WordPress does not include a full login history screen by default. This means you can manage users from the WordPress admin area, but you cannot automatically see a complete list of recent successful and failed login attempts.
Checking recent logins is useful when you want to confirm who accessed the website, investigate unexpected activity, or review whether an administrator account was used recently.
Table of Contents
Why login history is not visible by default
WordPress creates a user session when someone logs in with valid account details. The user can then access the website based on their assigned role, such as Administrator, Editor, Author, or Subscriber.
However, WordPress does not keep a detailed visible login report in the admin dashboard by default. To review login activity clearly, you usually need to use a plugin or check server logs.
Check recent logins with a WordPress plugin
The simplest way to check recent logins is to install an activity log plugin.
One example is Simple History, a WordPress plugin that records user activity such as logins, content changes, plugin updates, and other important events inside the website. According to its WordPress.org listing, Simple History tracks user logins and other meaningful WordPress changes.
To use a plugin like Simple History:
- Log in to your WordPress admin area.
- Go to Plugins.
- Select Add New Plugin.
- Search for Simple History.
- Install the plugin.
- Activate the plugin.
- Open the plugin’s activity log screen from the WordPress dashboard.
- Review recent login entries.
Depending on the plugin, login records may include details such as the username, date, time, IP address, and whether the login was successful.
What login records can show
A login record can help you understand account activity on the website.
It may show:
- which user account was used
- when the login happened
- whether the login was successful or failed
- which IP address made the request
- whether other WordPress changes happened after the login
This information is especially useful when more than one person manages the same website.
Check active sessions in WordPress
WordPress also allows administrators to manage active sessions for user accounts.
To check this:
- Log in to the WordPress admin area.
- Go to Users.
- Open the user account you want to review.
- Scroll to the account management section.
- Use Log Out Everywhere Else if you want to close other active sessions for that account.
This option does not show a full login history. It only helps you end other currently active sessions.
Check server access logs
Server access logs can also help identify login-related activity. These logs record requests made to the website, including requests to the WordPress login page.
In the logs, you can look for requests related to:
/wp-login.php/wp-admin/- repeated login attempts
- unusual IP addresses
- many requests in a short time
Server logs are more technical than a WordPress plugin. They can show that someone accessed the login page, but they may not always clearly show whether a login was successful.
Successful logins vs. failed login attempts
A successful login means someone entered valid account details and accessed WordPress.
A failed login attempt means someone tried to log in but did not enter valid credentials.
Failed login attempts are common on public WordPress websites. They do not always mean the website has been compromised. Repeated failed attempts from unknown IP addresses may indicate automated login attempts.
What to do if you notice suspicious login activity
If you see a login you do not recognize, review the account and recent website activity.
Check whether:
- the user account belongs to someone who should have access
- the login time matches expected activity
- the IP address is familiar
- new administrator accounts were created
- plugins or themes were changed
- website files were modified
If the activity looks unusual, reset administrator passwords, remove unused accounts, and enable two-factor authentication where possible.
Practical notes
A plugin can only show login history from the moment it starts recording activity. If logging was not enabled before an event happened, older login activity may not be available inside WordPress.
For future visibility, keep an activity log plugin active and review it when needed. On busy websites, activity logs can grow over time, so it is useful to keep only the amount of history you actually need.
Summary
WordPress does not show a complete recent login history by default. To check recent logins, use an activity log plugin such as Simple History, review active user sessions, or inspect server access logs. For better account security, keep administrator access limited, remove unused users, and enable two-factor authentication when possible.