Contents

PHP errors and 404s - Plugixa Activity Log

Two monitors record things nobody did on purpose: errors PHP raises while the site runs, and requests for pages that do not exist. They answer “what is quietly going wrong” - and both start switched off.

The Error and 404 monitoring tab in Settings, with the options for which PHP errors are recorded and which missing addresses are ignored

Why they are off by default

Every other monitor records a person doing something, which happens at a human pace. These two record what the machine and the open internet do, which does not.

  • PHP errors installs an error handler on every request, and a site with one noisy plugin can raise the same warning thousands of times a day.
  • 404 errors would record every probe for wp-login.php backups and .env files, and every public site gets those all day.

Both are useful when you are looking for something - a broken link, a plugin that fails after an update, an address scanning the site - and noise otherwise. So somebody should decide to want them.

Switch them on in Monitors. Once either is on, a section called Error & 404 monitoring appears in Settings with its options. The section is not there while both are off.

PHP errors

What is recorded

Code Severity Event
7000 High A fatal error
7001 Medium A warning
7002 Low A notice
7003 Informational A deprecation
7004 Medium Errors are being suppressed, more than 100 in an hour

Each entry names the component - which plugin, must-use plugin or theme the file belongs to, or WordPress itself - the message, the file and the line. Open the event for the address that was being requested when it happened.

File paths are stored relative to the WordPress folder, and the same folder is stripped from the message, so the log does not publish the server’s directory layout to everybody who may read it.

How much is recorded

Record, in the settings section, sets the lowest level kept:

Choice Keeps
Fatal errors only 7000
Warnings and fatal errors (default) 7000, 7001
Notices, warnings and fatal errors 7000 to 7002
Everything, including deprecations 7000 to 7003

Fatal errors are kept at every level. Deprecations are left out by default because a site running an older plugin on a newer PHP can raise hundreds on every page, and they are real but rarely urgent.

What keeps it from flooding

  • Each distinct error is recorded at most once an hour. The same message at the same file and line counts as one.
  • At most 100 entries an hour in all. The entry that crosses the limit records event 7004 instead, and the rest of that hour is dropped. Seeing 7004 means the site has a real problem, and that the log is not the full list of it.
  • At most 50 distinct non-fatal errors are looked at per request.

Ignore errors from these paths takes one piece of text per line, up to 50. Any file whose path contains the text is skipped: plugins/noisy-plugin/ hides everything from that plugin.

What it leaves alone

The monitor is a guest in PHP’s error handling. Whatever handler was there before still runs, and the error display, debug.log and WordPress’s own fatal-error screen behave exactly as they did without it.

Two things are deliberately not recorded: errors silenced in code with @, and non-fatal errors raised by Plugixa Activity Log’s own files, because a log that reports on itself can feed itself. Errors the site merely does not display are still recorded - a production site that hides warnings is exactly the one that wants them kept somewhere.

404 errors

What is recorded

Code Severity Event
7100 Low 404 Not Found, with the path
7101 Medium Many 404 errors from one address, a possible scan

Only front-end page requests count. Admin screens, feeds, scheduled jobs, AJAX and REST API requests are not recorded.

Only the path is stored, never the query string. A query string can carry a password-reset key or a tracking token, and a log is the wrong place for either. For the same reason the referring page is cut down to its host and path. Open the event to see it, along with whether the visitor looked like a browser or a bot.

What keeps it from flooding

One address gets 20 recorded 404s per ten minutes. The request that crosses that line records one 7101 possible scan event, at most once an hour per address, and further 404s from that address in the same ten minutes are counted but not stored.

So a scanner asking for five hundred paths costs twenty rows and one warning, not five hundred rows. The 7101 event is the one worth a notification or an alert rule PRO.

The ignore list

Ignore these addresses takes one pattern per line, up to 50. * matches anything, the match ignores upper and lower case, and a pattern must match the whole path. It starts with:

*/favicon.ico
*/apple-touch-icon*
*/robots.txt
*.map

The leading * is what lets a pattern match on a site installed in a sub-directory. wp-login on its own matches nothing; *wp-login* matches any path containing it.

Reading them in the log

Both monitors have their own group, so More filters -> Group narrows the activity log to PHP errors or 404 errors. For 404s, type the start of an address in the search box to follow one visitor.

Troubleshooting

Symptom Usual cause
There is no Error & 404 monitoring section in Settings Both monitors are off. Switch one on in Monitors.
An error I can see on screen is not in the log It was already recorded within the last hour, or it is below the level set under Record.
No deprecations are recorded The default level is warnings and worse. Choose Everything.
7004 appears every hour More than 100 new errors an hour. Fix the loudest, or add its path to the ignore list.
A plugin’s errors never appear Its path is on the ignore list, or the errors are silenced with @.
Only fatal errors are recorded, whatever the level PHP itself is configured to report fatal errors only, and the monitor respects that.
A missing page is not recorded It matches the ignore list, or that address passed 20 in ten minutes.
An ignore pattern does nothing It must match the whole path. Add * at both ends.
404s show no query string Deliberate. Only the path is kept.
The log filled up after switching 404s on The site is being scanned from many addresses. Ignore the common patterns, or switch the monitor off again.

What to do next

Quick Links