Unstoppable Activity Tracker
Unstoppable Activity Tracker

Unstoppable Activity Tracker

0/5 (0 ratings) 30 active installs Updated Jul 22, 2026

Unstoppable Activity Tracker is a fully standalone activity tracker. It does not depend on any other plugin — it hooks WordPress directly and writes to its own database table.

New in 2.1.0: an Insights dashboard. See activity trends over time, event breakdown by category, most active users, and security highlights (failed logins, role changes, plugin activity, and more) — all with a time range switcher (24 hours / 7 days / 30 days / 90 days).

Use it as an audit log for a single site, or expose the REST endpoint to a dashboard, monitoring tool, or client portal of your choice.

What it tracks

  • Authentication: successful logins, failed login attempts, logouts.
  • Posts and pages (and any other public post type): created, updated, published, unpublished, trashed, restored, permanently deleted.
  • Users: registered, deleted, profile updated, role changed.
  • Plugins: activated, deactivated, installed, updated, deleted.
  • Themes: switched, installed, updated.
  • WordPress core: updated.
  • Site settings: site title, tagline, admin email, site URL, home URL, registration, default role, permalink structure, language.

Every event is stored with: timestamp, numeric event code, severity (info / notice / warning / error / critical), user, role, IP, user agent, message, and event-specific metadata (JSON).

What it does NOT do

  • It does not depend on any other plugin.
  • It does not send any data anywhere. All data stays on your site. Outbound requests only happen when you configure something else (a dashboard, portal, monitoring tool) to read the REST endpoint with the per-site API key.
  • It does not modify any third-party plugin’s data.

REST endpoints

All endpoints live under /wp-json/unstoppable/v1/ and require an API key in the X-Unstoppable-Key header. The key is auto-generated on activation and shown on the plugin’s settings page — no signup, no license, no external service. You can regenerate it any time. The requirement is authentication only (so the endpoint doesn’t expose activity data to the public web), not a paywall.

  • GET /ping — health check
  • GET /events — paginated events feed, with limit, since, object, event_type, severity filters
  • GET /stats — aggregate counts (total / last 24h / last 7d / by object)

Retention

A daily cron job deletes events older than the retention window (default 90 days). Set the retention to 0 to keep events forever.