Privacy and Reference
Logify Event Reference — Every Event It Records
Want to know exactly what Logify can record and how each entry is scored? This is the complete reference of every event Logify writes, grouped by area, with the event ID, action, and severity for each. Use it to work out what a log entry means, to build a filter or alert rule, or to pick a free ID when adding your own event. Events marked PRO require Logify PRO.
How severity works
Every event is scored on a fixed scale so you can filter, alert, and report by importance rather than by listing individual actions. The Activity Logs viewer shows a colour badge for each level, and PRO notifications can target a minimum severity.
| Severity | Level |
|---|---|
| 100 | Info |
| 200 | Notice |
| 300 | Warning |
| 400 | Alert |
| 500 | High |
| 600 | Critical |
| 700 | Emergency |
Most everyday activity — logins, content edits, plugin and theme changes — is recorded at Info (100). Failed logins are High (500), and an aggregated brute-force burst is Emergency (700). Yoast SEO changes that affect how search engines treat a page are recorded above Info.
How event IDs are organised
Each area owns a block of IDs, which is what makes it possible to filter or alert on a whole category without naming every event. The blocks in use:
| Range | Area |
|---|---|
| 1000–1999 | Users and security |
| 2000–2999 | Media |
| 3000–3999 | Comments |
| 4000–4999 | Plugins and plugin file edits |
| 5000–5999 | Themes and theme file edits |
| 6000–6999 | Posts and pages |
| 7000–7999 | Taxonomy terms |
| 8000–8999 | Navigation menus |
| 9000–9999 | Widgets |
| 10000–10999 | WordPress settings |
| 11000–11999 | Advanced Custom Fields PRO |
| 12000–12999 | bbPress PRO |
| 13000–13999 | WooCommerce PRO |
| 14000–14999 | URL Shortify and MemberPress PRO |
| 15000–15999 | Gravity Forms PRO |
| 16000–16999 | Yoast SEO PRO |
| 17000–17999 | MemberPress subscriptions, transactions, and members PRO |
To add your own event, pick an ID from an unused range — see hooks and filters.
Users and security
| ID | Event type | Action | What it means | Severity |
|---|---|---|---|---|
| 1000 | user | login |
A user signed in | Info |
| 1001 | user | logout |
A user signed out | Info |
| 1002 | user | registered |
A new user account was created | Info |
| 1003 | user | delete |
A user account was deleted | Info |
| 1004 | security | login_failed |
A sign-in attempt failed for an existing user | High |
| 1005 | user | updated |
A profile was updated | Info |
| 1006 | user | password_reset |
A password was reset | Info |
| 1007 | security | login_failed_nonexistent |
A sign-in attempt for a username that does not exist | High |
| 1008 | user | role_changed |
A user's role changed | Info |
| 1009 | security | brute_force_detected |
Repeated failed logins from one IP within the detection window | Emergency |
| 1010 | user | session_terminated |
An administrator forced a session to log out PRO | Info |
Logins also record the method used, so a sign-in through Magic Link or a Temporary Login link is labelled as such. See Magic Link tagging and Temporary Login tagging.
Media
| ID | Action | What it means |
|---|---|---|
| 2000 | added |
A file was uploaded |
| 2001 | updated |
An attachment was edited |
| 2002 | deleted |
An attachment was deleted |
Comments
| ID | Action |
|---|---|
| 3000 | created |
| 3001 | updated |
| 3002 | deleted |
| 3003 | spammed |
| 3004 | unspammed |
| 3005 | trashed |
| 3006 | untrashed |
| 3007 | status_changed |
Plugins
| ID | Action | What it means |
|---|---|---|
| 4000 | activated |
A plugin was activated |
| 4001 | deactivated |
A plugin was deactivated |
| 4002 | installed_updated |
A plugin was installed or updated through the updater |
| 4003 | deleted |
A plugin was deleted |
| 4004 | installed |
A plugin was installed |
| 4005 | file_edited |
A plugin file was edited in the built-in editor |
| 4006 | updated |
A plugin was updated |
Themes
| ID | Action | What it means |
|---|---|---|
| 5000 | activated |
A theme was activated |
| 5001 | installed_updated |
A theme was installed or updated through the updater |
| 5002 | deleted |
A theme was deleted |
| 5003 | switched |
The active theme changed |
| 5004 | customized |
A change was saved in the Customizer |
| 5005 | installed |
A theme was installed |
| 5006 | file_edited |
A theme file was edited in the built-in editor |
| 5007 | updated |
A theme was updated |
Posts and pages
| ID | Action | What it means |
|---|---|---|
| 6000 | deleted |
Permanently deleted |
| 6001 | status_changed |
Status changed |
| 6002 | created |
Created |
| 6003 | trashed |
Moved to trash |
| 6004 | restored |
Restored from trash |
| 6005 | published |
Published |
| 6006 | updated |
Updated |
These apply to every public post type, not only posts and pages.
Taxonomy terms, menus, widgets and settings
| ID | Event type | Action |
|---|---|---|
| 7000 | term | created |
| 7001 | term | updated |
| 7002 | term | deleted |
| 8000 | menu | created |
| 8001 | menu | updated |
| 8002 | menu | deleted |
| 9000 | widget | updated |
| 10000 | option | changed |
Option changes cover key WordPress settings such as the site title, tagline, admin email, and default role. Add your own with the kc_lf_tracked_options filter — see hooks and filters.
Advanced Custom Fields PRO
PRO feature
ACF tracking requires Logify PRO.
| ID | Action | What it means |
|---|---|---|
| 11000 | deleted |
A field group was deleted |
| 11001 | deleted |
A post field was deleted |
| 11002 | deleted |
A taxonomy field was deleted |
See how to track ACF deletions.
bbPress PRO
PRO feature
bbPress tracking requires Logify PRO and covers the whole forum, using the 12000–12999 ID block.
- Forums — created, updated, trashed, restored, deleted, and status changed.
- Topics — created, updated, trashed, restored, deleted, opened, closed, stickied, unstickied, marked spam, unspammed, approved, unapproved, moved, merged, and tags changed.
- Replies — created, updated, trashed, restored, deleted, and moved.
Forums, topics, and replies are recorded once as forum activity rather than appearing again as generic post entries. See how to track bbPress activity.
WooCommerce PRO
PRO feature
WooCommerce tracking requires Logify PRO.
| ID | Action | What it means |
|---|---|---|
| 13000 | created |
Product created |
| 13001 | deleted |
Product deleted |
| 13002 | trashed |
Product trashed |
| 13003 | restored |
Product restored |
| 13004 | updated |
Product updated |
| 13010 | created |
Order created |
| 13011 | status_changed |
Order status changed |
| 13012 | item_added |
Item added to an order |
| 13013 | item_removed |
Item removed from an order |
| 13014 | item_quantity_changed |
Order item quantity changed |
| 13015 | refunded |
Order refunded |
| 13016 | refund_deleted |
A refund was deleted |
| 13017 | updated |
Order updated |
| 13020 | created |
Coupon created |
| 13021 | updated |
Coupon updated |
| 13022 | trashed |
Coupon trashed |
| 13023 | restored |
Coupon restored |
| 13024 | deleted |
Coupon deleted |
| 13030 | created |
Customer created |
| 13031 | updated |
Customer updated |
| 13032 | deleted |
Customer deleted |
| 13040 | created |
Product category created |
| 13041 | updated |
Product category updated |
| 13042 | deleted |
Product category deleted |
| 13050 | created |
Product tag created |
| 13051 | updated |
Product tag updated |
| 13052 | deleted |
Product tag deleted |
| 13060 | updated |
WooCommerce settings saved |
See how to track WooCommerce store changes.
URL Shortify PRO
PRO feature
URL Shortify tracking requires Logify PRO.
| ID | Action | What it means |
|---|---|---|
| 14000 | created |
A short link was created |
| 14001 | updated |
A short link was updated |
| 14002 | deleted |
A short link was deleted |
See URL Shortify integration logs.
MemberPress PRO
PRO feature
MemberPress tracking requires Logify PRO. Membership, group, rule, and settings events use the 14000 block; subscriptions, transactions, and members use the 17000 block.
- Memberships, groups, and access rules — created, updated, trashed, restored, and deleted (IDs 14010–14040).
- Subscriptions — created, updated, expired, and deleted (IDs 17000–17003).
- Transactions — created, updated, and deleted (IDs 17010–17012).
- Members — added, signup completed, account updated, and deleted (IDs 17020–17023).
- Settings — MemberPress settings changes (ID 14040).
Memberships, groups, and rules are recorded once as membership activity rather than again as generic post entries. See how to track MemberPress activity.
Gravity Forms PRO
PRO feature
Gravity Forms tracking requires Logify PRO.
| ID | Action | What it means |
|---|---|---|
| 15000 | created |
A form was created or saved |
| 15001 | trashed |
A form was moved to trash |
| 15002 | deleted |
A form was deleted |
| 15003 | duplicated |
A form was duplicated |
| 15004 | imported |
Forms were imported |
| 15005 | activated |
A form was activated |
| 15006 | deactivated |
A form was deactivated |
See how to track Gravity Forms changes.
Yoast SEO PRO
PRO feature
Yoast SEO tracking requires Logify PRO.
| ID | Action | What it means |
|---|---|---|
| 16000 | updated |
A post's Yoast SEO fields changed |
Each save produces a single entry listing every SEO field that changed — title, meta description, focus keyphrase, social and X titles and images, canonical URL, indexing and following, cornerstone content, schema types, and breadcrumb title — with its old and new value. Changes that affect how search engines treat the page are recorded above Info severity. The tracked fields can be adjusted with the kc_lf_yoast_tracked_fields filter. See Yoast SEO activity logs.
Conclusion
This reference maps every event Logify records to its ID, action, and severity, so you can read any log entry and build filters, alerts, and reports against the right values. To act on these events, see how to filter WordPress activity logs; to record your own events or change what is logged, see hooks and filters.
FAQs
What do the severity levels mean?
Logify scores every event from Info (100) up to Emergency (700): Info, Notice, Warning, Alert, High, Critical, and Emergency. Most routine activity is Info. Failed logins are High (500) and an aggregated brute-force burst is Emergency (700). The scale lets you filter the log and target PRO notifications by a minimum severity instead of naming individual events.
Which events are free and which need Logify PRO?
All WordPress core events — users, security, media, comments, plugins, themes, posts, taxonomy, menus, widgets, and settings (IDs 1000–10999) — are free. Integration events for ACF, bbPress, WooCommerce, URL Shortify, MemberPress, Gravity Forms, and Yoast SEO (IDs 11000 and up) require Logify PRO, along with forced session termination.
What is the difference between failed login and brute-force events?
A failed login (ID 1004, or 1007 for a non-existent username) records one unsuccessful sign-in at High severity. When failures from the same IP and username cross the threshold within the detection window, Logify stops recording each attempt and writes a single aggregated brute-force event (ID 1009) at Emergency severity for the rest of the window, keeping the log readable during an attack.
Can I add my own event types to Logify?
Yes. Create an activity class that extends BaseActivity, set its $event_id, $event_type, $action, and $severity, and pick an event ID from an unused range so it does not collide with the blocks listed above. Trackers are auto-discovered by file. See hooks and filters for the full procedure.
Do these events apply to custom post types?
Yes. The post events (IDs 6000–6006 — created, updated, published, trashed, restored, status changed, and deleted) apply to every public post type, not only posts and pages. You can narrow which post types are logged using the Excluded Post Types rule on the Exclusions settings tab.