports connector version 1.6.0 or newer, new WordPress actions are queued automatically. The log starts from that point; it does not reconstruct actions that happened before the connector was updated.

2

Open the agency-wide activity timeline

In Destiny Manage, open Websites and select WordPress Activity. The newest events appear first, with the action summary, WordPress user, role, IP address, website, action type, source, and event time. The screen refreshes regularly, so an event normally appears within seconds. If the Destiny Manage API is temporarily unavailable, the connector retains the event locally and retries it.

3

Search and filter the log

Use the main search box for an action summary, page or media name, WordPress username, display name, or IP address. The separate filters narrow the list by website, user, category, action, severity, and date. Filters run on the server and every page contains 25 records, so searches stay responsive without loading an entire agency history into the browser.

4

Open an event's details

Select View details when an event includes additional context. Content and settings changes show focused before-and-after values, with the original character lengths where relevant. Large Gutenberg, page-builder, and ACF documents are reduced to the area around the change rather than copied in full. When WordPress provides a safe link, the event also opens the affected page, media item, user, comment, menu, or settings screen in a new tab.

5

Understand what is and is not captured

The connector records actions that pass through WordPress: authentication, users, posts, pages, supported custom post types, Site Editor content, media, plugins, themes, core updates, selected settings, widgets, menus, comments, and taxonomies. It also recognises common Gutenberg, Bricks, Fusion, Elementor, Beaver Builder, Divi, Oxygen, and ACF data. Direct filesystem changes through SFTP, SSH, a host file manager, or another server process do not pass through WordPress and therefore need separate file-integrity monitoring.

6

Retention, privacy, and failed logins

Activity is retained for 90 days by default. Secret-like fields such as passwords, tokens, cookies, nonces, API keys, and licence keys are redacted, and payload sizes are bounded. Repeated failed logins for the same username and IP are grouped into a five-minute event with an occurrence count, keeping an attack visible without creating an unlimited row for every attempt.

Cookie Consent Preferences

We use cookies to enhance your browsing experience, serve personalized content, and analyze our traffic. By clicking "Accept All", you consent to our use of all cookies. You can manage your preferences or read our Cookie Policy for details.