Watch who signs in, and what they change, on every site
VigilDeck records logins, failed attempts, password resets, new users and role changes across all your WordPress sites, a full user activity audit trail, with personal data masked by default.
At a glance
- Logins, logouts and failed attempts, with the account and time
- Password resets and changes recorded as they happen
- New users, role changes and capability grants tracked
- Email and profile edits captured with before/after context
- PII masked by default; every reveal is itself audit-logged
By the time you notice the new admin, it is late
The fastest way into a WordPress site is not a clever exploit, it is a valid password on an admin account. Reused credentials, phishing and careless privilege grants put more sites at risk than any zero-day. That is why WordPress user activity and password monitoring is less about surveillance and more about early warning: an unexpected role change or a sudden run of failed logins is often the first visible sign of a breach.
VigilDeck records the events that matter on the authentication and account side, who signed in, who failed, who reset a password, who was promoted to administrator, and streams a signed copy off-site to a tamper-evident timeline. You get a genuine audit trail for security and compliance, spanning every site you manage, without the log living inside the account someone may have just compromised.
A compromised account rarely announces itself. An attacker who lands valid credentials will often create a second admin user, change an email address so reset links flow to them, or quietly bump a low-privilege account up to administrator. Native WordPress shows you a user list, not a history, so unless you happened to be watching at that exact moment, the change blends in.
The signals that would have warned you are just as invisible. A burst of failed logins against one username, a password reset nobody requested, a role change made at 3am from an unfamiliar session: individually easy to miss, together a clear pattern. Without a record, there is nothing to spot the pattern in.
Then there is accountability. When a setting changes on a site three people can access, "who did that?" should have an answer. Native WordPress cannot give you one after the fact, and on a portfolio of sites the question multiplies until it is unanswerable.
The full user and authentication trail
VigilDeck captures the account events that signal trouble and satisfy an audit, each tied to the user, the object and the time it happened.
Logins & logouts
Successful sign-ins and sign-outs are recorded with the account and timestamp, building a session history per user.
Failed login attempts
Failed sign-ins are logged so a brute-force run or credential-stuffing spike shows up as a visible pattern.
Password resets & changes
Every password reset and change is captured the moment it happens, whether the user or an admin triggered it.
User creation & deletion
New accounts and removed ones are recorded, so a stealth admin created during a breach cannot slip in unseen.
Role & capability changes
Promotions, demotions and capability grants are tracked, because an unexpected jump to administrator is a red flag.
Email & profile edits
Changes to email addresses and profile fields are logged with before and after, since a swapped email hijacks resets.
From a login to a signed, searchable record
Capture
The free connector hooks WordPress authentication and user actions the instant they fire on the site.
Mask & sign
Personal data such as emails and mobile numbers is masked, then the event is signed with the site's HMAC key.
Verify & store
VigilDeck checks the signature over HTTPS and writes the event to an append-only, tamper-evident off-site store.
Surface & alert
The event lands on your cross-site timeline in seconds, where you can filter, review and act on it.
Why user and password monitoring pays off
Catch breach signals early
Spot a failed-login spike, an unexpected role change or a stealth admin while you can still act, not in the post-mortem.
Keep the evidence off-site
Because the trail lives away from the site, it survives exactly when an attacker would delete the on-site log.
Protect personal data by default
Emails and mobile numbers are masked unless a privileged role reveals them, and every reveal is itself recorded.
Satisfy compliance reviews
Hand an auditor a clean, tamper-evident record of who signed in and what account changes were made, per site.
Who relies on the user activity trail
-
Security teams & incident response
Reconstruct exactly how an account was compromised and what the attacker touched, from a record they could not erase.
-
Agencies with shared client logins
Answer "who changed that?" across every client site from one screen, and prove your team was not the cause.
-
Compliance & data protection
Show that user access and personal-data changes are logged and that PII is masked by default under least-privilege access.
Related monitoring features
User & Password Monitoring: frequently asked questions
What is WordPress user activity and password monitoring?
It is a full audit trail of account activity on your WordPress sites: logins, logouts, failed attempts, password resets and changes, new users, role changes and profile edits. VigilDeck records these events and streams a signed copy to a tamper-evident, cross-site timeline for security and compliance.
How does this help me detect a compromised account?
Compromised or careless admin accounts are a leading WordPress risk, and they leave traces: a flurry of failed logins, a password reset nobody asked for, or an account suddenly promoted to administrator. VigilDeck records each of these so the pattern is visible early, rather than surfacing only after the damage is done.
Does VigilDeck expose users' personal data?
No. Personal data such as email addresses and mobile numbers is masked by default. Only privileged roles can reveal it, and every reveal is itself written to the audit log, so access to sensitive fields is tracked and accountable.
Are failed login attempts recorded?
Yes. Failed sign-ins are logged with the account targeted and the time, so a brute-force run or credential-stuffing attempt shows up as a clear spike instead of disappearing. It is one of the earliest and most useful breach signals on a WordPress site.
Is the user activity log kept if the site is hacked?
Yes. Each event is signed on the site and written to an append-only store off-site, so the record survives even if the site is wiped or the on-site database is tampered with. That is the point when an attacker would try to erase their tracks, and the off-site trail is exactly what they cannot reach.
Can I see user activity across all my sites in one place?
Yes. Every connected site rolls up into a single timeline you can filter by site, user and event type. Pair it with team management to keep your own seats organized, and see pricing for retention by plan.
Put every login and account change on one trail
Install the free connector, link your sites, and start watching user activity stream into your dashboard within minutes.
Free for up to 3 sites · No credit card required · Cancel anytime