* Images may vary from the product shown

EHERO Audit Log – Audit log for WordPress and WooCommerce: who changed what, person or plugin

SKU: ehero-audit-log

Brand: EHERO

The audit log for WordPress and WooCommerce that tells you who changed what, when and how, person or plugin, with the old value and the new one. Even what was done outside WordPress.

  • The plugin or theme responsible for each change, with file and line
  • Products and orders field by field, with before, after, and undo
  • Detection of changes in the database and in files made outside WordPress
  • Alerts by email, Slack, Discord, Telegram, or webhook
  • Signed and chained log, guardian, and external copy
  • Report for GDPR, NIS2, and ISO 27001, without slowing down your site

Audit log for WordPress and WooCommerce: who changed what, when and how, person or plugin

The audit log for WordPress from EHERO Audit Log is the black box of your website. When something happens that you didn’t expect — a price changes overnight, a product runs out of stock, a backup plugin someone disabled — it gives you the exact answer: who did it, what changed, when, from where, and what the previous value was.

Most logs stop at the logged-in user. But in a store with synchronizations, many changes are not made by a person: they are made by a plugin, a scheduled task, or an external program. This audit log for WordPress also tells you which plugin or theme made the change, with the file and line, and detects what was changed outside WordPress, where no other log looks.

And it does it without weighing things down: visits to your site add no queries, events are written once at the end of each request, and all the heavy work runs in the background. Each event is signed and chained to the previous one, so nobody can erase their tracks without verification flagging it.

Audit log for WordPress: event viewer on desktop and mobile
All inside WordPress
From doubt to answer in one minute
This is how EHERO Audit Log’s audit log for WordPress works from day one.
1. Activate Install it, activate the license, and it starts logging. No setup needed: the areas and basic alerts come ready to use.
2. Log Every change to content, products, orders, users, plugins, and settings is saved with its before and after, and with the person or plugin that made it.
3. Notify Important events reach you by email, Slack, Discord, Telegram, or webhook as soon as they happen, with a daily summary of everything else.
4. Prove Filter, export, or print the report for the period. Integrity verification proves the log has not been tampered with.
Documentation Full manual in Spanish inside the plugin itself and on the website. Questions before buying? Write to us at soporte@consultoriaehero.com

Person or plugin: who really made each change

It’s the question every store with synchronizations asks: “Who changed the price at 3:00?”. The answer is almost never a person.

  • Each event shows the logged-in user and, in addition, the plugin or theme that executed the change.
  • With one click you see the exact file and line, and the WordPress action that triggered it.
  • Scheduled tasks appear as “cron” and commands as “wp-cli”, with the originating request.
  • Everything that happened in the same page load, grouped together: if an importer touched a hundred products, you see it together.
Detail of an event with the plugin, file and line that made the change

A complete audit log for WordPress with WooCommerce

Everything in WordPress and, with WooCommerce active, the entire store field by field. No separate extensions for products or orders.

  • Products and variations: prices, stock, SKU, description, attributes, shipping, taxes, and visibility, with before and after.
  • HPOS-compatible orders: creation, status changes, notes, refunds, line items, and addresses.
  • Store: coupons, shipping and payment methods, taxes, and WooCommerce settings.
  • Content, media, comments, menus, taxonomies, and custom fields.
  • Users and access: signups, deletions, roles, logins, grouped failed attempts, and password resets (never the password).
  • Plugins, themes, and core: installs, activations, updates, deletions, and file editing.

Before and after, history on every screen, and undo

It’s not enough to know that something changed: you need the previous value to fix it.

  • Detailed view of each event with all fields before and after, and line-by-line comparison of long text.
  • Change history inside the edit screen for each product, order, post, and page, and in each user’s profile.
  • Undo post, product, custom field, and user data changes with one click.
  • If the object changed again afterward, it warns you before overwriting anything.
Change history on the product screen with before, after and undo

Changes made outside WordPress

Some changes never go through WordPress: an edit in phpMyAdmin, an ERP writing directly to the tables, or a file uploaded by FTP. No hook fires, and a normal log won’t see them.

  • Compares background fingerprints of administrators, key settings (site URL, admin email, default role, active plugins), and all product fields.
  • Checks the PHP files of WordPress, plugins, and themes every 6 hours.
  • Separates expected changes from unexpected ones: a change that matches a recorded update is not an alert.
  • Looks for PHP files in the uploads folder, where they should never be.
  • Everything it detects enters the log as another event, with its alert.
Changes made outside WordPress detected in the database

Instant alerts, without flooding you

You find out about the important stuff when it happens, not a week later while checking the log.

  • Email, Slack, Discord, Telegram, or webhook with signed JSON, each channel with its own test button.
  • Rules by area, event type, and minimum importance: critical, security, plugins, prices, or whatever you define.
  • Daily summary at the time you choose with everything else.
  • Alert limit per rule and hour, so an importer doesn’t fill your inbox.
  • They are sent in the background, so they never slow down a page.
Alerts by email, Slack, Discord, Telegram and webhook with rules

A tamper-proof log

An intruder first tries to erase their tracks. Here they can’t do it without it being noticed.

  • Each event is signed and chained to the previous one in its area.
  • Verification, weekly or on demand, detects edits, deletions, and insertions and says exactly where.
  • The signing key can live in wp-config.php: even with full database access, events cannot be forged.
  • The guardian keeps logging even if someone disables the plugin from the dashboard, and leaves a critical entry if they remove it.
  • Individual events cannot be edited or deleted; emptying the log requires confirmation and is recorded.
Signed and chained log with integrity verification

Site health: what breaks is logged too

Many store problems are not changes made by anyone, but things that fail silently.

  • Fatal PHP errors, with the responsible plugin and file.
  • Emails that could not be sent, such as the notice for a new order.
  • HTTP requests to external services that fail or are slow.
  • Scheduled tasks that fail or are delayed, and slow requests from your own site.

Summary and viewer to find everything in seconds

See what’s happening in your store at a glance, and the exact event when you need it.

  • Activity by day and area, alerts, critical events, and failed logins from the last 24 hours.
  • Who changes the most things, which plugins touch your store, and which events are most frequent.
  • Filters by date, person, role, area, importance, event type, plugin, object, source, IP, and text.
  • Quick views, saved filters, and CSV or JSON export, even for large logs.
Activity summary by day and area, most active people and plugins

Compliance report ready for audits

When a client, insurer, or auditor asks for it, you have it in one click. Designed with GDPR Article 32, the NIS2 directive, ISO 27001, and DORA in mind.

  • Activity by area, access, privilege changes, and alerts for the period you choose.
  • Log integrity status, with the latest full verification.
  • Print or save as PDF directly from the browser.
  • Read-only Auditor role for your consultant, DPO, or auditor, without access to the rest of the dashboard.
Activity and integrity report for audits, ready for PDF

External backup and central console for multiple sites

If someone takes full control of the server, they can delete the log. An off-site copy cannot.

  • Signed delivery of events to your own webhook: your SIEM, storage, or automation.
  • Central console: one of your sites receives the full history of the others and alerts you if any stops reporting.
  • If the destination is down, delivery pauses and continues where it left off, without losing anything.
  • Age-based cleanup never deletes what has not yet reached the external copy.

A WordPress audit log that doesn’t slow down your site

Logging everything can’t come at the cost of speed. That’s why the design starts with performance.

  • Visits to the site add no database queries.
  • Events are kept in memory during the request and written all at once at the end.
  • Signing, detection, alerts, external backup, and cleanup run in the background, in small batches and with a time limit.
  • Repeated events are grouped with a counter, tables are custom and indexed, and retention is capped.
Performance: no extra queries on visits and heavy work in the background

Privacy, WP-CLI and custom events

Made in the EU and designed so that the log itself complies with what it helps prove.

  • IP anonymized by default, export and deletion of personal data from WordPress tools, and text for your privacy policy.
  • It never stores passwords or keys: settings that look like secrets are logged hidden.
  • Retention by days, general and by area, and a row limit.
  • WP-CLI commands to list, export, verify, seal and scan, and an action so your own plugins can log their events.

Ideal for

If more than one person or more than one plugin touches your site, the audit log for WordPress from EHERO Audit Log saves you hours of looking for culprits. Where it pays off most:

🔄

Stores with synchronizations

ERPs, suppliers or marketplaces that change prices and stock on their own: you’ll know which plugin did it and when.

👥

Teams with multiple people

Managers, editors and external users in the same dashboard, each with their own trail of changes.

🏢

Agencies with multiple websites

A central console with the history of all your clients and an alert if any of them stops reporting.

🛡️

Companies with obligations

GDPR, NIS2, ISO 27001 or DORA: signed evidence and a report ready for the auditor.


📋 System requirements

Compatibility tested with the current versions of WordPress and WooCommerce.

WordPress 6.0 or higher
PHP 7.4 or higher
WooCommerce Optional; tested up to 10.8 and HPOS compatible
Server Any hosting with WP-Cron or system cron
Alerts WordPress email, Slack, Discord, Telegram or webhook
Multisite Central console to bring together multiple websites
Languages Spanish and English

🛟 Technical support

Email support in Spanish* at soporte@consultoriaehero.com and a complete manual inside the plugin. The audit log for WordPress updates itself from your dashboard during the license year.


⚖️ Comparison: why EHERO Audit Log?

What sets this audit log for WordPress apart from free activity logs and generic premium ones.

Feature Free logs Generic premium logs EHERO Audit Log
Who made the change (user) ✅ ✅ ✅
Which plugin or theme did it, with file and line ❌ ⚠️ Only the channel ✅
Products and orders field by field (HPOS) ⚠️ ⚠️ With extension ✅
Undo changes ❌ ⚠️ ✅
Changes made outside WordPress ❌ ❌ ✅
Signed and chained log ❌ ❌ ✅
Alerts via Slack, Discord, Telegram and webhook ❌ ✅ ✅
External copy and central console ❌ ⚠️ Higher plan ✅
Report for GDPR, NIS2 and ISO 27001 ❌ ⚠️ ✅
Price in euros, EU company — ❌ ✅
Price / year Free 79–189 $ from 99.99 €

Works especially well with…

The more automated processes your store has, the more useful it is to know what each one did.

  • EHERO Woo Supplier Stock Manager — every supplier stock entry is recorded with the plugin that made it.
  • EHERO Woo Holded — if a synchronization with Holded touches a product or an order, you see its before and after.
  • EHERO Woo POS — sales and changes made from the register, with the person who was on shift.
  • EHERO Woo Multilang — who translated or changed each version of your products and pages.

Practical case: a fashion store wakes up with a pair of sunglasses at €9 instead of €90. The log shows it wasn’t anyone on the team: it was the supplier sync plugin at 3:00, from its importer, line 214. The manager undoes the change in one click, the price alert had already warned via Slack, and the supplier receives the exact details to fix their file.


Frequently asked questions

Does it slow down the site?

No. Visits add no queries, changes are written once at the end of the request, and all heavy work runs in the background, in batches and with a time limit. In our tests, public pages take the same time with the plugin active as without it.

Are passwords or keys logged?

Never. Password changes are logged as done, without the value, and any setting that looks like a secret is stored hidden.

Can I edit or delete individual events?

No, and that is intentional: an audit log for WordPress that can be altered is not valid evidence. It can only be emptied entirely by typing a confirmation word, and the purge leaves its own entry and notifies your alerts.

Does it work without WooCommerce?

Yes. It logs all of WordPress: content, users, plugins, themes and settings. With WooCommerce active, it adds products, orders and store settings.

What happens if someone deactivates the plugin?

If you install the guardian from the Integrity page, the log keeps working even if they deactivate the plugin from the dashboard, and if someone deletes its files a critical entry is created. With the external copy, the events already sent are also out of reach.

How many websites does my license cover?

It depends on the plan: 1, 5 or 25 sites. All plans include all features, including the central console; only the number of websites changes.


✔️ One license for all your websites — from 1 to 25

All plans include all features of the audit log for WordPress — person or plugin, before and after, undo, detection outside WordPress, alerts, signed log, guardian, external copy, central console and report —, one year of updates and email support*. Only the number of sites changes.

1 site
99.99 €
per year
5 sites
249.99 €
per year
25 sites
499.99 €
per year

The next time something changes without permission, you’ll know who did it, person or plugin, and undo it in one click. Start today from 99.99 €.

Put a black box on your site with the EHERO Audit Log audit log for WordPress.

Want to see more tools for your store? Discover all our plugins for WooCommerce or visit the Consultoría EHERO store.

*Support covers incidents, errors, and plugin installation; it does not include consulting, custom configurations, or custom development. Conditions apply.

Reviews of EHERO Audit Log – Audit log for WordPress and WooCommerce: who changed what, person or plugin

0
☆☆☆☆☆
0 reviews
5 ★
0
4 ★
0
3 ★
0
2 ★
0
1 ★
0

No reviews yet. Be the first to share your opinion!

Questions and answers

There are no questions about this product yet. Be the first to ask!

Do you have a question?

How we handle reviews

Where reviews come from.
Reviews are written by customers and visitors to our store. After each purchase we send an email invitation to rate the product.

"Verified purchase" label.
We only show this label when we can confirm the author bought the product in this store (same email as the order).

Incentivized reviews.
We sometimes offer a discount coupon as a thank-you for leaving a review. The coupon is given regardless of whether the rating is positive or negative, and those reviews are marked with an "Incentivized review" label.

Moderation.
We review submissions before publishing only to filter out spam, offensive language, personal data, or content unrelated to the product. We do not delete or hide reviews for being negative.

Publication.
Reviews are shown sorted by date by default, and users can reorder or filter them. The average rating is calculated over all published reviews.

Ask us any questions you have with no obligation! Our team will be happy to help you.

Do you have questions about EHERO Audit Log – Audit log for WordPress and WooCommerce: who changed what, person or plugin?

Name: *
Company:
Email Address: *
Message: *

The controller of the personal data provided is Consultoría EHERO SLU, which will process it in order to contact and inform you in accordance with the request made through this form. The legal basis that allows us to use this data is your consent. Your data will not be shared except where legally required, and it may be accessed by the service providers listed in the Privacy Policy. You have the right to access, rectify and erase your data by emailing Consultoría EHERO SLU at info@consultoriaehero.com. You may also file a complaint with the supervisory authority (www.aepd.es) if you believe the processing does not comply with the regulations.

Subscribe to our newsletter

Get exclusive deals and updates.

Get 10% OFF your first order!
0