xpay✦ Commerce
Directory
WooCommerce plugins
MH User Activity Monitor
MH User Activity Monitor
Live monitoring for WordPress visitors, users, WooCommerce carts, bots and suspicious requests with privacy-friendly options.
Will this break my store?
What the WordPress.org registry says about keeping MH User Activity Monitor running.
Tested to 7.0.2
Tested against the WordPress branch in use today.24 days ago
7.4
Your host must be running at least this version.6.2
1
A single maintainer. Worth knowing if the plugin is load-bearing for your store.Maintenance & trust
Scored on how MH User Activity Monitor is looked after — not on how many stores run it.
Maintenance
35 / 35WordPress compatibility
20 / 20Support responsiveness
Not enough dataMerchant satisfaction
Not enough dataListing transparency
7 / 10Ratings
No one has rated this plugin on WordPress.org yet. That is a statement about the ratings page, not about the plugin — plenty of well-kept plugins never collect them.
MH User Activity Monitor shows in real time which users, visitors, WooCommerce customers and bots are currently active on your WordPress website. The plugin helps administrators identify unusual activity, cart sessions, bot traffic and suspicious requests more quickly, with privacy options such as IP anonymization, data-saving mode and automatic cleanup.
Live monitoring for WordPress websites
MH User Activity Monitor displays active sessions directly in the WordPress admin area. Administrators can see which visitors are currently online, whether logged-in users are active, which page types are being viewed and when the last activity occurred.
The overview uses dashboard cards, filters, sorting and live refresh. This makes it easier to distinguish normal visitor activity from unusual access patterns.
Administrators can also export the currently filtered session overview as a CSV file for short-term support or security review workflows.
Keep an eye on WooCommerce carts
When WooCommerce is active, the plugin can display active cart sessions. Depending on the selected setting, it stores and displays only the item count, item count and cart total, or detailed product information.
This can help shop owners see whether customers currently have products in their cart, whether carts are abandoned or whether unusual sessions appear in the checkout area.
Detect bots and suspicious requests
The plugin detects known bots, crawlers, SEO tools, AI crawlers, social media preview bots and suspicious request patterns. Examples include requests to login areas, XML-RPC, .env files, .git directories or other typical scanner targets.
The bot and risk indicators are not a firewall and do not replace a dedicated security plugin. They help make suspicious technical traffic more visible and easier to classify.
Privacy-friendly settings
Because the plugin processes technical visitor data, it includes several privacy options. New installations use anonymized IP addresses by default. Additional privacy modes such as None, Standard, Data-saving and Strict are available.
Stored URLs and referrers are saved without query parameters so sensitive values such as tokens, email addresses, search terms or tracking parameters are not stored unnecessarily. User-agent, URL and referrer values are also length-limited to reduce the amount of stored data.
Additional options include automatic cleanup via WordPress-Cron, ignored IP rules, CIDR support, WooCommerce cart modes and the ability to disable the frontend ping completely.
Who is this plugin for?
The plugin is suitable for operators of WordPress websites, WooCommerce shops, membership areas, booking sites and editorial websites who want a short-term view of what is happening on their website right now.
Typical use cases include:
- Shop owners want to monitor active carts and checkout sessions.
- Administrators want to identify unusual bot traffic or scanners more quickly.
- Website operators want to see which pages are currently being visited.
- Support teams want to understand short-term technical visitor activity.
- Operators of smaller websites want a simple live overview without external tracking services.
The plugin is intended for short-term technical monitoring. Site operators should check which data they really need, how long it is stored and whether information must be added to their privacy policy.
Stability note
This version is marked as the current stable build. Translations, help texts, screenshots, version metadata and basic PHP/ZIP checks were reviewed again before release.
Requirements
- WordPress 6.2 or newer.
- PHP 7.4 or newer.
- Tested up to WordPress 7.0.
- WooCommerce is optional and only required for cart monitoring.
No. The plugin is designed for short-term activity monitoring. Cleanup is handled by WordPress-Cron and the configured retention time.
Yes. When WooCommerce is active, the plugin can display cart information for active sessions if the WooCommerce session is available.
Yes. The plugin provides multiple IP modes. New installations use anonymized IP addresses by default. In Data-saving and Strict modes, storing full raw IP addresses is prevented.
None applies no additional privacy mode and uses only the individually enabled settings. Standard uses the enabled options but removes query parameters from stored URLs and referrers. Data-saving stores IPs only as hashes, removes stored user agents, stores referrers only as domains and reduces cart data. Strict effectively disables the frontend ping and does not store referrers, user agents, raw IPs or WooCommerce cart details.
Yes. The plugin includes user-agent based bot detection and simple detection of suspicious request patterns. It is not a firewall and does not replace a dedicated security plugin.
Yes. The frontend ping can be disabled completely in the settings. In that case only normal page views are recorded and the recurring frontend AJAX script is not loaded.
Ignored IP addresses and trusted proxy IP addresses support exact IPs, IPv4 wildcards such as 192.168.178.* and IPv4/IPv6 CIDR ranges such as 10.0.0.0/8 or 2001:db8::/32.
Yes. The cart mode can store only the item count, the item count and cart total, or detailed product information. The privacy-friendly default is item count and cart total.
The plugin provides privacy-friendly settings. The legal assessment depends on the actual website configuration, processing purpose, privacy policy and local requirements. Site operators should review their settings and seek professional advice if needed.
Categories
Plugin details
Tags on WordPress.org
