WordPress Administrator accounts often accumulate over time. Old developers, agencies, employees, and temporary accounts can remain active for years.
Trolla Last Login & Security gives you a focused overview of who currently has Administrator access, when each account was created, and when the account was last observed logging in.
Trolla Last Login & Security does not delete accounts, change roles, or claim that an account is malicious. It provides factual information so a site owner can make an informed review.
Trolla Last Login & Security does not transmit site or user information to external services. Monitoring data is stored locally in your WordPress database.
WordPress does not store a native last-login timestamp. Trolla Last Login & Security starts recording successful logins after the plugin begins monitoring.
For an older account without an observed login, the plugin displays “No login recorded.” It does not claim the person has never logged in. “Never logged in” is only shown when the account itself was created after monitoring began and no login has been observed.
WordPress does not store historical role-grant dates. Existing Administrators therefore show “Before monitoring” in the Admin Since column. Exact dates are recorded for Administrator access granted while monitoring is active.
Trolla Last Login & Security does not transmit site or user information to external services. Monitoring data is stored locally in your WordPress database.
The plugin stores:
It does not store IP addresses, user agents, geographic information, passwords, authentication information, cookies, or analytics identifiers.