Descripción
Usado por más de 300 000 sitios WordPress, valorado con 4,9 estrellas con más de 430 reseñas de cinco estrellas, desarrollado activamente durante más de 10 años y traducido a más de 15 idiomas.
Simple History es el registro de auditoría completo para WordPress. Registra todos los cambios importantes (ediciones de contenido, inicios de sesión de usuarios, actualizaciones de plugins, eventos de seguridad y más) para que los propietarios de sitios, equipos, agencias y desarrolladores sepan siempre quién hizo qué y cuándo. Solo instala y activa, no se necesita configuración.
🔍 Cómo ayuda Simple History en situaciones reales
Registra lo que ocurre en tu sitio
“¿Alguien ha hecho algo hoy? Ah, Sarah subió el nuevo comunicado de prensa y creó un artículo para él. Genial, ahora no tengo que hacerlo yo.”
Identifica problemas y depura más rápido
“El sitio va lento desde ayer. ¿Alguien ha hecho algo especial? … Ah, Steven activó “naughty-plugin-x”, debe ser eso.”
Mantén a los autónomos y agencias responsables
“Contraté a un desarrollador para optimizar mi sitio. Pero, ¿realmente hicieron algo? Un vistazo rápido a Simple History me muestra exactamente en qué trabajaron.”
Detecta actividad sospechosa a tiempo
“Veo tres inicios de sesión fallidos desde una dirección IP desconocida durante la noche. Voy a hacer clic en la IP para comprobar toda la actividad desde esa dirección, solo esos intentos, nada más. Bueno saberlo.”
✨ Lo que Simple History registra
Seguridad y monitorización
- Inicios de sesión fallidos con seguimiento de IP y filtrado por tipo (contraseña incorrecta frente a nombre de usuario inexistente)
- Comprobaciones de integridad de archivos del núcleo contra sumas de comprobación oficiales
- Actualizaciones automáticas de seguridad forzadas desde WordPress.org
- Cambios en el estado de salud del sitio
- Eventos de acceso denegado a páginas de administración
Contenido y usuarios
- Entradas, páginas y tipos de contenido personalizados: creación, edición, borrado y asignación como página de inicio
- Archivos adjuntos con detalles de edición de imagen (recortar, rotar, voltear, escalar) y vistas previas de miniaturas
- Taxonomías con diferencias detalladas de nombre, slug, descripción y principal
- Comentarios, menús (con detalle a nivel de elemento) y widgets
- Perfiles de usuario, inicios de sesión, cierres de sesión y cambios de perfil
- Notas: la función de colaboración en WordPress 6.9
Sistema y actualizaciones
- Ciclo de vida de los plugins: instalación, actualización, activación, desactivación, borrado y conmutación de actualización automática
- Instalación, actualización, activación, cambio y borrado de temas
- Actualizaciones del núcleo de WordPress (manuales y automáticas)
- Actualizaciones de traducciones y paquetes de idioma
- Avisos de actualizaciones disponibles
- Cambios en la pantalla de ajustes y opciones
Privacidad y cumplimiento normativo
- Exportación de datos de privacidad y solicitudes de supresión de datos de usuario
- Cambios en la página de privacidad
- Direcciones IP anonimizadas por defecto: sin cookies, sin fuentes externas
🔌 Soporte integrado para plugins de terceros
Simple History incluye registro integrado para:
- Jetpack: activaciones y desactivaciones de módulos
- Advanced Custom Fields (ACF): cambios en grupos de campos y campos
- User Switching: eventos de cambio de usuario
- WP Crontrol: cambios en eventos cron y horarios
- Enable Media Replace: detalles de reemplazo de archivos
- Limit Login Attempts: intentos de inicio de sesión, bloqueos y cambios de configuración
- Redirection: cambios en redirecciones y grupos, ajustes globales
- Duplicate Post: clonación de entradas y páginas
- Beaver Builder: guardados de diseños, plantillas y ajustes
¿Falta tu plugin? Los autores de plugins pueden agregar soporte usando la API de registro.
💬 Lo que dicen los usuarios
Más de 430 reseñas de cinco estrellas en WordPress.org:
- “Hasta ahora, el mejor y más completo plugin de registro” – @herrschuessler
- “El mejor plugin de historial que he encontrado” – Rich Mehta
- “Fantástico plugin que uso en todos los sitios” – Duncan Michael-MacGregor
- “Es un plugin estándar para todos nuestros sitios” – Mr Tibbs
🚀 Consulta tu registro en cualquier lugar
Simple History comienza a registrar al instante después de la activación, sin necesidad de configuración. Incluso importa la actividad reciente para que tu registro no esté vacío el primer día. Accede a tu registro desde:
- Widget del Escritorio: resumen de estadísticas de actividad y eventos recientes
- Vista rápida en la barra de administración: menú desplegable con los últimos eventos en cualquier página de administración
- Paleta de comandos: escribe “Simple History” para saltar al registro de la entrada actual
- Página de administración dedicada: registro completo con búsqueda, filtros y barra lateral de perspectivas
- Informes por correo electrónico: resumen semanal entregado en tu bandeja de entrada
- Feed RSS: feed protegido por contraseña para tu lector favorito
- WP-CLI: acceso desde la línea de comandos para automatización y scripts
- API REST: acceso programático para integraciones personalizadas
📧 Informes semanales por correo electrónico: mantente informado sin iniciar sesión
Los informes semanales por correo electrónico envían un resumen de la actividad de tu sitio cada lunes por la mañana: actividad total, desglose diario, métricas clave (inicios de sesión, actualizaciones de contenido, cambios en plugins) y enlaces directos al registro completo.
Perfecto para propietarios de sitios, agencias que gestionan sitios de clientes y equipos que necesitan actualizaciones periódicas sin iniciar sesión. Actívalo en los ajustes y mira cómo es el correo electrónico antes de activarlo.
🛠️ Para desarrolladores y usuarios avanzados
- WP-CLI: lista, busca y exporta eventos desde la línea de comandos, perfecto para la automatización y la gestión de múltiples sitios
- API REST: acceso programático completo para consultar el registro y agregar eventos personalizados. Consulta la documentación
- API de registro: Registra tus propios eventos desde temas y plugins con una sola línea de código
- Feed RSS: suscríbete a los cambios usando cualquier lector de feeds
- Amigable para IA y agentes: la API REST y el feed RSS hacen que Simple History sea accesible para agentes de IA y flujos de trabajo automatizados como Claude Code
- Modo sigiloso: ejecuta Simple History completamente oculto de la interfaz de administración mediante código; Premium agrega una interfaz gráfica. Ideal para agencias y sitios de clientes
🔆 Amplía con complementos
Simple History Premium
Alertas y avisos: recibe avisos al instante por correo electrónico, Slack, Discord o Telegram cuando ocurran eventos importantes. Empieza rápidamente con reglas predefinidas para escenarios comunes o crea reglas personalizadas filtradas por tipo de evento, usuario, perfil y nivel de registro.
Reenvío de registros: envía eventos a destinos externos: archivos de registro locales, servidores syslog (UDP/TCP/TLS), Datadog, Splunk, webhooks o bases de datos externas MySQL/MariaDB. Perfecto para registro centralizado, cumplimiento normativo y copias de seguridad.
Controles mejorados: periodos de retención personalizados (o conservar los registros para siempre), exportación CSV/JSON de los resultados de búsqueda filtrados, panel de actividad de entradas en el editor de bloques, entradas de registro personalizadas para decisiones del equipo, interfaz de modo sigiloso, control de registradores para ajustar qué eventos se registran y una experiencia sin anuncios.
WooCommerce Logger
Registra la actividad de WooCommerce: pedidos, reembolsos, cambios de stock, actualizaciones de productos, ajustes de precios, modificaciones de ajustes y uso de cupones.
Debug and Monitor
Monitoriza las solicitudes HTTP salientes y los correos electrónicos, depura llamadas API y descubre lo que ocurre bajo el capó. Esencial para equipos de desarrollo y soporte.
💚 Patrocina este proyecto
Si te gusta este plugin, considera patrocinar el desarrollo del plugin gratuito. El plugin ha sido gratuito durante más de 10 años y seguirá siéndolo.
Capturas de pantalla

El registro de eventos principal: una línea temporal clara de quién hizo qué en tu sitio, cuándo y desde dónde, junto a una barra lateral con la actividad diaria y tus usuarios más activos.

Los cambios de contenido muestran una diferencia completa entre el antes y el después, para que puedas ver exactamente qué palabras se editaron en una entrada o página, no solo que algo cambió.

Los eventos de usuario capturan cada cambio en un perfil: nombre y apellidos, nombre para mostrar, sitio web, perfil y más, con el valor anterior conservado junto al nuevo.

Cada instalación, activación y desactivación de plugin se registra con el autor, la versión, el origen y un enlace al plugin, para que siempre sepas qué se está ejecutando en tu sitio.

Haz clic en cualquier dirección IP para ver de dónde proviene (nombre de host, organización, ciudad y país) y luego filtra todos los eventos desde esa IP o subred con un solo clic. Ideal para investigar inicios de sesión fallidos.

Abre cualquier evento para ver todos los detalles que Simple History almacena detrás: ID de entradas, ID de usuarios, valores antes/después y cualquier otro campo: el registro de auditoría completo para cada entrada.

Perspectivas del historial muestra un gráfico de la actividad diaria, recuentos de eventos para hoy, esta semana y este mes, y tus usuarios más activos, todo junto al registro.

Estadísticas y resúmenes es un Escritorio de informes completo: desgloses de usuarios, entradas y páginas, plugins, medios y más, para cualquier intervalo de fechas que elijas.

Widget del Escritorio: una vista compacta de la actividad reciente directamente en tu Escritorio de WordPress, para que veas lo que ha pasado en tu sitio sin salir de la página que ya revisas cada día.

Los informes semanales por correo electrónico te mantienen informado sin necesidad de iniciar sesión. Elige quién recibe el resumen, previsualízalo o envía un correo de prueba, todo desde la página de ajustes.

El resumen semanal en sí mismo: un resumen claro de entradas, usuarios, inicios de sesión, cambios en plugins y más, enviado directamente a tu bandeja de entrada.
FAQ
¿Es gratuito el plugin?
¡Sí! Simple History ha sido gratuito durante más de 10 años y seguirá siéndolo. Para apoyar el desarrollo y desbloquear funciones adicionales, puedes adquirir el complemento premium. Ver funciones premium.
¿Cómo veo el registro?
Puedes acceder al registro de varias formas:
- El widget del Escritorio con el resumen de estadísticas de actividad
- Una página de registro dedicada en el área de administración de WordPress
- El menú desplegable de vista rápida de la barra de administración en
- La paleta de comandos de WordPress: escribe “Simple History” para saltar al registro de la entrada actual
¡Sí! Puedes personalizar la posición del menú en los ajustes del plugin. Elige entre mostrar Simple History en la parte superior o inferior del menú principal, o dentro del menú del Escritorio o del menú de herramientas.
¿Necesito conocimientos de programación para usar el plugin?
¡No! Solo instala y activa el plugin, y empezará a recopilar registros de actividad automáticamente.
¿Dónde se almacena el registro?
El registro se almacena en tu base de datos de WordPress.
¿Puedo exportar el registro?
Sí, puedes exportar los registros en formato CSV o JSON para un análisis más detallado.
¿Es compatible con otros plugins?
¡Sí! Simple History es compatible con muchos plugins populares de serie. Además, los desarrolladores pueden integrarlo con cualquier plugin usando la API de registro.
¿Ralentizará este plugin mi sitio web?
No, Simple History es ligero y está optimizado para el rendimiento. La mayor parte del registro se produce en el área de administración de WordPress cuando un usuario de WordPress realiza una acción.
Por defecto, no se registra nada en el frontend, lo que garantiza que los visitantes no experimenten ningún impacto en el rendimiento.
¿Quién puede ver el registro?
El acceso al registro depende del perfil del usuario:
- Los administradores pueden ver todos los eventos registrados.
- Los editores pueden ver los eventos relacionados con entradas y páginas.
¿Puedo excluir a ciertos usuarios del registro?
Sí, puedes excluir usuarios según su perfil o correo electrónico usando el filtro
simple_history/log/do_log.Para más detalles, consulta la documentación de hooks.
¿Durante cuánto tiempo se conserva el historial?
Por defecto, los registros se conservan durante 60 días.
Actualiza a Simple History Premium para cambiar esto mediante una interfaz gráfica.
¿Puedo hacer un seguimiento de los cambios realizados por usuarios específicos?
¡Sí! Puedes filtrar los registros por nombre de usuario, lo que facilita el seguimiento de la actividad individual.
¿Cumple este plugin con el RGPD?
El cumplimiento del RGPD depende de cómo uses el plugin y de cómo gestiones los datos recopilados. Las directrices de WordPress prohíben a los plugins hacer declaraciones de cumplimiento legal, por lo que debes revisar las políticas de datos de tu sitio para asegurar el cumplimiento.
Dicho esto, Simple History sigue prácticas respetuosas con la privacidad:
- ❌ Sin fuentes de Google
- ❌ Sin cookies
- ❌ Sin almacenamiento local
- ✅ Las direcciones IP están anonimizadas por defecto
Dado que el plugin registra eventos (que pueden contener datos personales), es tu responsabilidad garantizar el cumplimiento del RGPD en función del uso de tu sitio.
Para obtener más información, consulta nuestra página de soporte RGPD y privacidad: cómo se almacenan tus datos en Simple History.
Reseñas
Colaboradores & Desarrolladores
“Simple History – Track, Log, and Audit WordPress Changes” es software de código abierto. Las siguientes personas han contribuido a este plugin.
Colaboradores“Simple History – Track, Log, and Audit WordPress Changes” ha sido traducido en 18 idiomas. Gracias a los traductores por sus contribuciones.
Traduce “Simple History – Track, Log, and Audit WordPress Changes” a tu idioma.
¿Interesado en el desarrollo?
Revisa el código, echa un vistazo al repositorio SVN, o suscríbete al registro de desarrollo por RSS .
Historial de cambios
✨ If you find Simple History useful ✨
- Sponsor the plugin to keep it free.
- Add a 5-star review so other users know it’s good.
- Get the premium add-on for more features.
Experimental entries are gated behind the experimental features setting (Settings Simple History Experimental). Enable it to try them, then share feedback so we know what to ship for everyone.
5.30.0 (August 2026)
👍 Two experimental features graduate in this release: event reactions and the header status bar, which shows the status of your current settings at a glance — how long history is kept, whether email reports and alerts are on, and where logs are forwarded. This release also includes a round of security hardening and some miscellaneous fixes.
Read more about all changes in the release post
Added
- “Plugin info” action link on plugin update-available events, so you can quickly check what an unfamiliar plugin is without leaving the log.
- “Find events from the same IP address” in an event’s actions menu, alongside the existing user and event-type filters.
- Changes to more Simple History settings are now logged: Email Reports, the Experimental features toggle, and add-on license keys (key values are never stored in the log). (And yes – it was a bit funny that the plugin that logs changes to other plugins didn’t log its own settings changes!)
- WP-CLI:
--metadata_searchand--ai_onlyoptions onwp simple-history list, matching the metadata search and AI filter in the GUI. - WP-CLI: AI attribution columns (
ai_agent,ai_detected_via,ai_application) onwp simple-history list, showing which AI tool made a change and how it was detected. - Header now shows “Stealth mode: on” while stealth mode is hiding Simple History from other users, including other administrators.
Changed
- Reactions graduated from experimental and are now on by default — react to events with a 👍 (disable in Settings General). Premium adds ❤️ 🎉 🚀 and more reaction types.
- Header settings/info bar is graduated from experimental and now shows for all admins — a glance at how long history is kept, whether email reports and alerts are on, and where logs are forwarded, with each one linking straight to its setting.
- Checkbox settings now show as On/Off (instead of 1/0) in the “Modified settings” log details.
- Settings changes are now detected across all save mechanisms (Settings API, direct option updates, and REST) and recorded as a single event.
- Large or structured settings are now logged as “changed” without storing their full value, keeping the log readable.
- Developers:
simple_history/user_can_clear_lognow defaults to whether the user can manage settings, instead of always allowing it. The “Clear log” button is unaffected for administrators.
Deprecated
- WP-CLI:
wp simple-history event search— usewp simple-history event list --search=<term>instead. The old command still works but will be removed in a future version.
Fixed
- WP-CLI:
wp simple-history event searchalways returned zero results. - WP-CLI:
--fieldsonwp simple-history listignored column names written with a space after the comma. - PHP 8 fatal error when a setting was changed by a request without a referrer, such as from the REST API or WP-CLI. #649
- Untranslatable strings in the statistics view and the weekly email report. #672
- Invalid date or month filter values now return a clear error (HTTP 400 in the REST API, a friendly message in WP-CLI) instead of a server error.
- RSS feed no longer breaks when its address contains a date filter it can’t read — for example an older feed URL saved in a feed reader. It now returns an empty feed instead of an error.
- Removed an unnecessary database query on every admin page load (a leftover from the one-time history backfill check).
- Dashboard widget now shows an error message with details when the log can’t be loaded (for example when the REST API is blocked), instead of loading placeholders forever.
- Fatal error on WordPress 6.3 when saving a post that creates a revision.
- Post update events now link to the revision they created. (The link had been missing since the feature was added in 5.16.0!)
- PHP warning when logging a comment whose post has been deleted. Such events now read “a comment to (deleted)” instead of showing an empty title.
- “Filter events: This IP” in the IP address popover did nothing when used from the dashboard widget — it now opens the event log filtered to that address.
- Filtering by IP address now finds events by any address recorded for them, not just the one the web server saw. On sites behind a proxy or load balancer the visitor’s real address is read from a forwarding header, and filtering by it previously returned nothing.
- Experimental — Failed XML-RPC logins no longer create a duplicate “failed application password” entry alongside the regular failed-login entry.
Security
- Looking up a person’s username, email address and roles from the user card now follows WordPress’s own rule and requires permission to list users. Who performed an event is still shown to everyone who can read that event.
- REST API endpoints now require the same permission as opening the history page.
- Detective Mode masks more field names — passwords, tokens, secrets and card numbers — and now also covers nested values, query strings and command line arguments.
- Clearing the log, exporting it and regenerating the RSS feed address now also require permission to manage settings.
- Event text escaping is now consistent across the media, categories, user and comments loggers, and in exported HTML files.
5.29.0 (June 2026)
🔒 This release brings Simple History together with WordPress’s built-in privacy tools: a person’s activity log is now included in personal-data exports (Tools Export Personal Data), and a new “Privacy & Data” settings tab explains how it works. Plus: overview action links across user, plugin, post, and media events, and action links on core update and privacy events for quicker navigation.
Read more about all changes in the release post
Added
- Overview action links (“All users”, “All plugins”, “All posts”, “All media”) on user, plugin, post, and media events.
- “About this version” and “WordPress X.Y release notes” links on core update events for major-version bumps.
- Action links on privacy events linking to the matching WordPress tool page (Tools Export / Erase Personal Data, Settings Privacy).
- Activity log is now included in WordPress’s personal-data export (Tools Export Personal Data).
- New “Privacy & Data” settings tab (Settings Simple History) explaining how Simple History works with WordPress’s personal-data tools.
- Experimental — Exports also include activity about a person performed by others, with other people’s names and emails redacted.
- Experimental — Running a WordPress personal-data erasure (Tools Erase Personal Data) anonymizes the person’s data in matching log entries while keeping the entries as audit records.
Changed
- Action link labels dropped the “View” prefix (“View plugin info” “Plugin info”).
- External action links now show an “open in new tab” icon and open in a new tab.
- Dashboard widget action links are now more compact, so the event message stays the visual anchor.
- License reminder for missing add-on license keys moved from a full-width banner to a dismissible card in the History Insights sidebar.
- Experimental — Role and capability events show a count (“Added 40 capabilities to role Editor”) instead of dumping every capability slug into the headline; the full list stays in the event details.
Fixed
- Alt-text changes to media made via direct meta updates are now logged.
- Removed custom fields on post updates are now counted in the event details.
- The UTC publish date no longer appears as a duplicate row in post update details.
5.28.0 (May 2026)
Ready for WordPress 7.0! This version is tested and confirmed working on the latest WordPress version. It also adds logging for the new AI Connectors Screen. Plus: WP-CLI and REST API coverage for content and settings changes. And the usual round of UI improvements and bug fixes.
Read more about all changes in the release post
Added
- WordPress 7.0 AI Connectors screen changes are now logged.
- Built-in WordPress settings changed via the REST API (
POST /wp/v2/settings) or WP-CLI (wp option update) are now logged. Previously the Options Logger only captured changes made through Settings General/Writing/Reading/Discussion/Media/Permalinks, so automation, scripts, and AI agents could change the site tagline, title, default category, permalinks, and similar settings invisibly. - Post, user, media, menu, widget, and privacy page changes made via WP-CLI or the REST API are now logged. Previously these loggers only captured changes from inside wp-admin, so commands like
wp post create,wp post update,wp user update,wp menu item add, and REST-driven edits from external tools or AI agents were not recorded. - Post update events now expose status, publish date, comment status, author, and page template as structured data in the REST API, “Copy as JSON”, and “Copy as Markdown” outputs — previously these fields were only available as prerendered HTML, so external clients had to parse the markup.
- Action link on Options Logger events for quick navigation back to the Settings page where the option lives.
- “How are AI agents detected?” link in the AI agent attribution tooltip, pointing to a docs article that explains the detection signals.
- System Information page,
wp simple-history db stats, and the/wp-json/simple-history/v1/support-infoREST endpoint now report the charset and collation of each Simple History table — useful when diagnosing emoji-related context-drop issues. - Reminder card on Simple History pages when an add-on is installed without a license key entered, so users notice that updates won’t arrive until the key is added. Links directly to the license entry field.
Changed
wp simple-history infonow shows “Experimental features: enabled” when experimental features are active.- Options Logger event details show the change inline as a single row (new value strike-through old value) labeled with the setting name (e.g. “Site Title”, “Tagline”), instead of stacked “New value” / “Old value” rows.
- Admin display for post update status, publish date, comment status, author, and page template switches from a stacked table row (“Changed from draft to publish”) to an inline pill style (“Status: draft publish”), matching how user profile changes already render. Title, content, custom field, term, and featured-image diffs still render in the existing table layout.
Fixed
- “Copy as JSON” and “Copy as Markdown” now include the full event context (request URI, method, user agent, error codes, etc.), making copied payloads self-contained for triage and bug reports.
- IP addresses are now included in failed application password authentication events, matching how wp-login failures already worked.
- New installs create history tables as
utf8mb4(using$wpdb->get_charset_collate()), so emoji and other 4-byte UTF-8 characters in events are preserved. - Support info page no longer prints a “no such table: dbstat” database error when
WP_DEBUGis on and SQLite’s optionaldbstatvirtual table isn’t available (notably on WordPress Playground). - “Most active users” widget no longer shows nameless entries for users without a display name.
- Redirect loops in wp-admin for low-privilege users. A legacy-URL redirect intended only for the old
/wp-admin/index.php?page=simple_history_pagebookmark was also firing for unrelated access-denied events on the dashboard, which could send users in circles. #639 - Experimental — Brute-force attempts against
xmlrpc.phpnow show which account is being targeted instead of logging an empty username.
5.27.0 (May 2026)
🤖 This release adds AI agent attribution to log events, so you can see when an action was triggered through Claude Code, ChatGPT, or other AI tools. Also, Action links are now front-and-center for media, plugins, users, menus, and failed plugin installs.
Read more about all changes in the release post
Added
- Plugin active/inactive status is now recorded when plugins are updated, shown in event details when the plugin was inactive at update time.
- Success confirmation and automatic log refresh after manually adding a log entry.
- Action links for media attachments (Edit, View), plugins (“View changelog”), user profiles (“Edit user”), menu edits (“Edit menu” and “Manage menu locations”.
- “Show error message” action link on plugin install/update failure events — opens the event details modal where the underlying error message and diagnostic context are shown.
wp simple-history infoWP-CLI command — prints the installed version, premium add-on status, and a list of useful subcommands.- New opt-in columns for
wp simple-history listvia--fields=:date_relative(“5 minutes ago” style timestamps),site(blog name and host, useful when comparing output across installs), andai_agent(detected AI tool name when an event was initiated through an AI agent). - AI agent attribution on event log rows: when an event is triggered by an AI tool (Claude Code, ChatGPT, MCP clients, the Abilities API, etc.), a sparkle icon and the agent name appear next to the user who initiated the event. The signed-in user remains the actual initiator — this is additional audit context, not an authentication signal.
- “AI-initiated events only” filter in the expanded filters panel — quickly narrow the log to actions triggered via AI tools.
- New “Copy as JSON” menu item for each event, that copies the full event payload — including all context data — for scripting and debugging.
- Experimental — “History” column on post and page list tables showing recent activity at a glance, with “View history” row action links.
- Experimental — Failed application password authentication on REST API and XML-RPC requests is now logged as a warning, with the attempted user, error code and message, request URI, request method, and user agent. Closes a visibility gap where wrong app password attempts left no trace in the log, while wp-login failures already did. Can also be toggled directly via the new
simple_history/log_failed_app_password_authfilter.
Changed
- Event details for 12 loggers are now more consistent across the UI and structured in the REST API (migrated from manual HTML output to the Event Details API).
- Navigational links in comment and plugin events (e.g. “Edit comment”, “View plugin info”) moved from event details to the action links bar for better discoverability.
- Date filter dropdown reorganized: “All dates” moved to the top as the reset option, presets grouped under “Recent” (Today through Last 60 days, plus “Custom range…”), and specific months grouped under “By month” — easier to scan and matches how users think about date ranges.
- “Copy detailed event message” action menu item renamed to “Copy as Markdown” with a richer Markdown layout (heading + properties table + structured details + context table) suitable for pasting into a ticket, Slack, or notes app. The Details section reflects what the event row shows (e.g. plugin description / version / author for plugin install events).
- Stats page “Events overview” chart and sidebar “History Insights” daily activity chart switched from line charts to bar charts, with today highlighted in a contrasting accent color for at-a-glance recency.
Security
- Event reaction endpoints now enforce per-event read permissions to prevent logged in users to be able to read events they shouldn’t have access to. Reactions are experimental and off by default. Many thanks to Ly Hoang at Wordfence for responsibly disclosing this vulnerability.
- Password reset request events no longer store the full reset email body, which contained the activation URL. User, email, and origin are still logged.
- Removed the
simple_history/comments_logger/log_failed_passwordandsimple_history/comments_logger/log_not_existing_user_passwordfilters, which could log plaintext passwords from failed logins. Both defaulted to off.
Fixed
- Retention upsell message showing “deleted in 0 days” when event deletion is imminent. Now shows “scheduled for deletion” instead.
- Menu logger flagging unrelated items as “Renamed” on every menu save. Items with HTML in their label, and items inheriting their label from a linked page, are no longer reported as renamed when nothing was actually changed.
- Menu logger not surfacing renames of the menu itself — the previous and new menu name are now shown in the event details when the “Menu Name” field is changed.
5.26.0 (April 2026)
This version makes the log actions more discoverable by moving them out of the dropdown menu and into inline buttons. It also contains a new experimental feature: reactions!
Read more about it in the release post
Added
- Media, Comments, and Themes sections to the weekly email summary report. Comments section only appears when comments are enabled on the site.
--fieldssupport forwp simple-history listWP-CLI command, including areactionsfield showing reaction counts.- Experimental — Event reactions: react to log events with a thumbs up emoji, with a Slack-style emoji picker in the actions bar.
Changed
- Control bar actions are now inline buttons instead of a dropdown menu, making Export, Create Alert, Create Log Entry, and Share View more visible and accessible.
- Expanded filters panel: reordered filters with Users first, moved “Hide my own events” into the Users row, replaced initiators help link with an icon, and trimmed helper text for a cleaner layout.
Fixed
- Memory exhaustion when exporting large event logs by reducing batch size and eliminating redundant database queries.
- Layout shift in control bar action buttons while search options are loading.
- Oversized file type icon for non-image attachments (e.g. DOCX, PDF) in the event log.
5.25.0 (March 2026)
This release focuses on keeping your database lean. Three features that reduce log storage size are now active for all users: smarter default retention for new installs, failed login rate limiting, and compact diff storage for post content changes.
Read more about it in the release post
Added
- Failed login rate limiting is now active for all users, capping logging at 100 consecutive failed attempts to prevent database bloat from brute force attacks.
- Compact diff storage for post content changes is now active for all users, storing only a compact diff instead of full old+new content (up to 99% smaller for typical edits) with automatic fallback when the diff would be larger.
- Search is now faster and more accurate for all users: queries skip occasion grouping for speed and only search relevant context keys from registered loggers instead of scanning all metadata. Previously this was an experimental opt-in feature. Use the “Event metadata” search field in the advanced filters to search all metadata (similar to the old behavior).
- Hover-reveal quick action button on event rows for faster access to event details.
- List of current experimental features shown near the enable toggle in settings.
- “/” keyboard shortcut to focus the search input, with a visual hint badge. Pressing Escape returns focus to the previously focused element.
- Settings and Premium/Get Premium buttons in the top-right header, replacing the Add-ons link.
- Email Reports settings moved to their own sub-tab under Settings for better discoverability.
- New installs default to 30-day retention (existing installs keep 60 days), keeping your database lean from day one.
- Experimental — Feature discovery bar in the page header showing active features and settings status with dot indicators. Each item links directly to its settings section for quick access.
Changed
- Search and filters redesigned into a single compact row with search input, date selector, and action buttons — replacing the previous multi-line layout.
- Expanded filters panel now stacks labels above inputs on smaller screens for better usability.
- History Insights sidebar: today’s data point is now highlighted with a visible dot and the end date shows “(today)” for clarity.
- History Insights sidebar: reduced y-axis clutter on the activity chart for a cleaner look.
- History Insights sidebar: database stats section is now visually separated as footer content with cache freshness info moved into the tooltip.
Fixed
- Dashboard widget corners not matching the new rounded style in WordPress 7.0.
- PHP notice on the widget editor screen (widgets.php) caused by the command palette script loading
wp-editoron non-post-editor screens. - Occasion counts in the RSS feed were always zero and never rendered.
- Inverted condition in the GitHub plugin info handler that caused it to always fail.
- “No matching events” empty state text and icon too light to meet WCAG AA contrast requirements.
- Deprecation notice when using Yoast Duplicate Post 4.6, which replaced the
dp_duplicate_postanddp_duplicate_pagehooks withduplicate_post_after_duplicated.
Security
- Nonce verification added to the GitHub plugin info AJAX handler to prevent CSRF.
5.24.1 (March 2026)
Security
- RSS feed error response no longer exposes the feed secret token in the self-referencing link.
Changed
- Capabilities added to roles are now logged at “notice” level instead of “warning” to reduce unnecessary alarm during routine plugin activations.
Fixed
- Role Capability Logger no longer spams the log when plugins (e.g. Astra/Spectra) toggle capabilities on every page load. Changes are now batched per request and only net differences are logged.
Added
- User ID displayed as an inline suffix on the name in the user card popover, making it easier to identify users when debugging.
5.24.0 (March 2026)
A redesigned dashboard widget that takes up less space, user details card on click, and much better logging of menus, categories, and image edits.
Read more about it in the release post
Added
- User card on avatar and name click, showing name, role, and email with a link to the user profile. The Premium add-on extends the card with login history and recent activity.
- “Copy as image” action in the event menu that captures an event as a shareable image, ready to paste into Slack, social media, or bug reports.
- Site Health Logger that tracks WordPress Site Health test status changes, logging when issues are detected, resolved, or change severity.
- Menu change logging now shows item names, types, renames, moves, order changes, and display location updates instead of just item counts.
- Parent category changes and diff details (name, slug, description, parent) when viewing edited category and tag events.
- Logging when a page is set as the homepage or posts page from the block editor, including the name of the previously assigned page.
- Image edit logging (crop, rotate, flip, scale) in the media logger, including a thumbnail preview.
- Command palette command to view event history for the current post or page.
- “Event metadata” search field in the advanced filters for searching all event data including IP addresses and emails.
- “Clear filters” button to reset all search filters to their default values.
- Rotating tips in the sidebar to help users discover features like RSS feeds, WP-CLI, export, and sticky events.
- User creation and profile update counts in the email digest report, displayed alongside login statistics in the Users section.
- REST API
skip_count_queryparameter to skip the total count query when pagination info is not needed, improving response time for clients that don’t require total counts. - Multisite uninstall support, removing tables, options, and cron events across all subsites in the network.
- Compact storage for post content changes (used for creating a diff between the old and new content), reducing database size for large posts (experimental).
- Failed login throttling to protect the database from brute-force attacks — logs the first 100 failed attempts, then automatically skips the rest. Includes an informational notice on both the main event log and the dashboard widget (experimental).
- Role & Capability Logger that tracks when roles are created, deleted, or have their capabilities modified, including which plugin triggered the change (experimental).
Changed
- WP-CLI
--userargument renamed to--useridand--exclude_userto--exclude_useridto avoid conflict with WP-CLI’s global--userargument, which caused warnings on newer WP-CLI versions. #629 - Dashboard widget redesigned with an activity stats summary showing event counts for today and last 7 days, and a more compact event list. Loads significantly faster by limiting queries to the last 7 days and skipping the total count query.
- Search now only searches the visible event message text by default, making results more relevant and dramatically faster on sites with large activity logs. Previously, search also scanned all hidden metadata which was slow and returned unexpected matches (experimental).
- Multi-word search now matches each word independently across all searchable fields. For example, “api request 400” now finds events where “api” and “request” appear in the message text and “400” appears in event metadata, instead of requiring all words to exist in the same field (experimental).
- “Show filters” / “Hide filters” toggle replaces “Show search options” / “Collapse search options”.
- Action links (Edit, View, Preview, Revisions) now appear below post events.
- IP address popover redesigned with prominent IP display, AS number links, map service links (Google Maps and OpenStreetMap), and subnet filtering.
- Core file integrity restored log entry now shows how many files are still modified.
- Auto backfill runs on the first admin page load instead of WP-Cron, ensuring it works in more environments.
- Admin bar JavaScript reduced by removing the wp-components dependency, saving ~919 KB on every page load.
- Object caching added to stats queries, preventing duplicate database queries within the same request.
Fixed
- False-positive core file integrity warnings on localized WordPress installs (e.g. sv_SE) caused by hardcoded en_US checksums.
- Term names showing backslash before apostrophes when editing categories and tags.
- Incomplete option cleanup on plugin uninstall, leaving orphaned options in the database.
- Three scheduled cron events not cleared during uninstall (database purge, core file integrity check, log file cleanup).
- Missing icon for “Other” initiator type.
- Manual backfill memory error on sites with many users, now processed in batches.
5.23.1 (February 2026)
Fixed
- Added backward-compatibility stubs for PHP classes 5.21–5.23, hopefully preventing crashes when updating from those versions. 🤞
5.23.0 (February 2026)
Added
- Detection of forced security updates from WordPress.org; shown as “Update method: Security auto-update” in plugin update details.
- Upgrade notices from WordPress.org API in plugin update details.
- Search labels on 11 loggers (Beaver Builder, Duplicate Post, Enable Media Replace, Jetpack, Limit Login Attempts, Redirection, User Switching, WP Crontrol, Privacy, Simple History, Translations) for better filtering in alert rules.
- Granular failed-login filters: “Failed login (wrong password)” for known users and “Failed login (unknown user)” for non-existent usernames, alongside the existing “Failed user logins” option.
- User role (
_user_role) in event context for debugging and used by alerts to be able to add rules for specific user roles. - Notes feature stats (WordPress 6.9+):
- Statistics in weekly email reports (notes added and resolved).
- Statistics on History Insights for block editor notes activity.
- REST API at
/wp-json/simple-history/v1/stats/notes.
- Alerts settings page with premium notification teasers (presets and custom rules in Premium).
Changed
- Updated some logger messages to use active voice: e.g. “Was denied access” “Attempted to access restricted”, “was auto-disabled” “Auto-disabled”, “Was locked out because” “Locked out after”, “was updated” “Updated”.
- Debug tab merged into Help & Support; System Information sits directly under support links.
- Status bar on Help & Support showing plugin version, event count, and retention at a glance.
- System Information extended with PHP Max Input Vars, WP Memory Limit, Child Theme, Theme Author, and User Agent for support debugging.
- Log level for forced security plugin updates is changed from “info” to “notice”, so auto-updates stand out.
- Disable autoload for Available Updates Logger options, so they are only loaded when needed.
- Sub-navigation tabs scroll horizontally on narrow screens instead of wrapping.
- Plugin loading no longer scans the filesystem at startup; loggers and extensions are registered via static class lists for faster, more reliable init.
- Sidebar stats and database purge queries rewritten to use the date index (faster on large tables).
- Log_Query now has a
skip_count_queryoption to omit the total row count when pagination metadata is not needed. - RSS feed now defaults to last 7 days and skips the count query for better performance. It also has a
datesparameter for date filtering (e.g.&dates=lastdays:30).
Fixed
- Infinite loop when the Debug & Monitor add-on logged HTTP requests from channels (Webhook, Datadog, Splunk).
See CHANGELOG.md for the full changelog, including all releases from 2025 and earlier.
