{"id":339286,"date":"2026-07-18T05:18:12","date_gmt":"2026-07-18T05:18:12","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/itx-userops\/"},"modified":"2026-08-09T10:41:36","modified_gmt":"2026-08-09T10:41:36","slug":"itx-userops","status":"publish","type":"plugin","link":"https:\/\/vec.wordpress.org\/plugins\/itx-userops\/","author":454108,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.9.1","stable_tag":"1.9.1","tested":"7.0.4","requires":"6.0","requires_php":"7.4","requires_plugins":null,"header_name":"ITX UserOps","header_author":"ITECHTICS","header_description":"User management, login activity, sessions & audit log \u2014 one unified admin console for WordPress users.","assets_banners_color":"c8d3e9","last_updated":"2026-08-09 10:41:36","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/itxuserops.com","header_author_uri":"https:\/\/www.itechtics.org","rating":5,"author_block_rating":0,"active_installs":10,"downloads":168,"num_ratings":1,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"nanosani","date":"2026-07-18 05:45:04"},"1.9.1":{"tag":"1.9.1","author":"nanosani","date":"2026-08-09 10:41:36"}},"upgrade_notice":{"1.9.1":"<p>First update since 1.0.0. Adds the Roles editor and the Email Log, proxy-aware IP detection, a tamper-evident activity log, and many fixes. Database upgrades run automatically and are additive \u2014 nothing existing is touched.<\/p>"},"ratings":{"1":0,"2":0,"3":0,"4":0,"5":1},"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3639231,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128}},"assets_banners":{"banner-772x250.png":{"filename":"banner-772x250.png","revision":3639231,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0","1.9.1"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3639231,"resolution":"1","location":"assets","locale":"","width":3692,"height":1903},"screenshot-10.png":{"filename":"screenshot-10.png","revision":3639234,"resolution":"10","location":"assets","locale":"","width":3700,"height":5954},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3639231,"resolution":"2","location":"assets","locale":"","width":3729,"height":1910},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3639231,"resolution":"3","location":"assets","locale":"","width":3734,"height":1885},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3639231,"resolution":"4","location":"assets","locale":"","width":3728,"height":1901},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3639231,"resolution":"5","location":"assets","locale":"","width":3725,"height":1895},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3639234,"resolution":"6","location":"assets","locale":"","width":3731,"height":1902},"screenshot-7.png":{"filename":"screenshot-7.png","revision":3639234,"resolution":"7","location":"assets","locale":"","width":3729,"height":1902},"screenshot-8.png":{"filename":"screenshot-8.png","revision":3639234,"resolution":"8","location":"assets","locale":"","width":3734,"height":1892},"screenshot-9.png":{"filename":"screenshot-9.png","revision":3639234,"resolution":"9","location":"assets","locale":"","width":3734,"height":1911}},"screenshots":{"1":"User dashboard \u2014 who is online, logins, security alerts, role breakdown and recent activity in one view","2":"Per-user profile drawer with sessions, devices, activity and one-click account actions","3":"Login log \u2014 successes, failures, blocked attempts and logouts charted over 14 days","4":"Failed-login detail with IP address, user agent and aggregated attack counts","5":"Activity log with per-severity charts and filtering by event, severity, IP and date","6":"Activity entry detail \u2014 who changed what, from where, with the full metadata","7":"Email log \u2014 what the site sent and what the mail server said, with per-message detail","8":"Role editor \u2014 areas and levels instead of raw capabilities, with drafts and compare","9":"The raw capability list, one click away and always in step with the grid","10":"Settings \u2014 staff detection, log retention, email logging, IP detection and privacy controls"}},"plugin_section":[262246],"plugin_tags":[8534,22959,66964,2461,212032],"plugin_category":[],"plugin_contributors":[272138],"plugin_business_model":[],"class_list":["post-339286","plugin","type-plugin","status-publish","hentry","plugin_section-dashboard-widgets","plugin_tags-audit-log","plugin_tags-disable-users","plugin_tags-login-activity","plugin_tags-user-management","plugin_tags-user-sessions","plugin_contributors-nanosani","plugin_committers-nanosani"],"banners":{"banner":"https:\/\/ps.w.org\/itx-userops\/assets\/banner-772x250.png?rev=3639231","banner_2x":false,"banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/itx-userops\/assets\/icon-128x128.png?rev=3639231","icon_2x":false,"generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/itx-userops\/assets\/screenshot-1.png?rev=3639231","caption":"User dashboard \u2014 who is online, logins, security alerts, role breakdown and recent activity in one view"},{"src":"https:\/\/ps.w.org\/itx-userops\/assets\/screenshot-2.png?rev=3639231","caption":"Per-user profile drawer with sessions, devices, activity and one-click account actions"},{"src":"https:\/\/ps.w.org\/itx-userops\/assets\/screenshot-3.png?rev=3639231","caption":"Login log \u2014 successes, failures, blocked attempts and logouts charted over 14 days"},{"src":"https:\/\/ps.w.org\/itx-userops\/assets\/screenshot-4.png?rev=3639231","caption":"Failed-login detail with IP address, user agent and aggregated attack counts"},{"src":"https:\/\/ps.w.org\/itx-userops\/assets\/screenshot-5.png?rev=3639231","caption":"Activity log with per-severity charts and filtering by event, severity, IP and date"},{"src":"https:\/\/ps.w.org\/itx-userops\/assets\/screenshot-6.png?rev=3639234","caption":"Activity entry detail \u2014 who changed what, from where, with the full metadata"},{"src":"https:\/\/ps.w.org\/itx-userops\/assets\/screenshot-7.png?rev=3639234","caption":"Email log \u2014 what the site sent and what the mail server said, with per-message detail"},{"src":"https:\/\/ps.w.org\/itx-userops\/assets\/screenshot-8.png?rev=3639234","caption":"Role editor \u2014 areas and levels instead of raw capabilities, with drafts and compare"},{"src":"https:\/\/ps.w.org\/itx-userops\/assets\/screenshot-9.png?rev=3639234","caption":"The raw capability list, one click away and always in step with the grid"},{"src":"https:\/\/ps.w.org\/itx-userops\/assets\/screenshot-10.png?rev=3639234","caption":"Settings \u2014 staff detection, log retention, email logging, IP detection and privacy controls"}],"raw_content":"<!--section=description-->\n<p>WordPress has no unified user administration console. To see who is online, keep a login audit trail, force-logout a compromised account, disable a departed contractor without deleting their content, find out whether the password reset actually went out, or edit a role without deciphering sixty capability checkboxes, you normally need five or six single-purpose plugins.<\/p>\n\n<p><strong>ITX UserOps replaces that whole stack with one fast, cohesive console<\/strong> \u2014 the kind of user administration Microsoft 365 or Google Workspace admins get out of the box.<\/p>\n\n<p><a href=\"https:\/\/itxuserops.com\/\">Website<\/a> | <a href=\"https:\/\/itxuserops.com\/docs\/getting-started\/\">Documentation<\/a> | <a href=\"https:\/\/itxuserops.com\/features\/\">All features<\/a> | <a href=\"https:\/\/itxuserops.com\/changelog\/\">Changelog<\/a> | <a href=\"https:\/\/itxuserops.com\/support\/\">Support<\/a><\/p>\n\n<h4>Unified user dashboard<\/h4>\n\n<ul>\n<li>Every user in one table: online-now indicator, last login, last activity, active sessions, role, status, registered date, post count<\/li>\n<li>Server-side search, sorting and pagination \u2014 stays fast at 100,000+ users<\/li>\n<li>Quick filters that combine: role, status, online now, last login (today \/ 7 \/ 30 \/ 90 days \/ never), registered date range, inactive 30\/60\/90 days<\/li>\n<li>Overview tiles \u2014 online now, logins today, failed logins, disabled accounts, security alerts \u2014 each clickable, drilling into the matching filtered view<\/li>\n<li>Toggleable columns, per-admin<\/li>\n<\/ul>\n\n<p><a href=\"https:\/\/itxuserops.com\/docs\/console\/dashboard\/\">Dashboard documentation \u2192<\/a><\/p>\n\n<h4>Disable users without deleting them<\/h4>\n\n<ul>\n<li>One click disables an account: the user can no longer log in <strong>on any channel<\/strong> \u2014 wp-login, XML-RPC, REST, application passwords \u2014 and every active session is destroyed instantly<\/li>\n<li>Content, comments and history stay intact<\/li>\n<li>Customizable \"account disabled\" message<\/li>\n<li>Safety rails: you can never disable yourself or the last administrator<\/li>\n<\/ul>\n\n<p><a href=\"https:\/\/itxuserops.com\/docs\/console\/account-status\/\">Account status documentation \u2192<\/a><\/p>\n\n<h4>Session management<\/h4>\n\n<ul>\n<li>See every active session per user: browser, OS, device, IP, signed-in time, last activity<\/li>\n<li>Terminate any single session, log a user out everywhere, or log <strong>all<\/strong> users out (your own session survives)<\/li>\n<\/ul>\n\n<p><a href=\"https:\/\/itxuserops.com\/docs\/console\/sessions\/\">Sessions documentation \u2192<\/a><\/p>\n\n<h4>Login &amp; user audit log<\/h4>\n\n<ul>\n<li>Dedicated Login Log: every sign-in attempt \u2014 success, failed or blocked \u2014 with user, IP, device, user agent, and which door it came through (login form, XML-RPC, REST API or WP-CLI)<\/li>\n<li>Records logins, failed logins (with attempted username), logouts, blocked logins, registrations, deletions, role changes, password changes\/resets, email and profile changes, application passwords, and bulk actions<\/li>\n<li>Site visibility: content published\/updated\/trashed\/deleted (with author and actor), plugin activations\/deactivations, theme switches and WordPress core updates<\/li>\n<li><strong>Tamper-evident<\/strong>: each entry is chained to the one before it, so database-level tampering \u2014 an edited dump, SQL injection, a rogue database user \u2014 is detectable<\/li>\n<li>Filter by event, user, actor, IP, severity and date; full-text search; CSV export<\/li>\n<li>Configurable retention (30 days up to keep-forever) with daily auto-purge<\/li>\n<li>Brute-force flood protection: failed-login noise is aggregated, never table-flooding<\/li>\n<\/ul>\n\n<p><a href=\"https:\/\/itxuserops.com\/docs\/console\/activity-log\/\">Activity log documentation \u2192<\/a> \u00b7 <a href=\"https:\/\/itxuserops.com\/docs\/console\/tamper-evidence\/\">How tamper evidence works \u2192<\/a><\/p>\n\n<h4>Email log<\/h4>\n\n<ul>\n<li>Every message WordPress hands to the mail server, recorded at the moment of hand-off: recipient, subject, timing, and what the server said back<\/li>\n<li>Honest states: nothing is labelled \"Delivered\" or \"Sent\", because your site cannot observe either. The good state is <strong>Handed off<\/strong>, failures carry the server's error, and results another plugin merely claimed are shown as reported rather than observed<\/li>\n<li>You choose which kinds of mail are logged \u2014 account mail on by default, high-volume kinds off \u2014 which is what keeps the log small on a busy store<\/li>\n<li>Message contents are <strong>not stored unless you switch it on<\/strong> \u2014 and when you do, password reset links, one-time codes and application passwords are stripped before anything is written, so the log cannot become a way in<\/li>\n<li>Its own retention setting with no \"keep forever\", and one-click deletion of stored message contents<\/li>\n<\/ul>\n\n<p><a href=\"https:\/\/itxuserops.com\/docs\/console\/email-log\/\">Email log documentation \u2192<\/a><\/p>\n\n<h4>Role editor<\/h4>\n\n<ul>\n<li>WordPress permissions as a grid of <strong>areas<\/strong> (Posts, Pages, Media, Comments, Users, Site settings, Plugins &amp; themes) against <strong>levels<\/strong> (None, View, Contribute, Manage) \u2014 instead of sixty raw checkboxes. Custom post types get their own row automatically<\/li>\n<li>Draft-first: every edit collects into a draft and nothing touches the live role until you press Publish<\/li>\n<li>A Plain English view of the role as toggleable statements, side-by-side role comparison, and people management \u2014 add someone to a role, move people out, reassign between roles<\/li>\n<li>Capabilities the grid does not manage are never touched, and a role the grid cannot describe shows the exact difference instead of quietly rewriting it on save<\/li>\n<li>\"Restore WordPress defaults\" puts the five built-in roles back exactly as WordPress ships them<\/li>\n<li>Guardrails enforced on the server, not merely hidden in the screen: you cannot grant access you do not hold, change your own role, or demote the last administrator<\/li>\n<\/ul>\n\n<p><a href=\"https:\/\/itxuserops.com\/docs\/console\/roles\/\">Roles documentation \u2192<\/a><\/p>\n\n<h4>Per-user profile drawer<\/h4>\n\n<ul>\n<li>Click any user for an Entra-ID-style panel: overview with 30-day login sparkline, live session list, that user's complete activity trail, and the mail sent to them \u2014 without leaving the page<\/li>\n<\/ul>\n\n<p><a href=\"https:\/\/itxuserops.com\/docs\/console\/profile-drawer\/\">Profile drawer documentation \u2192<\/a><\/p>\n\n<h4>Bulk actions<\/h4>\n\n<ul>\n<li>Multi-select users \u2192 change role, disable, enable, log out, send password reset, delete with content reassignment, export to CSV<\/li>\n<li>Runs in batches with a progress bar \u2014 no timeouts on large sites<\/li>\n<\/ul>\n\n<p><a href=\"https:\/\/itxuserops.com\/docs\/console\/bulk-actions\/\">Bulk actions documentation \u2192<\/a><\/p>\n\n<h4>Works behind Cloudflare and reverse proxies<\/h4>\n\n<ul>\n<li>Behind a CDN, load balancer or reverse proxy, logs normally record the proxy's address instead of the visitor's. Name your proxy (Cloudflare's ranges are built in) and the real client IP is recorded instead<\/li>\n<li>Forwarding headers are only trusted when the request genuinely arrives from a configured range, so they cannot be forged<\/li>\n<\/ul>\n\n<p><a href=\"https:\/\/itxuserops.com\/docs\/console\/proxies\/\">Client IP documentation \u2192<\/a><\/p>\n\n<h4>Privacy and GDPR<\/h4>\n\n<ul>\n<li>GDPR mode zeroes the last part of every captured IP before it is stored<\/li>\n<li>Log retention is capped and auto-purged; email bodies are opt-in and redacted<\/li>\n<li>Uninstalling can remove every trace of plugin data \u2014 your choice, off by default<\/li>\n<\/ul>\n\n<p><a href=\"https:\/\/itxuserops.com\/docs\/reference\/privacy\/\">Privacy documentation \u2192<\/a><\/p>\n\n<h4>Extras<\/h4>\n\n<ul>\n<li>Live \"online users\" count in the admin bar and a user-overview dashboard widget<\/li>\n<li>Online status and a UserOps details link right in the native Users screen<\/li>\n<li>Works on multisite \u2014 each subsite gets its own console (<a href=\"https:\/\/itxuserops.com\/docs\/console\/multisite\/\">multisite notes \u2192<\/a>)<\/li>\n<\/ul>\n\n<h4>Performance<\/h4>\n\n<p>Built to a strict budget: front-end requests incur at most one throttled database write per user per minute \u2014 no admin-ajax polling, no autoloaded bloat. Logs live in their own indexed tables, never in wp_options. The plugin makes no external HTTP requests and loads no remote assets.<\/p>\n\n<p><a href=\"https:\/\/itxuserops.com\/docs\/reference\/performance\/\">Performance notes \u2192<\/a><\/p>\n\n<h4>Free, and complete<\/h4>\n\n<p>Everything described above is free, fully functional, and stays that way. A separate premium edition exists for security teams \u2014 two-factor enforcement, passkeys, security alerts, temporary accounts, delegation and more \u2014 described at <a href=\"https:\/\/itxuserops.com\/pricing\/\">itxuserops.com\/pricing<\/a>. Nothing on this page requires it.<\/p>\n\n<h3>Development<\/h3>\n\n<p>The admin interface is a React app built with @wordpress\/scripts. The\nhuman-readable source lives in <code>assets\/src\/<\/code>; the compiled bundle in\n    assets\/build\/ is generated with:<\/p>\n\n<pre><code>npm install &amp;&amp; npm run build\n<\/code><\/pre>\n\n<p>No third-party JavaScript libraries are bundled \u2014 the app uses the\n@wordpress\/* packages that ship with WordPress core. The plugin makes no\nexternal HTTP requests and loads no remote assets.<\/p>\n\n<!--section=installation-->\n<h4>Minimum requirements<\/h4>\n\n<ul>\n<li>WordPress 6.0 or newer<\/li>\n<li>PHP 7.4 or newer<\/li>\n<li>Works on single sites and multisite networks<\/li>\n<\/ul>\n\n<p><a href=\"https:\/\/itxuserops.com\/docs\/getting-started\/requirements\/\">Requirements in detail \u2192<\/a><\/p>\n\n<h4>Installing from your WordPress dashboard (recommended)<\/h4>\n\n<ol>\n<li>Sign in to your WordPress admin and go to <strong>Plugins \u2192 Add New Plugin<\/strong><\/li>\n<li>Search for <strong>ITX UserOps<\/strong><\/li>\n<li>Click <strong>Install Now<\/strong>, then <strong>Activate<\/strong><\/li>\n<\/ol>\n\n<h4>Installing by upload<\/h4>\n\n<ol>\n<li>Download the plugin zip from this page<\/li>\n<li>In your WordPress admin, go to <strong>Plugins \u2192 Add New Plugin \u2192 Upload Plugin<\/strong><\/li>\n<li>Choose the zip, click <strong>Install Now<\/strong>, then <strong>Activate<\/strong><\/li>\n<\/ol>\n\n<p>Or unzip it into <code>wp-content\/plugins\/<\/code> over SFTP and activate from the Plugins screen.<\/p>\n\n<p><a href=\"https:\/\/itxuserops.com\/docs\/getting-started\/install\/\">Installation guide \u2192<\/a><\/p>\n\n<h4>After activation<\/h4>\n\n<p>Activation changes nothing on your site: no role is edited, no email is sent, no existing data is touched. The console appears as <strong>ITX UserOps<\/strong> in the admin menu \u2014 open the Dashboard and your users, sessions and logs are already there; recording starts from the moment the plugin is active.<\/p>\n\n<p>A guided tour of what to look at first \u2014 the dashboard, the login log, retention settings, and proxy configuration if you are behind Cloudflare \u2014 is in <a href=\"https:\/\/itxuserops.com\/docs\/getting-started\/first-hour\/\">Your first hour \u2192<\/a><\/p>\n\n<h4>Updating<\/h4>\n\n<p>Update from the Plugins screen like any other plugin. Database schema upgrades run automatically and every step is additive \u2014 existing log entries stay readable.<\/p>\n\n<h4>Uninstalling<\/h4>\n\n<p>Deactivating stops all recording and clears the plugin's scheduled tasks. Uninstalling keeps your data by default; if you want a complete removal, enable <strong>Delete all plugin data on uninstall<\/strong> in ITX UserOps \u2192 Settings first, and uninstalling then removes every table, option and user-meta entry the plugin ever created.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"how%20do%20i%20disable%20a%20wordpress%20user%20without%20deleting%20them%3F\"><h3>How do I disable a WordPress user without deleting them?<\/h3><\/dt>\n<dd><p>Open ITX UserOps \u2192 Dashboard, find the user, and choose \"Disable account\" from the row menu. They immediately lose access on every login channel while their content and history remain untouched. Re-enable them any time.<\/p><\/dd>\n<dt id=\"how%20do%20i%20log%20out%20all%20wordpress%20users%20at%20once%3F\"><h3>How do I log out all WordPress users at once?<\/h3><\/dt>\n<dd><p>ITX UserOps \u2192 Dashboard \u2192 \"Log out all users\". Every session on the site is destroyed except your current one.<\/p><\/dd>\n<dt id=\"how%20can%20i%20see%20who%20is%20currently%20online%3F\"><h3>How can I see who is currently online?<\/h3><\/dt>\n<dd><p>The dashboard's \"Online\" column shows a live indicator for every user with activity in the last 5 minutes, and the \"Online now\" filter lists exactly who is connected.<\/p><\/dd>\n<dt id=\"does%20it%20slow%20down%20my%20site%3F\"><h3>Does it slow down my site?<\/h3><\/dt>\n<dd><p>No. Visitors trigger zero extra queries. Logged-in users trigger at most one tiny indexed write per minute. All heavy lifting happens only on the plugin's own admin pages.<\/p><\/dd>\n<dt id=\"is%20it%20gdpr%20friendly%3F\"><h3>Is it GDPR friendly?<\/h3><\/dt>\n<dd><p>Yes. Enable \"Anonymize IP addresses\" and the last octet of every captured IP is zeroed before storage. Log retention is capped and auto-purged, and uninstalling can remove every trace of plugin data.<\/p><\/dd>\n<dt id=\"does%20it%20work%20on%20multisite%3F\"><h3>Does it work on multisite?<\/h3><\/dt>\n<dd><p>Yes \u2014 each subsite gets its own dashboard, log and settings. Subsite admins cannot disable super admins.<\/p><\/dd>\n<dt id=\"where%20is%20the%20audit%20log%20stored%3F\"><h3>Where is the audit log stored?<\/h3><\/dt>\n<dd><p>In its own indexed database table \u2014 not in wp_options or postmeta \u2014 so a busy log never slows down the rest of your site.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.9.1<\/h4>\n\n<p>The first update on WordPress.org since 1.0.0, condensing the development releases in between. What is new compared to 1.0.0:<\/p>\n\n<ul>\n<li>New: Roles. WordPress permissions described the way people think about them \u2014 a grid of areas (Posts, Pages, Media, Comments, Users, Site settings, Plugins &amp; themes) against levels (None, View, Contribute, Manage) instead of sixty raw checkboxes. Custom post types get their own row automatically.<\/li>\n<li>Roles is draft-first: every edit collects into a draft, a bar counts the changes, and nothing touches the live role until you press Publish. Leaving with a draft open prompts you like any unsaved form.<\/li>\n<li>Alongside the grid: a Plain English view of the role as toggleable statements, side-by-side role comparison with differences highlighted, people management (add someone to a role, move people out, reassign between roles), create\/duplicate\/rename\/delete, and \"Restore WordPress defaults\" for the five built-in roles.<\/li>\n<li>Capabilities the grid does not manage are never touched \u2014 if WooCommerce or a membership plugin added something to a role, saving leaves it byte-for-byte. A role the grid cannot describe reads \"Custom\" and shows the exact difference instead of quietly rewriting it on save.<\/li>\n<li>Role guardrails are enforced on the server, not merely hidden in the screen: you cannot grant access you do not hold yourself, change your own role, or demote the last administrator. The administrator role is visible but not editable. Activation changes nothing until you choose to change it.<\/li>\n<li>New: an Email Log. Every message WordPress hands to the mail server is recorded \u2014 recipient, subject, timing, and what the server said back. Nothing is labelled \"Delivered\" or \"Sent\", because your site cannot observe either: the good state is \"Handed off\", failures carry the server's error, and results another plugin merely claimed are shown as reported rather than observed.<\/li>\n<li>You choose which kinds of mail are logged; account mail and the plugin's own mail are on by default, high-volume kinds are off. Message contents are not stored unless you switch it on \u2014 and when you do, password reset links, one-time codes and application passwords are stripped before anything is written, so the log cannot become a way in. Stored contents can be deleted again in one click.<\/li>\n<li>New: client IP detection behind Cloudflare, a load balancer or another reverse proxy (Cloudflare's ranges are built in). Forwarding headers are only trusted when the request genuinely arrives from a configured range, so they cannot be forged.<\/li>\n<li>New: the activity log is tamper-evident. Each entry is chained to the one before it, so database-level tampering \u2014 an edited dump, SQL injection, a rogue database user \u2014 is detectable, and legitimate retention deletion records itself so it is never mistaken for interference.<\/li>\n<li>New: the activity log records which door a sign-in attempt came through \u2014 the login form, XML-RPC, the REST API or WP-CLI \u2014 shown as \"Signed in via\" in the event details.<\/li>\n<li>New: each user's profile panel gains an Emails tab beside Overview, Sessions and Activity; log rows on every screen open a keyboard-accessible side panel; every dashboard overview tile drills into its matching filtered view.<\/li>\n<li>Fixed: repeat login lockouts now double in length as intended \u2014 the record the escalation counted from was being deleted the moment a lock expired, so an attacker could simply wait out the shortest lockout and go again.<\/li>\n<li>Fixed: changing roles from the bulk actions bar, which failed on every site, and bulk-action failures that closed the toolbar without saying why.<\/li>\n<li>Performance: the online-users counter, dashboard counts and activity-log totals are cached instead of recomputed on every admin page load, session cleanup and IP searches are indexed, and the dashboard no longer counts every user account per visit.<\/li>\n<li>Database schema upgrades from version 1 to 6 run automatically on update; every step is additive and existing entries stay readable.<\/li>\n<\/ul>\n\n<p>The full release-by-release history is at https:\/\/itxuserops.com\/changelog\/<\/p>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release: unified user dashboard, enable\/disable accounts, device-grouped session management, activity &amp; login audit log, profile drawer, bulk actions with CSV export, admin-bar online counter, user-overview dashboard widget, and native Users-screen integration.<\/li>\n<\/ul>","raw_excerpt":"One admin console for your WordPress users: online status, login activity, sessions, disable accounts, audit log and bulk actions.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/vec.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/339286","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/vec.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/vec.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/vec.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=339286"}],"author":[{"embeddable":true,"href":"https:\/\/vec.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/nanosani"}],"wp:attachment":[{"href":"https:\/\/vec.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=339286"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/vec.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=339286"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/vec.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=339286"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/vec.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=339286"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/vec.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=339286"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/vec.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=339286"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}