← All guides

WordPress: Check WP Activity Log and saved IP addresses

Prerequisites

WordPress administrative access and clarity about which audit events are actually needed for administration or security.

WP Activity Log records detailed user and system events and explicitly mentions the Source IP as the event detail. Such an audit log can be useful for administration and security, but is not an anonymous visitor counter. Limit event scope, access and retention.

Check

After the change, check browser memory, network connections and web server, proxy and application logs separately. A product setting does not automatically prove that no visitor IP is stored at all levels.

Classification

To differentiate between technically necessary processing, security logging and permanent storage, additionally use IP processing and IP storage: the crucial difference . Security data should be dedicated, access-restricted and only retained for as long as necessary.

Dismantling

If more audit events are required for administration or security, only reactivate the required event types and limit their retention.

Related guides

Sources and verification

This guide is based on multiple current sources. Vendor documentation is not treated as proof that every concrete installation automatically follows the same privacy characteristics.

Important: IP processing is not IP storage

An IP address has to be processed to establish and deliver a network connection. Hosting providers, firewalls or DDoS protection may also process or retain it for a limited time for security purposes. No Logging distinguishes this security layer from unnecessary persistent visitor logging by the website, application and ordinary access logs.

↑