Track Every Plugin Change Across Your WordPress Sites
See exactly which plugin was installed, updated or removed, on which site, by whom, and tie any breakage to the precise version change that caused it.
At a glance
- Logs installs, activations, deactivations, updates and deletions
- Records the version before and after every plugin update
- Captures manual and auto-update events alike
- Cross-site view of every pending plugin update
- Off-site, tamper-evident record that survives a hacked site
When a site breaks, plugins are the usual suspect
Plugins are where most of WordPress actually happens, and they are also where most of it goes wrong. A single update can change a checkout flow, disable a contact form, or open a known vulnerability, and by default WordPress keeps almost no lasting record of any of it. WordPress plugin monitoring means having a durable, searchable history of every plugin event on every site you run.
VigilDeck watches the plugin layer continuously. When a plugin is installed, activated, updated, deactivated or deleted, VigilDeck records the event with the site, the user, the timestamp and the exact version numbers involved. It is an activity-intelligence tool, not a management tool: it does not push updates for you, it tells you precisely what changed so you can act with the full picture in front of you.
Outdated plugins are the most common way WordPress sites get compromised, and unattended auto-updates are the most common way they silently break. The form that stopped sending, the layout that shifted, the checkout that started failing at 2am: nine times out of ten it traces back to a plugin that changed, and you often find out from a customer rather than from your own tooling.
The built-in plugins screen only shows you the current state. It cannot tell you that WooCommerce jumped two minor versions last Tuesday, that a caching plugin was deactivated by a colleague, or that an add-on quietly auto-updated overnight. Once the change is made, the evidence of what it replaced is gone.
Multiply that across a dozen or a hundred sites and the guesswork compounds. You end up bisecting the problem by hand, toggling plugins on and off in production, hoping to reproduce a break whose cause was already recorded somewhere if only something had been watching.
Full-lifecycle plugin monitoring
Every meaningful thing that can happen to a plugin, logged with the context you need to act on it.
Installs and deletions
Records when a plugin is added to or removed from a site, with the name, version and the account responsible.
Version-aware updates
Every update is logged with the version before and after, so a regression can be matched to the exact change that introduced it.
Auto-update events
Background auto-updates are captured just like manual ones, so overnight changes never happen off the record.
Activation state
Activations and deactivations are tracked per site, showing when a plugin was switched on or quietly turned off.
Pending-update overview
A cross-site view surfaces which sites are behind on which plugins, so you can see your exposure at a glance.
Tamper-evident history
Events stream off-site to an append-only store, so the plugin record survives even if a site is wiped or hacked.
How plugin monitoring works
Install the free connector
Add the free VigilDeck plugin from WordPress.org to each site. No account is needed to start logging activity locally.
Connect to the dashboard
Link the site to your VigilDeck account to begin streaming signed plugin events off-site over HTTPS.
Every change is recorded
Installs, updates, activations and deletions are captured automatically with full version detail.
Investigate and correlate
When something breaks, filter the timeline to the site and time window and read the exact plugin change behind it.
Why teams monitor plugins with VigilDeck
Root-cause in minutes
Tie a broken form or failing checkout to the precise plugin version change, instead of bisecting by hand in production.
Smaller attack surface
The pending-updates view shows which sites run outdated plugins, so the most common attack vector does not go unnoticed.
No more silent changes
Auto-updates and colleague actions are all on the record, so nothing changes on your sites without a trace.
History that outlives the site
Because the log lives off-site, you can still see what a plugin did even after the site is restored or rebuilt.
Who relies on plugin monitoring
-
Agencies
Prove to a client exactly which plugin update broke their site, and when, without trawling through server logs across dozens of installs.
-
WooCommerce stores
Catch the extension update that changed checkout behaviour before it costs a day of orders.
-
Maintenance providers
Show a defensible record of every plugin change made under a care plan, per site, for every month billed.
Related monitoring features
Plugin Monitoring: frequently asked questions
What plugin events does VigilDeck record?
VigilDeck logs installs, activations, deactivations, updates and deletions for every plugin on a connected site. Updates include the version before and after the change. Both manual and automatic updates are captured.
Does VigilDeck update my plugins for me?
No. VigilDeck is a monitoring and activity-intelligence platform, not a management tool. It records and reports what changed so you can decide what to do, but it does not run updates, backups or installs on your behalf.
Can I see which sites have plugin updates pending?
Yes. The cross-site dashboard includes a pending plugin-updates view so you can see which sites are behind and on which plugins, all in one place rather than logging into each site.
Will the log survive if a site gets hacked?
Yes. Events are streamed off-site over HTTPS to an append-only, tamper-evident store as they happen. Even if a site is compromised or wiped, the record of what changed remains available on your dashboard.
How does this help me find what broke a site?
Because every update records the exact version change, you can match a regression to the specific plugin and version that introduced it. Filter the activity log to the time window and read the change directly.
Is there a free tier for plugin monitoring?
Yes. The free plan covers up to 3 sites with 7 days of cloud history. Pro adds 1-year history at $2 (₹99) per site per month, and Agency covers up to 100 sites with unlimited history. See pricing for details.
Start monitoring your plugins today
Install the free connector and see every plugin change across your WordPress sites.
Free for up to 3 sites · No credit card required · Cancel anytime