By the end of this page you know where to see which tools ran on your site, who ran them and how they came in, and how to undo an agent’s theme file changes yourself, without an agent.
Go to Settings → Block Theme MCP and open the Activity tab. It has two cards: Theme change sets and Activity log.
Theme change sets
Every write the theme tools make is recorded as a change set: the files that were touched and what happened to each. The agent tools btm.theme-list-change-sets and btm.theme-revert-change-set have worked on these records since before this screen existed. The Activity tab shows the same records to you.
The card lists the newest 20 change sets of the active theme. For each one you see:
- when it was made
- what the agent called it, the tool, and the account it ran as
- each file and what happened to it: created, changed or deleted. A set with more than three files shows the count, and the list opens when you click it.
- its state: Applied, Reverted, Interrupted, Rolled back or Partly rolled back
A revert is listed as Revert, with the date of the change set it undid. When the theme has more than 20 change sets, an agent can list and revert the older ones with the theme file tools.
Revert a change set
- Find the change set in the list.
- Click Revert.
Updated files go back to their earlier contents, created files are removed, and deleted files come back. The revert is recorded as a new change set, so it can be reverted too.
The button needs the manage_options capability, like the rest of the screen, and the two the theme file tools need: edit_themes and edit_theme_options. WordPress takes edit_themes away while DISALLOW_FILE_EDIT or DISALLOW_FILE_MODS is set. Without them the card still lists the change sets, shows no button and says why. The button works whether or not the Theme files group is switched on, because this is your own undo, not a tool for agents.
The revert only goes ahead if every file is still as the change set left it. If a file was changed afterwards, nothing is written. The notice starts with “Nothing was reverted” and names the files that changed. Look at those files before you decide. To overwrite the later edits anyway, ask an agent to call btm.theme-revert-change-set with force: true.
A set that was rolled back when it was made has nothing to revert, and a set that is already reverted cannot be reverted a second time. Revert the revert instead.
Activity log
The log lists calls to the tools that run on your server, newest first, 50 to a page. Older and Newer move between pages. Each row has these columns:
- Time
- Tool, for example
btm.theme-update-file - Account: the login the call ran as
- Came in through: Browser, Application Password (HTTP), WP-CLI, or the name of an application that connected over OAuth, followed by (OAuth). A call your own logged-in browser sends to the MCP endpoint shows Browser, not Application Password (HTTP). A revert you made on the Theme change sets card shows This screen. An application’s name is what it chose for itself, so a note above the table says the names are unverified, as on the Connect tab.
- Result: OK, or Failed with the error code
- Touched: one short label for what the call touched, if anything
What is recorded and what is not
- Recorded: the tool, the time, the account, the way in, the result, and one short label for what was touched, such as a theme path, a change set id, a template id or a post id.
- Never recorded: file contents, code, or the arguments of the call.
- Only calls that ran are logged. A call that was refused before it started, because a group is off, a capability is missing or a file changed since the agent read it, does not appear.
- The tools that run only in the browser are not logged:
btm.request,btm.browse-navigate,btm.browse-current-urlandbtm.browse-open-tab. They do their work in the browser tab and never reach your server as a tool call. A requestbtm.requestsends is still an ordinary request to your site, checked like any other. - A revert you make on the Theme change sets card is logged too, as you.
The log stays in your site’s database. Nothing is sent anywhere. The newest 500 entries are kept.
Switch the log off or clear it
The log is on from activation. Its switch, Keep an activity log, is in the Safety card on the Settings tab. Switching it off stops new entries. It does not delete the old ones.
Clear log, at the top of the Activity log card, removes every entry. Your browser asks you to confirm first.
When the log has no entries, the card says so instead of showing a table. When the log is switched off, the card says that too, with a link to the switch, and still lists the entries recorded before.
What to look for
- A tool you did not expect, or a time when nobody was working.
- Calls from an application you do not recognise. Cut it off under Connected apps. See Revoke a connected app.
- A run of failed calls with the same error code. The codes are explained in Troubleshooting.
Changes to templates and to content are undone through WordPress’s own revisions, not on this tab. See Site Editor templates and Search and replace in content.