{"id":372305,"date":"2026-09-22T03:49:47","date_gmt":"2026-09-22T03:49:47","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/ironcreed-request-log\/"},"modified":"2026-09-22T03:49:18","modified_gmt":"2026-09-22T03:49:18","slug":"ironcreed-request-log","status":"publish","type":"plugin","link":"https:\/\/nb.wordpress.org\/plugins\/ironcreed-request-log\/","author":23557995,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.0","stable_tag":"1.0.0","tested":"7.1.2","requires":"6.5","requires_php":"8.0","requires_plugins":null,"header_name":"IRONCREED Request Log","header_author":"IRONCREED","header_description":"Privacy-aware request logging for WordPress Runtime and opt-in Hosting Ukraine nginx logs.","assets_banners_color":"","last_updated":"2026-09-22 03:49:18","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/github.com\/IRONCREED\/SECURITY\/tree\/main\/plugins\/ironcreed-request-log","header_author_uri":"https:\/\/web.zhovten.games\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":41,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"ironcreed","date":"2026-09-22 03:49:18","revision":3706571}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3706571,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3706571,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[2679,396,281950,600],"plugin_category":[54,59],"plugin_contributors":[281951],"plugin_business_model":[],"class_list":["post-372305","plugin","type-plugin","status-publish","hentry","plugin_tags-debugging","plugin_tags-privacy","plugin_tags-request-log","plugin_tags-security","plugin_category-security-and-spam-protection","plugin_category-utilities-and-tools","plugin_contributors-ironcreed","plugin_committers-ironcreed"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/ironcreed-request-log\/assets\/icon-128x128.png?rev=3706571","icon_2x":"https:\/\/ps.w.org\/ironcreed-request-log\/assets\/icon-256x256.png?rev=3706571","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>IRONCREED Request Log offers two opt-in, clearly separated sources.<\/p>\n\n<ul>\n<li><strong>WordPress Runtime<\/strong> records requests that load WordPress. It cannot see traffic completed by a CDN, WAF, web server, full-page cache, static handler, or any layer before WordPress.<\/li>\n<li><strong>Hosting Ukraine API<\/strong> retrieves today's nginx access-log archive manually or on an explicitly enabled schedule. It shows only records and coverage returned by the provider API.<\/li>\n<\/ul>\n\n<p>This is intentionally a visibility-boundary diagnostic rather than a generic arbitrary-file log viewer. It keeps application-observed WordPress requests separate from provider-supplied nginx records, so operators can see what each layer can and cannot observe without a local-file reader, telemetry, or a general analytics stack.<\/p>\n\n<p>Both sources start disabled. Records use bounded retention and count limits. Sensitive query values are redacted. Runtime records omit IP addresses, User-Agent, Referer, bodies, cookies, and authorization data. Hosting Ukraine records may include IP addresses, URI identifiers, User-Agent, and Referer and must be covered by the site's privacy notice and lawful basis.<\/p>\n\n<p>The plugin has no telemetry, advertising, export, live tail, public endpoint, alternate updater, or local-file reader. It never sends fetched logs to IRONCREED or another service.<\/p>\n\n<p>Development source, tests, build tooling, and release documentation are maintained at <a href=\"https:\/\/github.com\/IRONCREED\/SECURITY\/tree\/main\/plugins\/ironcreed-request-log\">IRONCREED\/SECURITY<\/a>.<\/p>\n\n<h3>External services<\/h3>\n\n<p>The optional Hosting Ukraine integration calls <code>https:\/\/adm.tools\/action\/hosting\/log\/web\/nginx\/<\/code> when an authorized administrator explicitly tests\/fetches or separately enables scheduled imports. The read-only site lookup calls <code>https:\/\/adm.tools\/action\/get_services\/<\/code> with <code>type=host<\/code> and the Bearer token. It receives the host services available to that token, matches the entered domain locally, and uses the matching service <code>id<\/code> as <code>host_id<\/code>; <code>account_id<\/code> and <code>virtual_domain_id<\/code> are not used as substitutes. The discovery list is not stored. Test\/import requests send the saved Bearer token in the Authorization header and the matched Hosting Ukraine host ID in the request body. The log response is a gzip nginx access-log archive that may contain timestamps, IP addresses, methods, URIs, statuses, response sizes, User-Agent values, and Referer values. Imported records are retained in the local WordPress database. Disconnect deletes credentials, cancels future scheduled imports, and leaves imported records until retention expiry or manual clearing.<\/p>\n\n<p>Review the <a href=\"https:\/\/adm.tools\/user\/api\/#\/tab-sandbox\/hosting\/log\/web\/nginx\">API method<\/a>, <a href=\"https:\/\/www.ukraine.com.ua\/wiki\/account\/api\/\">general API guide<\/a>, <a href=\"https:\/\/www.ukraine.com.ua\/wiki\/hosting\/sites\/my-sites\/access-log\/\">access-log documentation<\/a>, <a href=\"https:\/\/www.ukraine.com.ua\/legal\/tos\/\">Terms of Service<\/a>, <a href=\"https:\/\/www.ukraine.com.ua\/legal\/publicoffer\/\">public offer<\/a>, and <a href=\"https:\/\/www.ukraine.com.ua\/legal\/privacypolicy\/\">Privacy Policy<\/a> before connecting.<\/p>\n\n<h3>Privacy<\/h3>\n\n<p>Administrators control enablement, access, retention, clearing, disconnect, and uninstall. Default retention is 24 hours with a 10,000-record cap; retention ranges from one hour to 30 days and the cap from 100 to 100,000. The plugin supplies suggested Privacy Policy Guide text. Site owners determine their lawful basis and privacy notice; the plugin does not promise legal compliance.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Install and activate the distribution ZIP in WordPress. For a source checkout, use tools\/build.sh as described in the repository README; do not ZIP the development directory with its tests and tools.<\/li>\n<li>Open Tools &gt; Request Log. Logging remains disabled until an administrator enables WordPress Runtime.<\/li>\n<li>Open Settings, choose Hosting Ukraine API, and enter a token. Resolve the hosting site ID by domain or enter it manually. Test uses the form values; saving a manual ID makes no network request.<\/li>\n<li>Use Fetch today's logs, or separately allow Scheduled imports and choose an interval. Refresh saved records only reloads the local table.<\/li>\n<li>Open Help or a question-mark link for instructions. The plugin is internationalized; WordPress.org directory installs receive translations through WordPress.org language packs when available.<\/li>\n<\/ol>\n\n<p>On Multisite, each site stores and displays its own records. Uninstall removes records, settings, credentials, all scheduled jobs, and capabilities from every site. Deactivation preserves data and credentials but cancels scheduled jobs until reactivation.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"is%20wordpress%20runtime%20a%20complete%20server%20access%20log%3F\"><h3>Is WordPress Runtime a complete server access log?<\/h3><\/dt>\n<dd><p>No. It records requests only after WordPress loads.<\/p><\/dd>\n<dt id=\"how%20is%20this%20different%20from%20a%20generic%20log%20viewer%3F\"><h3>How is this different from a generic log viewer?<\/h3><\/dt>\n<dd><p>It does not open arbitrary server files or present one source as complete. It records only requests WordPress actually sees and can optionally retrieve the hosting provider's current-day nginx archive through a read-only API. The two sources remain separate, with explicit visibility and privacy boundaries.<\/p><\/dd>\n<dt id=\"does%20hosting%20ukraine%20change%20my%20server%3F\"><h3>Does Hosting Ukraine change my server?<\/h3><\/dt>\n<dd><p>No. The provider adapter downloads the current day's nginx log and remains read-only with respect to hosting configuration.<\/p><\/dd>\n<dt id=\"when%20does%20the%20plugin%20make%20network%20requests%3F\"><h3>When does the plugin make network requests?<\/h3><\/dt>\n<dd><p>On an explicit domain lookup, connection test or log fetch, and periodically after separate opt-in. Installing, activating, opening a screen or saving a manual connection does not contact the provider. A token entered for a test is used but not saved.<\/p><\/dd>\n<dt id=\"why%20is%20automatic%20import%20late%3F\"><h3>Why is automatic import late?<\/h3><\/dt>\n<dd><p>WP-Cron needs site traffic or an operator-configured system scheduler. Low traffic, disabled cron or failed loopbacks can delay execution. The UI shows the last and next attempt. Errors back off; Retry-After is honored for rate-limited imports. Each download covers today's archive only.<\/p><\/dd>\n<dt id=\"which%20id%20should%20multisite%20use%3F\"><h3>Which ID should Multisite use?<\/h3><\/dt>\n<dd><p>For a shared hosting virtual host, start with the main network site domain. Separately hosted mapped domains may need different IDs. IDs from the user header, hosting account or WordPress blog are different objects. Connections remain local to the configured site.<\/p><\/dd>\n<dt id=\"does%20the%20wordpress%20personal-data%20exporter%20identify%20records%20by%20email%3F\"><h3>Does the WordPress personal-data exporter identify records by email?<\/h3><\/dt>\n<dd><p>The plugin does not register an exporter or eraser because records have no reliable WordPress-user identity and an email-keyed lookup cannot correctly identify all related URI, IP, User-Agent, or Referer values. Administrators can filter and clear records by source, and uninstall removes all plugin data.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial public release with WordPress Runtime and Hosting Ukraine API sources.<\/li>\n<\/ul>","raw_excerpt":"Inspect bounded WordPress requests and optionally scheduled Hosting Ukraine nginx access logs with privacy controls.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/nb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/372305","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/nb.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/nb.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=372305"}],"author":[{"embeddable":true,"href":"https:\/\/nb.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/ironcreed"}],"wp:attachment":[{"href":"https:\/\/nb.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=372305"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/nb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=372305"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/nb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=372305"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/nb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=372305"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/nb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=372305"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/nb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=372305"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}