Description
Admin Watch Central gives WordPress administrators a clear view of who can make meaningful changes to a site. Review privileged-user access, recent logins, current sessions, password-change visibility, supported MFA status, Site Health, aggregated 404 activity and a lightweight Site Activity history. All Admin Watch Central screens require the existing WordPress manage_options capability.
Key Features
- Privileged-user access visibility for roles that can make meaningful website changes.
- Latest successful login visibility after installation.
- A dedicated, searchable and paginated Active Sessions screen for eligible users.
- Lightweight Site Activity for successful logins, explicit logouts, grouped failed logins, user creation/deletion, role and password changes, content changes, plugin/theme activity, WordPress core updates and Admin Watch Central settings changes.
- Site Activity category, user and date filters, search, pagination and a five-item Dashboard preview.
- Site Activity recording and failed-login switches, 7/30/90-day retention and a confirmed clear-log control.
- Observed password-change dates and local password-strength estimates.
- Supported MFA status visibility without collecting MFA secrets.
- Site Health summary with a link to WordPress’s native Site Health screen.
- Aggregated 404 monitoring with accurate daily and seven-day request totals.
- Privacy-conscious local operation with no telemetry, IP collection or password copies, and WordPress personal-data export/erasure integration.
404 request totals are maintained as small daily aggregates, so the Dashboard’s today and seven-day totals remain accurate without retaining individual requests.
Login and password-change metadata is recorded only after Admin Watch Central observes the relevant event. MFA status is available only for supported authentication providers and may show “Not detected” when status cannot be reliably determined. Active Session counts are read from current WordPress core session state for eligible users and are not stored by Admin Watch Central.
Site Activity begins when recording is enabled; existing login/password timestamps are not backfilled into history. It stores known event types, user IDs, object references, bounded labels, UTC timestamps and allow-listed metadata. Account names are resolved from current WordPress accounts rather than copied into history. Failed attempts can retain a bounded attempted username or email address and are counted in 15-minute buckets, with at most 100 named groups plus an unnamed overflow group per bucket. Oversized identifiers and identifiers that are literal IP addresses are not retained. Retention defaults to 30 days, accepts only 7, 30 or 90 days, and uses daily WordPress Cron cleanup. Disabling recording preserves retained history until cleanup, erasure or a confirmed clear operation.
Admin Watch Central does not create or store copies of passwords, password hashes or password history. Free does not collect, store, display, hash or anonymize IP addresses. It does not retain session tokens, session metadata, cookies, browser/device history, request bodies, content snapshots, MFA secrets, referrers or telemetry. There are no external services, alerts, session-control actions, exports/reports or redirect tools. WordPress’s native privacy tools can export and erase this plugin’s account metadata and retained activity linked to an account ID or its current failed-login username/email identifier, without deleting the account. Advanced monitoring, actions, policies, reports and extended retention remain separate Pro planning.
Site Activity is a lightweight operational history, not a forensic audit log. It observes supported native WordPress hooks; direct file/database changes, expired session cookies, revisions, autosaves and metadata-only content changes are not treated as activity. Current valid sessions do not indicate real-time online presence. Network-wide multisite management is not supported.
Screenshots






Installation
- Upload the
adminwatch-centralfolder to/wp-content/plugins/or install it through WordPress. - Activate Admin Watch Central through the Plugins screen.
- Open Admin Watch Central from the administrator menu.
FAQ
-
Why does a user say “Not recorded yet”?
-
Admin Watch Central only records successful logins after it is installed. It does not guess historic login activity.
-
Does deactivation delete data?
-
No. Data is retained on deactivation. The optional delete-on-uninstall setting controls deletion when the plugin is removed.
-
Does Admin Watch Central monitor WordPress logins?
-
It records the latest successful login after observing WordPress’s successful-login hook. When Site Activity is enabled, known login/logout events are also retained within the configured activity retention period. Nothing is inferred about earlier activity.
-
Can I see active WordPress sessions?
-
Yes. The dedicated Active Sessions screen reads current valid WordPress sessions for privileged users, with search, role filtering and pagination. It does not store session details or provide session termination, IP, device or browser tracking.
-
Does Admin Watch Central store passwords?
-
No. It stores only an observed password-change date and a local strength estimate when a password is changed.
-
Does Admin Watch Central record IP addresses?
-
No. Free does not collect or persist IP addresses in any form, for any event.
-
How do I control Site Activity data?
-
Settings can disable all activity recording, disable grouped failed-login recording, choose 7, 30 or 90 days of retention, or clear retained Site Activity with an explicit confirmation. Clearing activity does not delete latest account metadata or 404 data. Deactivation preserves data. Delete-on-uninstall applies to all Admin Watch Central settings, account metadata and tables.
-
Does Admin Watch Central send data to Web Studio WA?
-
No. Admin Watch Central works locally within WordPress and does not send telemetry to Web Studio WA.
Reviews
There are no reviews for this plugin.
Contributors and Developers
“Admin Watch Central” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “Admin Watch Central” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Change Log
1.1.0
- Added a dedicated, searchable and paginated Active Sessions screen.
- Added lightweight Site Activity with category, user and date filters, search and pagination.
- Added Dashboard Recent Activity and user-specific activity links.
- Added bounded failed-login aggregation without IP addresses.
- Added activity recording controls, 7/30/90-day retention and confirmed log clearing.
- Added monitoring for supported user, content, plugin, theme and confirmed automatic WordPress update events.
- Improved role-change activity accuracy and compatibility with WordPress admin notices.
- Extended WordPress privacy tools and optional uninstall cleanup to Site Activity.
- Preserved existing account metadata, 404 data and the administrator access model during upgrades.
1.0.2
- Refined the Admin Watch Central product name for clearer presentation.
- Improved compatibility with third-party WordPress admin notices.
- Improved WordPress.org listing copy and discovery metadata.
1.0.1
- Moved the Admin Watch Central admin menu higher for easier access.
1.0.0
- Initial release.
