Use Activity Logs to Review Blocked Attempts
Use Blacklist Manager Activity Logs to review blocked attempts, inspect event details, understand actions, and clean old logs safely.
Activity Logs help you understand what Blacklist Manager did, when it happened, and which customer, order, IP address, form, or checkout request was involved.
Use this page when you need to review a blocked checkout, investigate a suspicious order, confirm an automation result, or explain why a customer was stopped.
Premium required: the free core plugin can show the Activity Logs screen, but real log recording and full review are Premium features.
Open Activity Logs
- Go to Blacklist Manager > Activity logs.
- Review the newest entries first. The table is ordered by time, with the latest activity at the top.
- If you are investigating a customer report, compare the log time with the order time, checkout attempt, form submission, or verification attempt.
- Click View when you need the full technical detail behind the short table summary.
What Each Column Means
| Column | Meaning | How to use it |
|---|---|---|
| Timestamp | When the event was recorded. | Use it to match the log with an order, checkout attempt, form submission, or support ticket. |
| Type | Whether the event looks like human activity or bot activity. | Use this as a quick signal only. Always check the details before changing rules. |
| Source | Where the event came from, such as WooCommerce checkout, Store API checkout, login, registration, comment, Contact Form 7, Gravity Forms, or WPForms. | Use it to know which part of the site triggered the rule. |
| Action | The result recorded by Blacklist Manager. | Common actions include Block, Suspect, Verify, Rate limit, Remove, and Unblock. |
| Details | A short explanation of the event. | Use it to quickly see the email, phone, IP, reason, risk score, rule, or signal involved. |
| View | More detailed log data. | Use it when the short summary is not enough, especially for anti-bot, Store API, risk score, or payment checks. |
Common Events You May See
- Blocked checkout: a checkout was stopped because the email, phone, IP address, domain, customer identity, address, browser, country, proxy, VPN, or payment signal matched your rules.
- Suspect action: a customer or order was flagged for review instead of being blocked immediately.
- Verification attempt: the customer was asked to verify an email address or phone number.
- Anti-bot event: checkout protection detected a risky pattern such as missing JavaScript proof, broken session continuity, fingerprint anomalies, Store API rate limits, or checkout velocity issues.
- Form submission: Contact Form 7, Gravity Forms, or WPForms activity was checked or blocked by Blacklist Manager.
- Manual admin action: a staff member added, removed, blocked, unblocked, or changed a customer-related entry.
Review a Blocked Checkout
- Ask the customer or staff member for the approximate time of the failed checkout.
- Go to Blacklist Manager > Activity logs.
- Look for a log near that time with a checkout-related source, such as Woo checkout or Woo Store API checkout.
- Check the Action and Details columns to see whether the customer was blocked, challenged, verified, rate-limited, or marked as suspect.
- Click View if you need the full event details, such as IP address, browser data, request route, anti-bot signals, risk score, or matching rule.
- If the block was correct, keep the rule as-is. If it was a false positive, adjust the related setting or move the customer details to the whitelist.
Use Activity Logs With Orders
Activity Logs are useful when an order has a risk score, a global blacklist result, or an unexpected status change. First review the order itself, then use Activity Logs to see what happened around the same time.
For order-specific review, also read Review Risk Score and Global Blacklist Results on an Order.
Use the View Details Popup
The View button opens the full log data. This is most useful for technical events where the table summary cannot show every signal.
- For anti-bot events, check the score, threshold, mode, request source, and main signals.
- For Store API rate limits, check the route, request pattern, limit, and time window.
- For form events, check which form source was involved and which submitted detail matched a rule.
- For verification events, check whether the event was a verification request, a failed attempt, or a successful verification.
Delete Old Logs Manually
You can delete selected log entries from the Activity Logs table if you no longer need them.
- Go to Blacklist Manager > Activity logs.
- Select the checkbox beside each log entry you want to remove.
- Choose Delete from the bulk actions dropdown.
- Click Apply.
Set Automatic Log Retention
Busy stores can generate many logs. Use log retention to keep the table useful and avoid storing more history than you need.
- Go to Blacklist Manager > Settings > Tools.
- Find Activity log retention.
- Enable Clean by amount if you want to keep only the newest logs, such as the latest 500 or 1000 entries.
- Enable Clean by time if you want to delete logs older than a number of days, such as 30, 60, or 90 days.
- Click Save Settings. When enabled, cleanup runs daily.
Recommended Settings
- Small stores: keep 500 to 1000 newest logs, or keep 60 to 90 days of history.
- Busy stores: use both amount and time cleanup so the table stays fast and readable.
- During troubleshooting: temporarily keep more logs until the issue is solved.
- For privacy-sensitive stores: keep logs only as long as your support and security review process needs them.
When to Change a Rule After Reading Logs
Do not change a strong rule based on one unclear log. Look for repeated patterns first.
- If many normal customers are blocked by the same rule, make that rule less strict.
- If one customer was blocked because of old or incorrect data, whitelist that customer instead of weakening the global rule.
- If bot activity is still continuing, make anti-bot protection stricter or lower the relevant threshold.
- If suspicious checkouts are only uncertain, use Suspect or Treat as score instead of direct blocking.
Related Guides
- Configure Anti-Bot Checkout Protection
- Configure Risk Score Thresholds and Score Actions
- Configure Form Integrations
- Use Import, Export, and Cleanup Tools
User block and unblock actions can appear in Activity Logs. For the account-level workflow, see Block and Unblock WordPress Users.
Expected Result
After using Activity Logs, you should know what happened, which rule or signal caused it, whether the action was correct, and what setting to adjust if the result was too strict.
Continue from Blacklist Manager Premium documentation to the complete product workflow.
Evaluate product scope on the money page, use the pillar Guide for decisions and trade-offs, and return here for exact configuration.
Did this guide answer your question?
Still stuck?
Open a support request and include this article title, your plugin version, and what you already tried.
Open Support