Description
FormCourier User Enumeration Protection reduces public exposure of WordPress usernames and author information without disabling the entire REST API.
The plugin:
- Blocks
/wp-json/wp/v2/usersfor unauthenticated visitors. - Blocks individual REST user endpoints such as
/wp-json/wp/v2/users/1. - Blocks numeric
?author=IDenumeration and returns a 404 response. - Adds an option to hide public
/author/username/archive pages. - Removes the core WordPress user sitemap to reduce public author enumeration.
- Replaces revealing WordPress login errors with a generic error message.
- Keeps REST user endpoints available to authenticated users.
- Does not collect, transmit, or share data with external services.
No external account, API key, or third-party service is required.
Settings
Go to Settings > User Enumeration Protection.
The Hide public author archives option controls whether normal /author/username/ archive pages are available.
When enabled, public author archive URLs return 404.
When disabled, normal author archives remain available. Numeric ?author=ID enumeration remains blocked regardless of this setting.
Privacy
This plugin does not collect, store, transmit, or share personal data with any external service.
The plugin stores one WordPress option that controls whether public author archives are hidden. This option is removed when the plugin is uninstalled.
Installation
- Upload the plugin ZIP from Plugins > Add New > Upload Plugin, or upload the plugin folder to
/wp-content/plugins/. - Activate FormCourier User Enumeration Protection.
- Open Settings > User Enumeration Protection.
- Choose whether public author archives should be hidden.
For a quick test, open /wp-json/wp/v2/users in a private or incognito browser window. The request should return HTTP 403.
A request such as /?author=1 should return 404.
FAQ
-
Does the plugin disable the WordPress REST API?
-
No. It only blocks the core WordPress REST API user endpoints for unauthenticated visitors. Other REST API routes remain available.
-
Yes. Disable Hide public author archives in the plugin settings. Normal
/author/username/pages will remain available, while numeric?author=IDenumeration stays blocked. -
Does this plugin change WordPress usernames or passwords?
-
No. It does not modify user accounts, usernames, passwords, roles, or capabilities.
-
Does this plugin prevent brute-force attacks?
-
No. It reduces common user-enumeration signals. Use strong passwords, two-factor authentication, and login rate limiting as separate security measures.
-
Does the plugin send any data to FormCourier or another service?
-
No. The plugin works locally on the WordPress site and does not send data to external services.
Reviews
There are no reviews for this plugin.
Contributors & Developers
“FormCourier User Enumeration Protection” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “FormCourier User Enumeration Protection” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
1.1.2
- Added WordPress and PHP requirement headers to the main plugin file.
- Added uninstall cleanup for the plugin setting.
- Expanded the WordPress.org readme with FAQ and privacy information.
- Prepared plugin metadata for WordPress.org directory submission.
1.1.1
- Removed plugin and author website links from the plugin header.
- Added a direct Settings link on the Plugins screen.
1.1.0
- Added a settings page under WordPress Settings.
- Added an option to enable or disable public author archives.
- Numeric
?author=IDenumeration remains blocked regardless of the archive setting.
1.0.1
- Improved author enumeration blocking to return 404 instead of redirecting.
- Improved compatibility with WordPress plugin checks.
1.0.0
- Initial release.
