Skip to content
WordPress User Activity & Password Monitoring

Watch who signs in, and what they change, on every site

VigilDeck records logins, failed attempts, password resets, new users and role changes across all your WordPress sites, a full user activity audit trail, with personal data masked by default.

At a glance

  • Logins, logouts and failed attempts, with the account and time
  • Password resets and changes recorded as they happen
  • New users, role changes and capability grants tracked
  • Email and profile edits captured with before/after context
  • PII masked by default; every reveal is itself audit-logged
The problem

By the time you notice the new admin, it is late

The fastest way into a WordPress site is not a clever exploit, it is a valid password on an admin account. Reused credentials, phishing and careless privilege grants put more sites at risk than any zero-day. That is why WordPress user activity and password monitoring is less about surveillance and more about early warning: an unexpected role change or a sudden run of failed logins is often the first visible sign of a breach.

VigilDeck records the events that matter on the authentication and account side, who signed in, who failed, who reset a password, who was promoted to administrator, and streams a signed copy off-site to a tamper-evident timeline. You get a genuine audit trail for security and compliance, spanning every site you manage, without the log living inside the account someone may have just compromised.

A compromised account rarely announces itself. An attacker who lands valid credentials will often create a second admin user, change an email address so reset links flow to them, or quietly bump a low-privilege account up to administrator. Native WordPress shows you a user list, not a history, so unless you happened to be watching at that exact moment, the change blends in.

The signals that would have warned you are just as invisible. A burst of failed logins against one username, a password reset nobody requested, a role change made at 3am from an unfamiliar session: individually easy to miss, together a clear pattern. Without a record, there is nothing to spot the pattern in.

Then there is accountability. When a setting changes on a site three people can access, "who did that?" should have an answer. Native WordPress cannot give you one after the fact, and on a portfolio of sites the question multiplies until it is unanswerable.

What gets recorded

The full user and authentication trail

VigilDeck captures the account events that signal trouble and satisfy an audit, each tied to the user, the object and the time it happened.

Logins & logouts

Successful sign-ins and sign-outs are recorded with the account and timestamp, building a session history per user.

Failed login attempts

Failed sign-ins are logged so a brute-force run or credential-stuffing spike shows up as a visible pattern.

Password resets & changes

Every password reset and change is captured the moment it happens, whether the user or an admin triggered it.

User creation & deletion

New accounts and removed ones are recorded, so a stealth admin created during a breach cannot slip in unseen.

Role & capability changes

Promotions, demotions and capability grants are tracked, because an unexpected jump to administrator is a red flag.

Email & profile edits

Changes to email addresses and profile fields are logged with before and after, since a swapped email hijacks resets.

How it works

From a login to a signed, searchable record

01

Capture

The free connector hooks WordPress authentication and user actions the instant they fire on the site.

02

Mask & sign

Personal data such as emails and mobile numbers is masked, then the event is signed with the site's HMAC key.

03

Verify & store

VigilDeck checks the signature over HTTPS and writes the event to an append-only, tamper-evident off-site store.

04

Surface & alert

The event lands on your cross-site timeline in seconds, where you can filter, review and act on it.

Benefits

Why user and password monitoring pays off

Catch breach signals early

Spot a failed-login spike, an unexpected role change or a stealth admin while you can still act, not in the post-mortem.

Keep the evidence off-site

Because the trail lives away from the site, it survives exactly when an attacker would delete the on-site log.

Protect personal data by default

Emails and mobile numbers are masked unless a privileged role reveals them, and every reveal is itself recorded.

Satisfy compliance reviews

Hand an auditor a clean, tamper-evident record of who signed in and what account changes were made, per site.

Who it's for

Who relies on the user activity trail

  • Security teams & incident response

    Reconstruct exactly how an account was compromised and what the attacker touched, from a record they could not erase.

  • Agencies with shared client logins

    Answer "who changed that?" across every client site from one screen, and prove your team was not the cause.

  • Compliance & data protection

    Show that user access and personal-data changes are logged and that PII is masked by default under least-privilege access.

Explore more

Related monitoring features

FAQ

User & Password Monitoring: frequently asked questions

What is WordPress user activity and password monitoring?

It is a full audit trail of account activity on your WordPress sites: logins, logouts, failed attempts, password resets and changes, new users, role changes and profile edits. VigilDeck records these events and streams a signed copy to a tamper-evident, cross-site timeline for security and compliance.

How does this help me detect a compromised account?

Compromised or careless admin accounts are a leading WordPress risk, and they leave traces: a flurry of failed logins, a password reset nobody asked for, or an account suddenly promoted to administrator. VigilDeck records each of these so the pattern is visible early, rather than surfacing only after the damage is done.

Does VigilDeck expose users' personal data?

No. Personal data such as email addresses and mobile numbers is masked by default. Only privileged roles can reveal it, and every reveal is itself written to the audit log, so access to sensitive fields is tracked and accountable.

Are failed login attempts recorded?

Yes. Failed sign-ins are logged with the account targeted and the time, so a brute-force run or credential-stuffing attempt shows up as a clear spike instead of disappearing. It is one of the earliest and most useful breach signals on a WordPress site.

Is the user activity log kept if the site is hacked?

Yes. Each event is signed on the site and written to an append-only store off-site, so the record survives even if the site is wiped or the on-site database is tampered with. That is the point when an attacker would try to erase their tracks, and the off-site trail is exactly what they cannot reach.

Can I see user activity across all my sites in one place?

Yes. Every connected site rolls up into a single timeline you can filter by site, user and event type. Pair it with team management to keep your own seats organized, and see pricing for retention by plan.

Command deck

Put every login and account change on one trail

Install the free connector, link your sites, and start watching user activity stream into your dashboard within minutes.

Free for up to 3 sites · No credit card required · Cancel anytime