{"id":363861,"date":"2026-09-14T07:06:43","date_gmt":"2026-09-14T07:06:43","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/user-last-login-tracker\/"},"modified":"2026-09-14T07:29:35","modified_gmt":"2026-09-14T07:29:35","slug":"ars-vigilo-sessions","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/ars-vigilo-sessions\/","author":23525604,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.1.0","stable_tag":"1.1.0","tested":"7.1","requires":"5.8","requires_php":"7.4","requires_plugins":null,"header_name":"ARS Vigilo Sessions","header_author":"Arjit Srivastava","header_description":"Track and display the last login date and time of WordPress users with advanced features.","assets_banners_color":"f1f7fe","last_updated":"2026-09-14 07:29:35","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"","rating":5,"author_block_rating":0,"active_installs":0,"downloads":33,"num_ratings":1,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.1.0":{"tag":"1.1.0","author":"arjitsri","date":"2026-09-14 07:29:35","revision":3694675}},"upgrade_notice":{"3.4.3":"<p>Icon and map assets are now bundled with the plugin instead of being loaded from a CDN. No action required.<\/p>","3.4.1":"<p>This release adds a proper uninstall routine. If you delete the plugin, all tracking data will now be removed automatically unless you opt out via the ULLT_KEEP_DATA_ON_UNINSTALL constant.<\/p>"},"ratings":{"1":0,"2":0,"3":0,"4":0,"5":1},"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3694662,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3694662,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256},"icon.svg":{"filename":"icon.svg","revision":3694662,"resolution":false,"location":"assets","locale":false}},"assets_banners":{"Banner-1544x500.png":{"filename":"Banner-1544x500.png","revision":3694759,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"Banner-772x250.png":{"filename":"Banner-772x250.png","revision":3694759,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.1.0"],"block_files":[],"assets_screenshots":[],"screenshots":{"1":"Admin dashboard with login stats and \"currently active users\" widget.","2":"Session history table with search, filters, and CSV export.","3":"Login map showing recent logins by approximate location.","4":"Plugin settings screen (idle timeout, geolocation, tracking options).","5":"Last login\/first login\/login count columns on the Users list screen."}},"plugin_section":[262246],"plugin_tags":[60860,602,600,257747,9257],"plugin_category":[38,54],"plugin_contributors":[280597],"plugin_business_model":[],"class_list":["post-363861","plugin","type-plugin","status-publish","hentry","plugin_section-dashboard-widgets","plugin_tags-last-login","plugin_tags-login","plugin_tags-security","plugin_tags-session-tracking","plugin_tags-user-activity","plugin_category-authentication","plugin_category-security-and-spam-protection","plugin_contributors-arjitsri","plugin_committers-arjitsri"],"banners":{"banner":"https:\/\/ps.w.org\/ars-vigilo-sessions\/assets\/Banner-772x250.png?rev=3694759","banner_2x":"https:\/\/ps.w.org\/ars-vigilo-sessions\/assets\/Banner-1544x500.png?rev=3694759","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":"https:\/\/ps.w.org\/ars-vigilo-sessions\/assets\/icon.svg?rev=3694662","icon":"https:\/\/ps.w.org\/ars-vigilo-sessions\/assets\/icon.svg?rev=3694662","icon_2x":false,"generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>ARS Vigilo Sessions records every user login and logout on your site and surfaces that information in an easy-to-read admin dashboard. Features include:<\/p>\n\n<ul>\n<li>Last login, first login, and total login count per user, shown on the Users list and on each user's profile screen.<\/li>\n<li>Full session history with login\/logout time, duration, IP address, browser, and operating system.<\/li>\n<li>Optional IP geolocation (city, region, country, and map view of recent logins).<\/li>\n<li>Optional idle-timeout auto-logout, with a configurable warning before forced logout.<\/li>\n<li>\"Currently active users\" widget on the dashboard.<\/li>\n<li>CSV export of session history.<\/li>\n<li>REST API endpoints for integrating session data with other tools.<\/li>\n<li>Scheduled daily cleanup of old session records, with a configurable retention period.<\/li>\n<\/ul>\n\n<h4>Privacy notice<\/h4>\n\n<p>This plugin stores IP addresses, browser\/OS strings, and (if geolocation is enabled) approximate location data tied to user accounts, in order to provide its tracking features. Site owners should disclose this in their privacy policy. All of this data is permanently removed when the plugin is deleted (see \"Data removal\" below), unless you opt out.<\/p>\n\n<h4>Third-party services<\/h4>\n\n<p>IP geolocation is off by default. If you turn it on in <strong>ARS Vigilo Sessions &gt; Settings<\/strong>, the plugin sends a visitor's login IP address to one of the following external services in order to look up an approximate location:<\/p>\n\n<ul>\n<li><a href=\"https:\/\/ip-api.com\/\">ip-api.com<\/a> \u2014 used automatically when no API key is configured. See their <a href=\"https:\/\/ip-api.com\/docs\/legal\">terms of use<\/a>.<\/li>\n<li><a href=\"https:\/\/ipinfo.io\/\">ipinfo.io<\/a> \u2014 used when you supply an ipinfo.io access token in Settings. See their <a href=\"https:\/\/ipinfo.io\/privacy-policy\">privacy policy<\/a>.<\/li>\n<li><a href=\"https:\/\/ip-geolocation.io\/\">ip-geolocation.io<\/a> \u2014 used when you supply an ip-geolocation.io API key in Settings. See their <a href=\"https:\/\/ip-geolocation.io\/privacy-policy\">privacy policy<\/a>.<\/li>\n<\/ul>\n\n<p>No other data (page views, form submissions, content, etc.) is ever sent off-site, and no lookup occurs unless geolocation is explicitly enabled.<\/p>\n\n<h3>Credits<\/h3>\n\n<p>This plugin bundles the following third-party libraries:<\/p>\n\n<ul>\n<li><a href=\"https:\/\/fontawesome.com\/\">Font Awesome Free<\/a> 6.5.2 (solid icon set only) \u2014 icons under CC BY 4.0, fonts under SIL OFL 1.1, code under MIT. See <code>assets\/vendor\/fontawesome\/LICENSE.txt<\/code>.<\/li>\n<li><a href=\"https:\/\/leafletjs.com\/\">Leaflet<\/a> 1.9.4 \u2014 BSD 2-Clause License. See <code>assets\/vendor\/leaflet\/LICENSE.txt<\/code>.<\/li>\n<\/ul>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>ars-vigilo-sessions<\/code> folder to the <code>\/wp-content\/plugins\/<\/code> directory, or install the zip file directly through the Plugins screen in WordPress.<\/li>\n<li>Activate the plugin through the 'Plugins' screen in WordPress.<\/li>\n<li>Go to <strong>ARS Vigilo Sessions<\/strong> in the admin menu to configure settings (idle timeout, geolocation, IP\/browser tracking, retention period).<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20deactivating%20the%20plugin%20delete%20my%20data%3F\"><h3>Does deactivating the plugin delete my data?<\/h3><\/dt>\n<dd><p>No. Deactivating only stops tracking and clears the scheduled cleanup cron event. Your session history, settings, and user meta remain intact so you can safely re-activate later without losing data.<\/p><\/dd>\n<dt id=\"does%20deleting%20the%20plugin%20delete%20my%20data%3F\"><h3>Does deleting the plugin delete my data?<\/h3><\/dt>\n<dd><p>Yes, by default. When you delete the plugin from the Plugins screen, it automatically removes:<\/p>\n\n<ul>\n<li>The custom database table that stores session history.<\/li>\n<li>All plugin settings\/options.<\/li>\n<li>All per-user meta fields it created (last login, login count, last IP, last browser, etc).<\/li>\n<li>Any scheduled cron events.<\/li>\n<li>On multisite networks, the same cleanup runs for every site.<\/li>\n<\/ul>\n\n<p>If you want to keep this data even after deleting the plugin (for example, to re-install later), add this line to your <code>wp-config.php<\/code> before deleting:<\/p>\n\n<pre><code>define( 'ULLT_KEEP_DATA_ON_UNINSTALL', true );\n<\/code><\/pre><\/dd>\n<dt id=\"does%20this%20plugin%20slow%20down%20my%20site%3F\"><h3>Does this plugin slow down my site?<\/h3><\/dt>\n<dd><p>Session\/activity tracking only runs for logged-in users. Geolocation lookups are cached per user so they don't run on every request, and old session rows are pruned automatically based on your configured retention period.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>Renamed the plugin from \"Login Pulse\" to \"ARS Vigilo Sessions\" (new slug: <code>ars-vigilo-sessions<\/code>). Updated the plugin header, text domain, translation template, and all user-facing admin menu\/page titles accordingly. Internal option names, database table, and function\/hook prefixes (<code>ullt_<\/code>) are unchanged, so no data migration is needed.<\/li>\n<\/ul>\n\n<h4>3.5.0<\/h4>\n\n<ul>\n<li>Renamed the plugin from \"User Last Login Tracker\" to \"Login Pulse\" (new slug: <code>login-pulse<\/code>) to resolve a name-similarity concern raised during the WordPress.org plugin review. Updated the plugin header, text domain, translation template, and all user-facing admin menu\/page titles accordingly. Internal option names, database table, and function\/hook prefixes (<code>ullt_<\/code>) are unchanged, so no data migration is needed.<\/li>\n<\/ul>\n\n<h4>3.4.7<\/h4>\n\n<ul>\n<li>Fixed placement of 4 <code>translators:<\/code> comments in the suspicious-login email builder \u2014 they must sit on the line immediately above the <code>__()<\/code> call itself, not merely above the enclosing <code>sprintf()<\/code>.<\/li>\n<\/ul>\n\n<h4>3.4.6<\/h4>\n\n<ul>\n<li>Replaced all <code>date()<\/code> calls that build stored\/displayed timestamps with <code>gmdate()<\/code> to avoid runtime-timezone-dependent output.<\/li>\n<li>Added missing <code>translators:<\/code> comments and switched to numbered placeholders on all remaining translatable strings that use <code>sprintf()<\/code>\/<code>printf()<\/code>.<\/li>\n<li>Added a justified suppression for <code>fopen()<\/code>\/<code>fclose()<\/code> on <code>php:\/\/output<\/code> in the CSV export (a PHP output stream, not a filesystem path, so <code>WP_Filesystem<\/code> doesn't apply).<\/li>\n<li>Rewrote <code>uninstall.php<\/code> so its cleanup logic runs inside a function, scoping its working variables locally instead of leaving them as unprefixed globals; deduplicated the single-site\/multisite cleanup into one function.<\/li>\n<li>Documented, with justified suppressions, the remaining static-analysis false positives on the Sessions page's dynamically-built <code>$where<\/code> clause (its placeholder\/argument counts can't be evaluated statically, but are correct at runtime).<\/li>\n<\/ul>\n\n<h4>3.4.5<\/h4>\n\n<ul>\n<li>Moved the session-expiry modal's inline <code>&lt;style&gt;<\/code> block to <code>wp_add_inline_style()<\/code>.<\/li>\n<li>Sanitized the raw <code>HTTP_USER_AGENT<\/code> header before storing or parsing it, and consistently ran <code>wp_unslash()<\/code> before <code>sanitize_text_field()<\/code> on all <code>$_GET<\/code>\/<code>$_POST<\/code>\/<code>$_REQUEST<\/code> reads.<\/li>\n<li>Sanitized the fallback nonce value read directly from <code>$_POST<\/code> before passing it to <code>wp_verify_nonce()<\/code>.<\/li>\n<li>Removed the now-unnecessary <code>load_plugin_textdomain()<\/code> call (WordPress.org has auto-loaded translations for hosted plugins since WP 4.6).<\/li>\n<\/ul>\n\n<h4>3.4.4<\/h4>\n\n<ul>\n<li>Fixed all escaping errors flagged by the WordPress.org Plugin Check tool: every <code>_e()<\/code> call now uses <code>esc_html_e()<\/code>\/<code>esc_attr_e()<\/code>, and remaining raw output (URLs, translated strings with embedded markup, numeric values) is now properly escaped with <code>esc_url()<\/code>, <code>esc_html()<\/code>, <code>wp_kses_post()<\/code>, or <code>absint()<\/code>.<\/li>\n<li>Rewrote the Sessions page's list\/count queries so they are always run through <code>$wpdb-&gt;prepare()<\/code> unconditionally, removing the conditionally-prepared query that Plugin Check flagged as an unescaped database parameter.<\/li>\n<li>Added missing <code>translators:<\/code> comments and switched to numbered (<code>%1$s<\/code>, <code>%2$d<\/code>, ...) placeholders for all translatable strings with more than one placeholder.<\/li>\n<li>Bumped \"Tested up to\" to 7.1.<\/li>\n<\/ul>\n\n<h4>3.4.3<\/h4>\n\n<ul>\n<li>Bundled Font Awesome (solid icon set) and Leaflet locally instead of loading them from a third-party CDN, so no visitor or admin data is ever sent to an external host just to render an icon or a map.<\/li>\n<li>Removed a debug field that echoed the submitted security token back in a failed AJAX response.<\/li>\n<li>Cleaned up plugin metadata (version numbers, headers) ahead of the WordPress.org directory submission.<\/li>\n<\/ul>\n\n<h4>3.4.1<\/h4>\n\n<ul>\n<li>Added uninstall routine that fully removes plugin data (database table, options, user meta, and cron events) when the plugin is deleted.<\/li>\n<li>Added directory-listing protection files.<\/li>\n<li>Added this readme.<\/li>\n<\/ul>","raw_excerpt":"Track and display the last login date and time of WordPress users, with session history, geolocation, idle auto-logout, and an admin dashboard.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/363861","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=363861"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/arjitsri"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=363861"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=363861"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=363861"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=363861"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=363861"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=363861"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}