Skip to content
WordPress.org
  • Showcase
  • Plugins
  • Themes
  • Hosting
  • News
    • Learn WordPress
    • Documentation
    • Education
    • Forums
    • Developers
    • Blocks
    • Patterns
    • Photos
    • Openverse ↗︎
    • WordPress.tv ↗︎
    • About WordPress
    • Make WordPress
    • Events
    • Five for the Future
    • Enterprise
    • Gutenberg ↗︎
    • Job Board ↗︎
  • Swag ↗︎
  • Get WordPress
Get WordPress
WordPress.org

Plugin Directory

FormCourier User Enumeration Protection

  • Submit a plugin
  • My favorites
  • Log in
  • Submit a plugin
  • My favorites
  • Log in

FormCourier User Enumeration Protection

By Den Slav
Download
  • Details
  • Reviews
  • Installation
  • Development
Support

Description

FormCourier User Enumeration Protection reduces public exposure of WordPress usernames and author information without disabling the entire REST API.

The plugin:

  • Blocks /wp-json/wp/v2/users for unauthenticated visitors.
  • Blocks individual REST user endpoints such as /wp-json/wp/v2/users/1.
  • Blocks numeric ?author=ID enumeration and returns a 404 response.
  • Adds an option to hide public /author/username/ archive pages.
  • Removes the core WordPress user sitemap to reduce public author enumeration.
  • Replaces revealing WordPress login errors with a generic error message.
  • Keeps REST user endpoints available to authenticated users.
  • Does not collect, transmit, or share data with external services.

No external account, API key, or third-party service is required.

Settings

Go to Settings > User Enumeration Protection.

The Hide public author archives option controls whether normal /author/username/ archive pages are available.

When enabled, public author archive URLs return 404.

When disabled, normal author archives remain available. Numeric ?author=ID enumeration remains blocked regardless of this setting.

Privacy

This plugin does not collect, store, transmit, or share personal data with any external service.

The plugin stores one WordPress option that controls whether public author archives are hidden. This option is removed when the plugin is uninstalled.

Installation

  1. Upload the plugin ZIP from Plugins > Add New > Upload Plugin, or upload the plugin folder to /wp-content/plugins/.
  2. Activate FormCourier User Enumeration Protection.
  3. Open Settings > User Enumeration Protection.
  4. Choose whether public author archives should be hidden.

For a quick test, open /wp-json/wp/v2/users in a private or incognito browser window. The request should return HTTP 403.

A request such as /?author=1 should return 404.

FAQ

Does the plugin disable the WordPress REST API?

No. It only blocks the core WordPress REST API user endpoints for unauthenticated visitors. Other REST API routes remain available.

Can I keep author archive pages enabled?

Yes. Disable Hide public author archives in the plugin settings. Normal /author/username/ pages will remain available, while numeric ?author=ID enumeration stays blocked.

Does this plugin change WordPress usernames or passwords?

No. It does not modify user accounts, usernames, passwords, roles, or capabilities.

Does this plugin prevent brute-force attacks?

No. It reduces common user-enumeration signals. Use strong passwords, two-factor authentication, and login rate limiting as separate security measures.

Does the plugin send any data to FormCourier or another service?

No. The plugin works locally on the WordPress site and does not send data to external services.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“FormCourier User Enumeration Protection” is open source software. The following people have contributed to this plugin.

Contributors
  • Den Slav

Translate “FormCourier User Enumeration Protection” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.

Changelog

1.1.2

  • Added WordPress and PHP requirement headers to the main plugin file.
  • Added uninstall cleanup for the plugin setting.
  • Expanded the WordPress.org readme with FAQ and privacy information.
  • Prepared plugin metadata for WordPress.org directory submission.

1.1.1

  • Removed plugin and author website links from the plugin header.
  • Added a direct Settings link on the Plugins screen.

1.1.0

  • Added a settings page under WordPress Settings.
  • Added an option to enable or disable public author archives.
  • Numeric ?author=ID enumeration remains blocked regardless of the archive setting.

1.0.1

  • Improved author enumeration blocking to return 404 instead of redirecting.
  • Improved compatibility with WordPress plugin checks.

1.0.0

  • Initial release.

Meta

  • Version 1.1.2
  • Last updated 20 hours ago
  • Active installations Fewer than 10
  • WordPress version 6.0 or higher
  • Tested up to 7.1.3
  • PHP version 7.4 or higher
  • Tags
    author archivelogin securityrest-apisecurityuser enumeration
  • Advanced View

Ratings

No reviews have been submitted yet.

Your review

See all reviews

Contributors

  • Den Slav

Support

Got something to say? Need help?

View support forum

  • About
  • News
  • Hosting
  • Privacy
  • Showcase
  • Themes
  • Plugins
  • Patterns
  • Learn
  • Documentation
  • Developers
  • WordPress.tv ↗
  • Get Involved
  • Events
  • Donate ↗
  • Swag ↗
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org

The WordPress® trademark is the intellectual property of the WordPress Foundation.

  • Visit our X (formerly Twitter) account
  • Visit our Bluesky account
  • Visit our Mastodon account
  • Visit our Threads account
  • Visit our Facebook page
  • Visit our Instagram account
  • Visit our LinkedIn account
  • Visit our TikTok account
  • Visit our YouTube channel
  • Visit our Tumblr account
Code is Poetry