Know when someone changes a site
See which WordPress user installed, removed or switched a plugin or theme, or added an admin, and get an email the moment it happens.
Updated Oct 7, 2026
Clients, their staff and other developers can still sign in to wp-admin and change things. With WP Foreman plugin 0.7.0 or newer, every one of those changes goes in the site’s log with the person’s name, and you can get an email the moment it happens. They don’t need a WP Foreman account.
Jane Doe installed the plugin Hello Dolly
Jane Doe ([email protected]) · editor · 203.0.113.9
What’s recorded
| Change | In the log | Emailed right away |
|---|---|---|
| Plugin installed, deleted, activated or deactivated | Yes | Yes |
| Plugin updated | Yes | No (it’s in the log) |
| Theme installed, deleted or switched | Yes | Yes |
| Theme updated | Yes | No |
| WordPress updated by hand | Yes | Yes |
| A new administrator account (created, or someone made an admin) | Yes, in red | Yes |
| An administrator signed in to wp-admin | Yes (under Sign-ins) | No |
| WordPress auto-updates | Yes, as “WordPress auto-update” | No |
Changes you make through WP Foreman are logged under your name already, so they’re never counted as “outside” changes.
Who and how
For each change the log shows the WordPress user’s name, email and role, the IP address it came from, and how it happened: in wp-admin, through WP-CLI (the command line), by a WordPress auto-update, by a scheduled task on the site, or through the WordPress REST API. Click the entry for the full details.
How fast
The site tells WP Foreman as soon as the change is made, usually within seconds. If WP Foreman can’t be reached at that moment, the site keeps the event and sends it with the next check (about every 30 minutes). Nothing is lost if a message fails.
Emails
You get one email per site per batch of changes, titled “Heads up: …”, listing what changed, who did it and when, with a link to the log. Turn these on or off in Settings › Notifications. They’re on by default.
Want them somewhere else? The site.changed webhook sends the same changes to Slack (through Zapier or Make) or your own system.
Changes WordPress can’t name
If files are changed directly on the server (FTP, the host’s file manager, a deploy script), WordPress doesn’t know who did it. WP Foreman still notices the change at its next check and logs it as “made on the site, outside WP Foreman”, without a name.
Privacy
To show who made a change, WP Foreman stores the WordPress user’s name, email, role and IP address with that log entry. It never sees or stores WordPress passwords. See What data WP Foreman stores.
Needs WP Foreman plugin 0.7.0 or newer. Changes are only recorded from the moment the site has 0.7.0. Update from the site’s Overview (see Update the WP Foreman plugin).
Thanks. If something was missing, tell us what.