Administrator re-authentication
The recovery action requires an authorized WordPress administrator, a valid nonce, and the administrator’s current WordPress password.
IN DEVELOPMENT · VERSION 0.1.3
SEDAJ Trace records meaningful WordPress administration activity, reconstructs user sessions, separates active work from idle browser time, and turns the local audit trail into clear reports.
Planned annual price €39 · 1 WordPress installation · purchasing is not active yet
Current maintenance release
A locked-out administrator uses a dedicated recovery screen and confirms the current WordPress account password locally—without competing with the PIN form.
The recovery action requires an authorized WordPress administrator, a valid nonce, and the administrator’s current WordPress password.
Attempts are rate-limited and audited. A successful recovery resets the separate Trace PIN to the marked bootstrap value, clears the PIN rate limit, and opens an authenticated Trace session immediately.
Accountability with context
Trace combines a structured audit trail with session reconstruction and privacy-conscious active-time measurement.
See who changed content, users, roles, extensions, updates, or important WordPress settings.
Reconstruct administration sessions and distinguish measured active work from hidden or idle browser time.
Filter events, compare active time, review sessions, and export a bounded CSV from the customer’s WordPress installation.
Reports require WordPress Administrator authorization and a separate four-digit PIN gate.
Current event coverage
Trace focuses on accountability events that help owners review work without uploading the audit trail to SEDAJ.
01Administrator28 sessions18h 42m
02Content editor34 sessions13h 09m
03Site manager17 sessions7h 51m
Reporting surface
Review 30-day metrics, an activity chart, active-user and session totals, user-time ranking, and a chronological audit table. Filter by user, category, severity, date range, or search text, then export a bounded CSV for review.
Privacy boundary
apps.sedaj.com receives only the minimal product-bound data needed for licensing. It never receives visited pages, content, users, IP addresses, events, reports, or session records.
Events, sessions, users, content references, pageviews, reports, active-time measurements, and CSV exports.
Product slug, plugin version, pseudonymous installation identity, bootstrap credential, requested scope, and signed proof.
Product-bound licensing
The server verifies license → subscription → Trace before issuing a short-lived entitlement for sedaj-trace-plugin.
Logging continues locally. Previously verified report access has a bounded 72-hour offline window; license failure never deletes the audit record.
The customer account will show subscription state, validity, one pseudonymous activation, invoices, revocation controls, and authorized releases.
Launch status
The product page and licensing contract are being prepared. Checkout, the installable package, and signed update downloads remain unavailable until Stripe test-mode and payment-to-entitlement verification pass.
Planned: €39/year · 1 installation