{"id":359897,"date":"2026-08-31T11:30:18","date_gmt":"2026-08-31T11:30:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/admin-security-auditor\/"},"modified":"2026-08-31T11:30:03","modified_gmt":"2026-08-31T11:30:03","slug":"trolla-last-login-security","status":"publish","type":"plugin","link":"https:\/\/he.wordpress.org\/plugins\/trolla-last-login-security\/","author":23556126,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.0","stable_tag":"1.0.0","tested":"7.1","requires":"6.5","requires_php":"8.0","requires_plugins":null,"header_name":"Trolla Last Login & Security","header_author":"Trolla Last Login & Security Contributors","header_description":"Audit WordPress administrator accounts and identify inactive, recently created, or unmonitored admins.","assets_banners_color":"bfabc8","last_updated":"2026-08-31 11:30:03","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"","rating":0,"author_block_rating":0,"active_installs":0,"downloads":52,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"kirser","date":"2026-08-31 11:30:03","revision":3673993}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3676113,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3676113,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3676113,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3676113,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3676113,"resolution":"1","location":"assets","locale":"","width":1920,"height":1100},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3676113,"resolution":"2","location":"assets","locale":"","width":1920,"height":1100}},"screenshots":{"1":"Administrator security summary with review counts.","2":"Prioritized Administrator table with account creation, Admin Since, last-login, and status information.","3":"Inactive Administrator detail and safe next steps.","4":"Dedicated settings tab for inactivity, recent-account, email, and data-retention settings."}},"plugin_section":[],"plugin_tags":[55390,3897,207601,60860,243374],"plugin_category":[],"plugin_contributors":[278465],"plugin_business_model":[],"class_list":["post-359897","plugin","type-plugin","status-publish","hentry","plugin_tags-admin-security","plugin_tags-administrator","plugin_tags-inactive-users","plugin_tags-last-login","plugin_tags-user-security","plugin_contributors-kirser","plugin_committers-kirser"],"banners":{"banner":"https:\/\/ps.w.org\/trolla-last-login-security\/assets\/banner-772x250.png?rev=3676113","banner_2x":"https:\/\/ps.w.org\/trolla-last-login-security\/assets\/banner-1544x500.png?rev=3676113","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/trolla-last-login-security\/assets\/icon-128x128.png?rev=3676113","icon_2x":"https:\/\/ps.w.org\/trolla-last-login-security\/assets\/icon-256x256.png?rev=3676113","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/trolla-last-login-security\/assets\/screenshot-1.png?rev=3676113","caption":"Administrator security summary with review counts."},{"src":"https:\/\/ps.w.org\/trolla-last-login-security\/assets\/screenshot-2.png?rev=3676113","caption":"Prioritized Administrator table with account creation, Admin Since, last-login, and status information."}],"raw_content":"<!--section=description-->\n<p>WordPress Administrator accounts often accumulate over time. Old developers, agencies, employees, and temporary accounts can remain active for years.<\/p>\n\n<p>Trolla Last Login &amp; Security gives you a focused overview of who currently has Administrator access, when each account was created, and when the account was last observed logging in.<\/p>\n\n<h4>Focused and useful<\/h4>\n\n<ul>\n<li>See every current Administrator in one place.<\/li>\n<li>Identify accounts with a recorded login older than your inactivity threshold.<\/li>\n<li>See recently created Administrator accounts.<\/li>\n<li>See when Administrator access was granted after monitoring began.<\/li>\n<li>Distinguish \"Never logged in\" from historical logins the plugin could not know about.<\/li>\n<li>Receive an optional email when Administrator access is granted.<\/li>\n<li>View locally observed Last Login information on the standard Users screen.<\/li>\n<\/ul>\n\n<p>Trolla Last Login &amp; Security does not delete accounts, change roles, or claim that an account is malicious. It provides factual information so a site owner can make an informed review.<\/p>\n\n<h4>Lightweight and private<\/h4>\n\n<ul>\n<li>No external services or API calls.<\/li>\n<li>No telemetry or analytics.<\/li>\n<li>No IP address, browser, geographic, password, cookie, or authentication-data logging.<\/li>\n<li>No frontend scripts or styles.<\/li>\n<li>No scheduled background jobs.<\/li>\n<\/ul>\n\n<p>Trolla Last Login &amp; Security does not transmit site or user information to external services. Monitoring data is stored locally in your WordPress database.<\/p>\n\n<h4>Login-history accuracy<\/h4>\n\n<p>WordPress does not store a native last-login timestamp. Trolla Last Login &amp; Security starts recording successful logins after the plugin begins monitoring.<\/p>\n\n<p>For an older account without an observed login, the plugin displays \"No login recorded.\" It does not claim the person has never logged in. \"Never logged in\" is only shown when the account itself was created after monitoring began and no login has been observed.<\/p>\n\n<p>WordPress does not store historical role-grant dates. Existing Administrators therefore show \"Before monitoring\" in the Admin Since column. Exact dates are recorded for Administrator access granted while monitoring is active.<\/p>\n\n<h3>Privacy<\/h3>\n\n<p>Trolla Last Login &amp; Security does not transmit site or user information to external services. Monitoring data is stored locally in your WordPress database.<\/p>\n\n<p>The plugin stores:<\/p>\n\n<ul>\n<li>Successful-login timestamps in user metadata.<\/li>\n<li>A local marker when user-account creation is observed while monitoring is active.<\/li>\n<li>Timestamps for when monitoring first began and most recently resumed.<\/li>\n<li>The most recent time Administrator access was granted to a user.<\/li>\n<li>Inactivity, recent-account, email-alert, and uninstall preferences.<\/li>\n<li>Minimal Administrator role-grant events containing a user ID, event type, and timestamp.<\/li>\n<li>A per-user notice fingerprint when a review notice is dismissed.<\/li>\n<\/ul>\n\n<p>It does not store IP addresses, user agents, geographic information, passwords, authentication information, cookies, or analytics identifiers.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>trolla-last-login-security<\/code> folder to <code>\/wp-content\/plugins\/<\/code>, or install the plugin through the WordPress Plugins screen.<\/li>\n<li>Activate Trolla Last Login &amp; Security.<\/li>\n<li>Open Users &gt; Trolla Last Login &amp; Security.<\/li>\n<li>Review the default thresholds and email-alert setting.<\/li>\n<\/ol>\n\n<p>The plugin begins recording successful login timestamps from activation onward. Existing historical login activity cannot be reconstructed.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20this%20plugin%20send%20data%20anywhere%3F\"><h3>Does this plugin send data anywhere?<\/h3><\/dt>\n<dd><p>No. It makes no external requests and includes no telemetry. Monitoring data remains in the site's WordPress database.<\/p><\/dd>\n<dt id=\"does%20it%20record%20ip%20addresses%20or%20browser%20information%3F\"><h3>Does it record IP addresses or browser information?<\/h3><\/dt>\n<dd><p>No. It records only successful-login timestamps and minimal Administrator role-grant events.<\/p><\/dd>\n<dt id=\"why%20does%20an%20account%20say%20%22no%20login%20recorded%22%3F\"><h3>Why does an account say \"No login recorded\"?<\/h3><\/dt>\n<dd><p>The account existed before Trolla Last Login &amp; Security started monitoring, and the plugin has not observed a successful login since then. The label preserves the uncertainty of older login history.<\/p><\/dd>\n<dt id=\"when%20is%20%22never%20logged%20in%22%20shown%3F\"><h3>When is \"Never logged in\" shown?<\/h3><\/dt>\n<dd><p>Only when the user account was created after monitoring began and the plugin has not observed a successful login.<\/p><\/dd>\n<dt id=\"how%20are%20email%20alerts%20delivered%3F\"><h3>How are email alerts delivered?<\/h3><\/dt>\n<dd><p>The plugin calls WordPress's <code>wp_mail()<\/code> function and sends to the site's Administration Email Address. It does not provide SMTP or mail-delivery configuration.<\/p><\/dd>\n<dt id=\"what%20happens%20when%20i%20deactivate%20or%20delete%20the%20plugin%3F\"><h3>What happens when I deactivate or delete the plugin?<\/h3><\/dt>\n<dd><p>Deactivation never removes data. By default, deletion also retains data so monitoring history survives a reinstall. Enable \"Remove all Trolla Last Login &amp; Security data when the plugin is deleted\" in the plugin settings if deliberate cleanup is required.<\/p><\/dd>\n<dt id=\"does%20it%20support%20wordpress%20multisite%3F\"><h3>Does it support WordPress Multisite?<\/h3><\/dt>\n<dd><p>Version 1 is designed for standard, site-level WordPress installations. Advanced and network-wide Multisite behavior has not been tested and is not claimed as supported.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release.<\/li>\n<\/ul>","raw_excerpt":"Find forgotten, inactive and recently created WordPress Administrator accounts.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/he.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/359897","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/he.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/he.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/he.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=359897"}],"author":[{"embeddable":true,"href":"https:\/\/he.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/kirser"}],"wp:attachment":[{"href":"https:\/\/he.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=359897"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/he.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=359897"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/he.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=359897"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/he.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=359897"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/he.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=359897"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/he.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=359897"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}