IRONCREED Request Log Wordpress Plugin - Rating, Reviews, Demo & Download
Plugin Description
IRONCREED Request Log offers two opt-in, clearly separated sources.
- WordPress Runtime records requests that load WordPress. It cannot see traffic completed by a CDN, WAF, web server, full-page cache, static handler, or any layer before WordPress.
- Hosting Ukraine API retrieves today’s nginx access-log archive manually or on an explicitly enabled schedule. It shows only records and coverage returned by the provider API.
This is intentionally a visibility-boundary diagnostic rather than a generic arbitrary-file log viewer. It keeps application-observed WordPress requests separate from provider-supplied nginx records, so operators can see what each layer can and cannot observe without a local-file reader, telemetry, or a general analytics stack.
Both sources start disabled. Records use bounded retention and count limits. Sensitive query values are redacted. Runtime records omit IP addresses, User-Agent, Referer, bodies, cookies, and authorization data. Hosting Ukraine records may include IP addresses, URI identifiers, User-Agent, and Referer and must be covered by the site’s privacy notice and lawful basis.
The plugin has no telemetry, advertising, export, live tail, public endpoint, alternate updater, or local-file reader. It never sends fetched logs to IRONCREED or another service.
Development source, tests, build tooling, and release documentation are maintained at IRONCREED/SECURITY.
External services
The optional Hosting Ukraine integration calls https://adm.tools/action/hosting/log/web/nginx/ when an authorized administrator explicitly tests/fetches or separately enables scheduled imports. The read-only site lookup calls https://adm.tools/action/get_services/ with type=host and the Bearer token. It receives the host services available to that token, matches the entered domain locally, and uses the matching service id as host_id; account_id and virtual_domain_id are not used as substitutes. The discovery list is not stored. Test/import requests send the saved Bearer token in the Authorization header and the matched Hosting Ukraine host ID in the request body. The log response is a gzip nginx access-log archive that may contain timestamps, IP addresses, methods, URIs, statuses, response sizes, User-Agent values, and Referer values. Imported records are retained in the local WordPress database. Disconnect deletes credentials, cancels future scheduled imports, and leaves imported records until retention expiry or manual clearing.
Review the API method, general API guide, access-log documentation, Terms of Service, public offer, and Privacy Policy before connecting.
Privacy
Administrators control enablement, access, retention, clearing, disconnect, and uninstall. Default retention is 24 hours with a 10,000-record cap; retention ranges from one hour to 30 days and the cap from 100 to 100,000. The plugin supplies suggested Privacy Policy Guide text. Site owners determine their lawful basis and privacy notice; the plugin does not promise legal compliance.
Screenshots
No screenshots provided

