Title: TraceVault Audit Log
Author: Naowas Morshed Eimon
Published: <strong>2026年7月12日</strong>
Last modified: 2026年8月11日

---

プラグインを検索

![](https://ps.w.org/tracevault-audit-log/assets/banner-772x250.png?rev=3604469)

![](https://ps.w.org/tracevault-audit-log/assets/icon.svg?rev=3604469)

# TraceVault Audit Log

 作者: [Naowas Morshed Eimon](https://profiles.wordpress.org/naowas/)

[ダウンロード](https://downloads.wordpress.org/plugin/tracevault-audit-log.1.1.0.zip)

 * [詳細](https://ja.wordpress.org/plugins/tracevault-audit-log/#description)
 * [レビュー](https://ja.wordpress.org/plugins/tracevault-audit-log/#reviews)
 *  [インストール](https://ja.wordpress.org/plugins/tracevault-audit-log/#installation)
 * [開発](https://ja.wordpress.org/plugins/tracevault-audit-log/#developers)

 [サポート](https://wordpress.org/support/plugin/tracevault-audit-log/)

## 説明

TraceVault Audit Log gives administrators a clear, searchable audit trail for important
WordPress activity. It records user, content, media, comment, plugin, theme, settings,
and optional WooCommerce events into optimized custom tables, then makes that activity
easy to review from wp-admin.

Use it to investigate account activity, track content changes, review system-level
events, export filtered reports, and control how long audit data stays on the site.

#### Key Features

 * Custom database tables for audit logs, searchable metadata, storyline incidents,
   and settings.
 * Batched log writes to reduce runtime overhead.
 * Indexed filters for event type, severity, user, role, IP address, object, date,
   and keyword search.
 * Activity Logs screen with readable event labels, quick filters, CSV/JSON exports,
   and clear controls.
 * Configurable admin date display, including WordPress format, relative time, and
   fixed timestamp formats.
 * TraceVault Storylines reconstructs related events into explainable security incidents.
 * Deterministic local risk scoring with the exact reasons each incident was flagged.
 * Privacy-safe request and session correlation without storing authentication cookies
   or raw session tokens.
 * Incident review notes, open/reviewed/resolved workflow, and forensic JSON exports.
 * REST API endpoints for logs, stats, and exports.
 * Retention controls, IP anonymization, personal data export, and personal data
   erasure support.
 * Multisite activation support.
 * Developer hooks and filters for custom event types.
 * Quiet defaults: verbose option-update logging is disabled unless enabled, and
   noisy cache-style options are ignored.

#### TraceVault Storylines

Storylines connects related audit records by actor, privacy-safe session fingerprint,
username, IP address, and time window. Instead of leaving administrators to interpret
isolated rows, it reconstructs a chronological security story and explains its risk
score.

Built-in local rules detect repeated failed logins, successful logins following 
repeated failures, administrator role escalation, privileged system changes after
an escalation, bursts of system changes, high-impact activity from a new session,
and sensitive WordPress setting changes. No AI service or external detection API
is used.

Administrators can investigate the full timeline, record an analyst note, mark incidents
reviewed or resolved, and export a forensic JSON report. Storyline sensitivity and
correlation window are configurable in settings.

#### Logged Activity

TraceVault Audit Log can record:

 * Users: login, logout, failed login attempts, profile updates, password changes,
   role changes, user creation, and deletion.
 * Content: post and page creation, updates, deletion, media upload/deletion, comment
   creation, comment status changes, and comment deletion.
 * System: plugin activation/deactivation/deletion, plugin and theme install/update
   completion, theme switch, and selected settings changes.
 * WooCommerce: order create/update/status change, product create/update, and coupon
   create/update when WooCommerce is active.

#### Privacy and Retention

Audit logs can contain operationally sensitive data. TraceVault Audit Log keeps 
the controls local to your WordPress install:

 * No external logging service is required.
 * Retention defaults to 90 days and can be changed from settings.
 * IP anonymization can be enabled before storage.
 * Personal data exporter and eraser callbacks are registered for WordPress privacy
   tools.
 * Data deletion on uninstall is opt-in so audit history is not removed accidentally.

#### Developer Friendly

Developers can create custom events with `tracevault_log_event()` and extend behavior
with filters such as `tracevault_allowed_events` and `tracevault_log_data_before_insert`.

Storyline scoring can be extended with `tracevault_storyline_evaluation`, and integrations
can listen for created or extended incidents with `tracevault_storyline_updated`.

## スクリーンショット

[⌊Activity Logs dashboard with summary cards, filters, exports, and the audit log
table.⌉⌊Activity Logs dashboard with summary cards, filters, exports, and the audit
log table.⌉[

Activity Logs dashboard with summary cards, filters, exports, and the audit log 
table.

[⌊Log details modal with event context, severity, user, IP address, user agent, 
and metadata.⌉⌊Log details modal with event context, severity, user, IP address,
user agent, and metadata.⌉[

Log details modal with event context, severity, user, IP address, user agent, and
metadata.

[⌊Settings screen for retention, privacy, date display, noisy option logs, and uninstall
behavior.⌉⌊Settings screen for retention, privacy, date display, noisy option logs,
and uninstall behavior.⌉[

Settings screen for retention, privacy, date display, noisy option logs, and uninstall
behavior.

## インストール

 1. Upload the `tracevault-audit-log` folder to `/wp-content/plugins/`.
 2. Activate the plugin through the Plugins screen.
 3. Open **Activity Logs** in wp-admin.
 4. Configure retention, privacy, and date display settings.

## FAQ

### Does this plugin use custom tables?

Yes. It creates `wp_tracevault_logs`, `wp_tracevault_meta`, `wp_tracevault_incidents`,
and `wp_tracevault_settings` for each site.

### Does it send logs to an external service?

No. Logs are stored in your WordPress database using the site’s configured database
connection.

### Does it support multisite?

Yes. Network activation creates tables for each site. Each site keeps its own audit
tables using the site table prefix.

### Does it store passwords or sensitive form fields?

No. Password hooks intentionally ignore password values, and option updates log 
the option key without serializing old or new option values.

### Can logs be deleted on uninstall?

Yes, but only if you enable the uninstall deletion setting before uninstalling.

### Can developers add custom audit events?

Yes. Use `tracevault_log_event()` to write custom events and filters to control 
allowed event types or modify log data before storage.

## 評価

このプラグインにはレビューがありません。

## 貢献者と開発者

TraceVault Audit Log はオープンソースソフトウェアです。以下の人々がこのプラグイン
に貢献しています。

貢献者

 *   [ Naowas Morshed Eimon ](https://profiles.wordpress.org/naowas/)

[“TraceVault Audit Log” をあなたの言語に翻訳しましょう。](https://translate.wordpress.org/projects/wp-plugins/tracevault-audit-log)

### 開発に興味がありますか ?

[コードを閲覧](https://plugins.trac.wordpress.org/browser/tracevault-audit-log/)
するか、[SVN リポジトリ](https://plugins.svn.wordpress.org/tracevault-audit-log/)
をチェックするか、[開発ログ](https://plugins.trac.wordpress.org/log/tracevault-audit-log/)
を [RSS](https://plugins.trac.wordpress.org/log/tracevault-audit-log/?limit=100&mode=stop_on_copy&format=rss)
で購読してみてください。

## 変更履歴

#### 1.1.0

 * Added TraceVault Storylines for automatic, explainable incident reconstruction.
 * Added privacy-safe request and session correlation using keyed, non-reversible
   fingerprints.
 * Added deterministic risk rules for login attacks, role escalation, privileged
   system changes, new sessions, system-change bursts, and sensitive settings.
 * Added an Incidents dashboard with chronological timelines, risk reasons, filtering,
   review notes, and resolution status.
 * Added forensic JSON incident exports.
 * Added automatic database upgrades and retention cleanup for incident records.

#### 1.0.0

 * Initial release.

## メタ

 *  バージョン **1.1.0**
 *  最終更新日 **1週間前**
 *  有効インストール数 **10未満**
 *  WordPress バージョン ** 5.0またはそれ以降 **
 *  検証済み最新バージョン: **7.0.4**
 *  PHP バージョン ** 7.4またはそれ以降 **
 *  言語
 * [English (US)](https://wordpress.org/plugins/tracevault-audit-log/)
 * タグ
 * [Activity Log](https://ja.wordpress.org/plugins/tags/activity-log/)[audit log](https://ja.wordpress.org/plugins/tags/audit-log/)
   [monitoring](https://ja.wordpress.org/plugins/tags/monitoring/)[security](https://ja.wordpress.org/plugins/tags/security/)
   [woocommerce](https://ja.wordpress.org/plugins/tags/woocommerce/)
 *  [詳細を表示](https://ja.wordpress.org/plugins/tracevault-audit-log/advanced/)

## 評価

レビューはまだ送信されていません。

[Your review](https://wordpress.org/support/plugin/tracevault-audit-log/reviews/#new-post)

[すべてのレビューを見る](https://wordpress.org/support/plugin/tracevault-audit-log/reviews/)

## 貢献者

 *   [ Naowas Morshed Eimon ](https://profiles.wordpress.org/naowas/)

## サポート

意見や質問がありますか ?

 [サポートフォーラムを表示](https://wordpress.org/support/plugin/tracevault-audit-log/)