{"id":356269,"date":"2026-08-24T22:07:18","date_gmt":"2026-08-24T22:07:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/presszeug-forensics\/"},"modified":"2026-08-24T22:06:41","modified_gmt":"2026-08-24T22:06:41","slug":"presszeug-forensics","status":"publish","type":"plugin","link":"https:\/\/fur.wordpress.org\/plugins\/presszeug-forensics\/","author":23551186,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.0","stable_tag":"1.0.0","tested":"7.1","requires":"6.2","requires_php":"7.4","requires_plugins":null,"header_name":"PRESSZEUG Forensics","header_author":"PRESSZEUG","header_description":"WordPress forensics and audit logging: see what changed, when it changed, and who changed it.","assets_banners_color":"0c151b","last_updated":"2026-08-24 22:06:41","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/presszeug.com\/forensics","header_author_uri":"https:\/\/presszeug.com","rating":0,"author_block_rating":0,"active_installs":0,"downloads":32,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"joedoll","date":"2026-08-24 22:06:41"}},"upgrade_notice":{"1.0.0":"<p>First public release.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3664327,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3664327,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3664327,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3664327,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3664327,"resolution":"1","location":"assets","locale":"","width":1448,"height":1086},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3664327,"resolution":"2","location":"assets","locale":"","width":1448,"height":1086},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3664327,"resolution":"3","location":"assets","locale":"","width":1448,"height":1086},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3664327,"resolution":"4","location":"assets","locale":"","width":1448,"height":1086},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3664327,"resolution":"5","location":"assets","locale":"","width":1448,"height":1086},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3664327,"resolution":"6","location":"assets","locale":"","width":1448,"height":1086}},"screenshots":{"1":"Overview dashboard with live and retrospective forensics, recent events, and monitored areas.","2":"Activity log with human-readable WordPress change events and before\/after context.","3":"Retrospective revision analysis for changes that existed before PRESSZEUG Forensics was installed.","4":"Evidence view for comparing revision details and preparing HTML or CSV exports.","5":"Integrations view showing WordPress Core and detected optional Deep Integrations such as Elementor.","6":"Settings for retention, appearance, diagnostics, and other PRESSZEUG Forensics preferences."}},"plugin_section":[],"plugin_tags":[8531,8534,76538,271118,6243],"plugin_category":[],"plugin_contributors":[277325],"plugin_business_model":[],"class_list":["post-356269","plugin","type-plugin","status-publish","hentry","plugin_tags-activity-log","plugin_tags-audit-log","plugin_tags-elementor","plugin_tags-forensics","plugin_tags-revisions","plugin_contributors-joedoll","plugin_committers-joedoll"],"banners":{"banner":"https:\/\/ps.w.org\/presszeug-forensics\/assets\/banner-772x250.png?rev=3664327","banner_2x":"https:\/\/ps.w.org\/presszeug-forensics\/assets\/banner-1544x500.png?rev=3664327","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/presszeug-forensics\/assets\/icon-128x128.png?rev=3664327","icon_2x":"https:\/\/ps.w.org\/presszeug-forensics\/assets\/icon-256x256.png?rev=3664327","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/presszeug-forensics\/assets\/screenshot-1.png?rev=3664327","caption":"Overview dashboard with live and retrospective forensics, recent events, and monitored areas."},{"src":"https:\/\/ps.w.org\/presszeug-forensics\/assets\/screenshot-2.png?rev=3664327","caption":"Activity log with human-readable WordPress change events and before\/after context."},{"src":"https:\/\/ps.w.org\/presszeug-forensics\/assets\/screenshot-3.png?rev=3664327","caption":"Retrospective revision analysis for changes that existed before PRESSZEUG Forensics was installed."},{"src":"https:\/\/ps.w.org\/presszeug-forensics\/assets\/screenshot-4.png?rev=3664327","caption":"Evidence view for comparing revision details and preparing HTML or CSV exports."},{"src":"https:\/\/ps.w.org\/presszeug-forensics\/assets\/screenshot-5.png?rev=3664327","caption":"Integrations view showing WordPress Core and detected optional Deep Integrations such as Elementor."},{"src":"https:\/\/ps.w.org\/presszeug-forensics\/assets\/screenshot-6.png?rev=3664327","caption":"Settings for retention, appearance, diagnostics, and other PRESSZEUG Forensics preferences."}],"raw_content":"<!--section=description-->\n<p>PRESSZEUG Forensics helps administrators understand what changed in WordPress, when it changed, and which WordPress account was associated with the event.<\/p>\n\n<p>It combines a live audit log with retrospective evidence from data WordPress already stores. The focus is on meaningful changes rather than ordinary admin navigation.<\/p>\n\n<h4>WordPress Core auditing<\/h4>\n\n<p>PRESSZEUG Forensics can record and investigate changes involving:<\/p>\n\n<ul>\n<li>Pages, posts, comments, and taxonomies.<\/li>\n<li>Users, roles, successful logins, logouts, and optional failed-login events.<\/li>\n<li>Plugin and theme activation, deactivation, deletion, installation, and updates.<\/li>\n<li>Relevant WordPress settings and revision evidence.<\/li>\n<li>Compact before\/after information for supported content changes.<\/li>\n<li>A live presence view that separates recent authenticated activity from merely valid WordPress sessions.<\/li>\n<li>HTML and CSV evidence exports for selected time windows.<\/li>\n<li>Optional read-only local file timestamp analysis as an additional retrospective indicator.<\/li>\n<\/ul>\n\n<h4>Elementor deep integration<\/h4>\n\n<p>Elementor is the first optional Deep Integration and is shown only when Elementor is detected.<\/p>\n\n<p>When available, PRESSZEUG Forensics can add field-level information about Elementor content, structure, and visual settings such as typography, colors, spacing, borders, dimensions, and responsive values. Stored Elementor revisions can also be compared retrospectively.<\/p>\n\n<p>Elementor is not required. WordPress Core auditing continues to work when no supported editor integration is active.<\/p>\n\n<h4>Live and retrospective forensics<\/h4>\n\n<p>The live audit log records supported events from the moment PRESSZEUG Forensics is active.<\/p>\n\n<p>Retrospective analysis is different: it examines evidence WordPress or a supported editor already stored, such as revisions, metadata, update information, and selected file timestamps. It cannot recreate actions for which no evidence exists.<\/p>\n\n<p>File modification and inode-change times are indicators only. Restores, migrations, manual uploads, server work, and updates can create similar timestamp patterns.<\/p>\n\n<h4>Privacy and data handling<\/h4>\n\n<ul>\n<li>No cloud account is required.<\/li>\n<li>Core forensic functionality does not send audit data to PRESSZEUG or another remote service.<\/li>\n<li>The live presence view does not store IP addresses.<\/li>\n<li>Passwords, submitted form contents, and complete Elementor document JSON are not stored in the audit table.<\/li>\n<li>Large values can be represented by size and SHA-256 fingerprints instead of full contents.<\/li>\n<li>CSV exports neutralize common spreadsheet-formula prefixes.<\/li>\n<li>Audit data is intentionally preserved on uninstall so forensic evidence is not destroyed accidentally.<\/li>\n<\/ul>\n\n<p>Access follows WordPress permissions. Administrators and other users granted the corresponding administration capability can open PRESSZEUG Forensics.<\/p>\n\n<h3>Support<\/h3>\n\n<p>The built-in Help tab contains explanations for common forensic questions and a privacy-safe system-information summary for support requests.<\/p>\n\n<p>For public support after the plugin is listed, use the PRESSZEUG Forensics support forum on WordPress.org. Product documentation and PRESSZEUG support links are also available from the plugin interface.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Install PRESSZEUG Forensics from the WordPress Plugin Directory, or upload the plugin ZIP from Plugins &gt; Add Plugin &gt; Upload Plugin.<\/li>\n<li>Activate the plugin.<\/li>\n<li>Open PRESSZEUG Forensics in the WordPress admin menu.<\/li>\n<li>Use Activity for events recorded from activation onward.<\/li>\n<li>Use Retrospective to inspect evidence already stored by WordPress and detected Deep Integrations.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20presszeug%20forensics%20require%20elementor%3F\"><h3>Does PRESSZEUG Forensics require Elementor?<\/h3><\/dt>\n<dd><p>No. WordPress Core auditing works independently. Elementor-specific analysis appears only when Elementor is detected.<\/p><\/dd>\n<dt id=\"can%20it%20tell%20me%20everything%20that%20happened%20before%20installation%3F\"><h3>Can it tell me everything that happened before installation?<\/h3><\/dt>\n<dd><p>No. It can analyze evidence that already exists, such as WordPress\/Elementor revisions and selected local file\/update traces. It cannot recreate events for which no evidence was stored.<\/p><\/dd>\n<dt id=\"does%20it%20send%20audit%20data%20to%20presszeug%20or%20another%20cloud%20service%3F\"><h3>Does it send audit data to PRESSZEUG or another cloud service?<\/h3><\/dt>\n<dd><p>No. Core forensic functionality works locally in the WordPress installation and does not require a cloud account.<\/p><\/dd>\n<dt id=\"does%20%E2%80%9Conline%20now%E2%80%9D%20prove%20that%20a%20person%20is%20currently%20at%20the%20computer%3F\"><h3>Does \u201cOnline Now\u201d prove that a person is currently at the computer?<\/h3><\/dt>\n<dd><p>No. Recent authenticated activity and WordPress session validity are displayed separately. A valid WordPress session can remain active after a browser is closed.<\/p><\/dd>\n<dt id=\"what%20happens%20to%20audit%20data%20when%20i%20uninstall%20the%20plugin%3F\"><h3>What happens to audit data when I uninstall the plugin?<\/h3><\/dt>\n<dd><p>It is preserved by default so forensic evidence is not destroyed accidentally. Back up evidence you need before deliberately removing stored PRESSZEUG data.<\/p><\/dd>\n<dt id=\"can%20presszeug%20prove%20which%20natural%20person%20used%20a%20wordpress%20account%3F\"><h3>Can PRESSZEUG prove which natural person used a WordPress account?<\/h3><\/dt>\n<dd><p>No. PRESSZEUG records the WordPress account associated with an event. If people share an account, the account alone does not prove which natural person performed the action.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>First public release of PRESSZEUG Forensics.<\/li>\n<li>Live WordPress audit logging for meaningful content, user\/access, plugin\/theme, update, and settings events.<\/li>\n<li>Retrospective WordPress revision analysis and evidence-oriented local update\/file indicators.<\/li>\n<li>Optional Elementor Deep Integration with content, structure, and field-level style comparisons.<\/li>\n<li>Human-readable before\/after details with technical diagnostics separated from the normal activity view.<\/li>\n<li>Live presence view distinguishing recent activity from valid WordPress sessions.<\/li>\n<li>HTML and CSV evidence exports for selected time windows.<\/li>\n<li>Per-user Auto, Light, and Dark appearance for PRESSZEUG Forensics only.<\/li>\n<li>Built-in onboarding, Help &amp; Support, privacy-policy guidance, and privacy-safe system information.<\/li>\n<li>WordPress.org Plugin Check release hardening completed for the tested release candidate.<\/li>\n<\/ul>","raw_excerpt":"Track meaningful WordPress changes, compare revisions, investigate incidents, and inspect deep Elementor content and style changes.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/fur.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/356269","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fur.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/fur.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/fur.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=356269"}],"author":[{"embeddable":true,"href":"https:\/\/fur.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/joedoll"}],"wp:attachment":[{"href":"https:\/\/fur.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=356269"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/fur.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=356269"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/fur.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=356269"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/fur.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=356269"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/fur.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=356269"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/fur.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=356269"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}