[WordPress] 外掛分享: Activity Guard – Security Scanner, Activity Log with IP blocking

首頁外掛目錄 › Activity Guard – Security Scanner, Activity Log with IP blocking
WordPress 外掛 Activity Guard – Security Scanner, Activity Log with IP blocking 的封面圖片
50+
安裝啟用
★★★★★
5/5 分(4 則評價)
20 天前
最後更新
問題解決
WordPress 5.9+ PHP 5.6+ v3.11.4 上架:2023-02-27

內容簡介

Activity Guard 是一款強大的 WordPress 活動日誌、WooCommerce 事件及安全外掛,旨在追蹤網站上的每一項活動。它即時監控用戶行為、管理變更、WooCommerce 事件及系統級變更,並在關鍵變更發生時發送通知。

【主要功能】
• 即時監控用戶行為與管理變更
• 詳細的活動日誌記錄變更來源與時間
• 追蹤與封鎖可疑的 IP 位址
• 支援多種通知方式如 Slack、Telegram、Email
• 內建用戶會話管理功能

外掛標籤

開發者團隊

⬇ 下載最新版 (v3.11.4) 或搜尋安裝

① 下載 ZIP → 後台「外掛 › 安裝外掛 › 上傳外掛」
② 後台搜尋「Activity Guard – Security Scanner, Activity Log with IP blocking」→ 直接安裝(推薦)
📦 歷史版本下載

原文外掛簡介

Activity Guard is a free WordPress plugin that covers four things most plugins charge separately for: a complete activity log, an IP-based security firewall, a plugin vulnerability scanner, and WooCommerce abandoned cart analytics. Alerts go out in real time to Slack, Telegram, or email, all from one dashboard.
Most activity log plugins stop at logging. Most security plugins don’t touch WooCommerce. Plugins like WP Activity Log, Simple History, and Stream do logging well — Activity Guard adds real-time Slack and Telegram alerts, an IP firewall with emergency shutdown, CVE vulnerability scanning, and WooCommerce abandoned cart recovery analytics, all at no cost. No paid tier required for any of it.
No other free plugin on WordPress.org combines these four in one place: a complete audit log, an IP security firewall, a multi-database vulnerability scanner, and WooCommerce analytics with cart recovery tracking.

Activity Guard Website | Documentation | Pro Support
WordPress Activity Log
Activity Guard records every meaningful change on your site, including the IP address, username, timestamp, and the exact change made. The audit log covers:

User logins, logouts, and failed login attempts
User registrations, role changes, and profile edits
Pages, posts, and custom post types: create, edit, delete, status changes
Plugin and theme activations, deactivations, updates, and deletions
WordPress core settings and configuration changes
Menu, widget, and sidebar modifications
Email delivery tracking via a full email log
Form submissions from Contact Form 7, SimpleForm, and others
Admin settings changes and debug log events
Cron job scheduling and background process tracking
Script modification and file change detection
Visitor traffic monitoring with an on/off toggle

Visual charts summarize your audit log at a glance. No need to scroll through raw log tables to understand what’s happening on your site.
Security Firewall and IP Blocking
Activity Guard actively blocks threats rather than just recording them.

IP blocking by manual entry, CIDR range, or conditional rule
Emergency Shutdown: force-logout every active session on your site with one click
Cloudflare Turnstile login protection against bots and brute force attacks
Login rate limiting to stop credential-stuffing
Bot detection and automatic IP blocking
Restrict or fully disable XML-RPC access
Core file integrity scanner to detect unauthorized file changes
File integrity monitoring across plugins and themes
Block TOR network access
Block vulnerability scanner user agents
HTTP security headers: custom, logged, and enforced
WordPress version hiding
404 error tracking and suspicious HTTP request alerts
Admin dashboard visitor tracking
Cron job failure and site downtime monitoring

The Emergency Shutdown feature is specific to Activity Guard: one click and every logged-in session on your site ends immediately — useful when you detect a breach in progress and need everyone out now.
Plugin Vulnerability Scanner
Activity Guard scans every installed plugin and theme against multiple vulnerability databases before problems develop:

Detect plugins with known CVEs across NVD, WPVulnerability.net, and the WPAzleen private API
Flag outdated plugins not compatible with your WordPress version
Identify abandoned plugins not updated in over a year
Warn about plugins with low install counts or poor ratings

No other free activity log plugin on WordPress.org includes a built-in multi-database vulnerability scanner.
WooCommerce Activity Log and Analytics
Activity Guard logs every WooCommerce event and adds analytics built specifically for store owners.
Order tracking covers status changes, payments, refunds, and cancellations. You also get stock level changes and low-stock events, coupon creation and usage, product pricing edits, billing and shipping address updates, customer registration changes, and real-time shipping status updates.
The abandoned cart and incomplete-order analytics go further than basic logging. The dashboard shows checkout drop-off rates, recovery potential, recovery rate, and how customers interact with their carts before leaving. This tells you where revenue is being lost, not just that it was lost.
WooCommerce abandoned cart analytics with recovery rate tracking is included free. No competing free activity log plugin on WordPress.org provides this.
Slack and Telegram Notifications
Activity Guard sends alerts the moment a critical event occurs, across four channels:

Slack: route alerts to any channel, tag specific users or groups with @mentions
Telegram: real-time activity and security alerts direct to your Telegram chat
Email: configurable per event type
Admin dashboard: in-panel notification view

Events that trigger alerts include core file changes, plugin and theme updates (with the username that triggered the update), WooCommerce orders, payments, coupon usage, incomplete order follow-ups, product edits, stock changes, login and registration events, page and post changes, form submissions, and admin settings changes. A daily digest and weekly plugin download summary are also available.
You can schedule notifications for specific times and control exactly which events send alerts.
Admin and Developer Tools

Maintenance mode toggle from the dashboard
Menu and widget change tracking
Plugin and theme activation and deactivation logs
Script modification detection
HTTP security header change logging
Debug log and fatal error detection
Email log: full delivery history for all outgoing WordPress emails
Contact Form 7 and SimpleForm integration alerts

Who Uses Activity Guard
WooCommerce store owners use it to track every order, coupon, product change, and shipping event, and to recover revenue with abandoned cart analytics. Site administrators use it to know exactly who changed what, instantly log out suspicious users, and maintain a clean audit trail. Agencies and developers use it to monitor plugin updates, configuration changes, fatal errors, and debug logs across client sites. Security-focused admins use it to block IPs, scan for CVEs, monitor file integrity, and trigger emergency shutdowns. Multi-author sites use it to hold contributors accountable with full user activity logging and role-change tracking.
Join us: Facebook | YouTube | X / Twitter
Competitor Analysis
Search the WordPress plugin directory for an activity log plugin and a handful of names come up again and again, so it is worth being clear about where Activity Guard actually fits among them.
WP Activity Log is the biggest name in the category, with the broadest event coverage of any activity log plugin and support for tracking third-party plugins like ACF, Gravity Forms, and LearnDash. It is a genuine alternative to Activity Guard for pure logging depth, but Slack and SMS alerts sit behind WP Activity Log Premium, and there is no IP firewall, no vulnerability scanner, and no WooCommerce analytics at any tier. Activity Guard includes Slack and Telegram alerts, an IP firewall, vulnerability scanning, and WooCommerce abandoned cart analytics in the free version, with a narrower focus on the WordPress admin rather than enterprise SIEM exports.
Activity Log Pro is the closest match on structure. Its free tier also adds real security-adjacent value beyond plain logging, with Login Flood Guard and severity-tagged events, so anyone comparing the two is comparing like for like on ambition. Where Activity Guard pulls ahead is in what ships free versus what is gated: Activity Log Pro’s Slack and webhook routing live behind its Premium “Log Channels” feature, while Activity Guard’s Slack and Telegram alerts, IP blocking, vulnerability scanning, and WooCommerce cart recovery analytics are all included at no cost.
Beyond those two, most of the other names that show up nearby are lighter tools solving a narrower slice of the same problem, or a different problem entirely. Activity Log – Monitor & Record User Changes (Aryo) is a lightweight, beginner-friendly logger with email-only notifications and no Slack, Telegram, IP firewall, or vulnerability scanning. Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity is built for agencies managing many client sites and does send Slack alerts, but it works by connecting each site to Logtivity’s hosted service with an API key rather than running standalone, and it has no IP firewall, no vulnerability scanner, and no WooCommerce analytics. Security Plugin, Firewall & Malware Scanner with Auto Removal is a genuinely strong free WAF and malware scanner, but it is not an activity log at all: it does not track content edits, role changes, or WooCommerce events, and its alerts are email-only through the CleanTalk cloud account it requires. Error Log Viewer by BestWebSoft has nothing to do with user activity either, it is a PHP and WordPress error log reader with email notifications, useful for debugging but unrelated to security monitoring or audit trails.
So of the plugins that show up in a “wordpress activity log” or “wp activity log alternative” search, only WP Activity Log, Activity Log Pro, Aryo Activity Log, and Logtivity are actually built for the same job as Activity Guard: tracking what changed on a WordPress site and who changed it. Among those four, Activity Guard’s combination of free Slack and Telegram alerts, an IP firewall with emergency shutdown, a CVE vulnerability scanner, and WooCommerce abandoned cart analytics, all in the free version with no external account required, is what sets it apart.
External Services
Slack Webhook Integration
Activity Guard sends notifications to your Slack workspace using a Slack incoming webhook URL that you provide. To set one up:

Create a Slack app or use an existing one
Enable Incoming Webhooks in the app settings
Add a webhook to your workspace
Paste the webhook URL into Activity Guard settings

No data is stored by Slack beyond what you configure in your own Slack workspace. See Slack’s privacy policy for details.
Cloudflare Turnstile
Activity Guard uses Cloudflare Turnstile for login bot protection. When Turnstile is enabled, your login page communicates with Cloudflare’s verification servers. See Cloudflare’s privacy policy for details.
Plugin Vulnerability Scanner – Data Sources

WordPress.org Plugin API: retrieves plugin metadata including latest version, last updated date, rating, and active install count. Privacy Policy
WPAzleen API: private endpoint for known vulnerabilities by plugin and version. No sensitive data is transmitted. Privacy Policy
WPVulnerability.net: public API for CVE-based vulnerability data. Privacy Policy
National Vulnerability Database (NVD): official CVE data from NIST. Privacy Policy

All scans run locally using public metadata and vulnerability feeds. Activity Guard does not collect, store, or transmit any personal information during scans.
Freemius
Activity Guard uses the Freemius SDK for optional telemetry. No data is collected by default. Data collection only starts after you explicitly confirm in the admin notice. See the Freemius privacy policy for details.
WPAzleen Settings API
Loads display settings for the Pro upgrade modal in the plugin admin area. No personal data is transmitted. WPAzleen Privacy Policy
Source Code
The source files for all compiled/minified JavaScript and CSS in this plugin are publicly available at:
https://github.com/wpazleen/activity-guard
Build instructions:

Clone the repository or visit the src directory directly.
Run npm install in the root to install dependencies.
Run npm run build to compile JavaScript and CSS assets.
Compiled files output to build/.

Contributions, bug reports, and pull requests are welcome.

延伸相關外掛

文章
Filter
Apply Filters
Mastodon