Title: FormCourier User Enumeration Protection
Author: Den Slav
Published: <strong>October 8, 2026</strong>
Last modified: October 8, 2026

---

Search plugins

![](https://ps.w.org/formcourier-user-enumeration-protection/assets/banner-772x250.
png?rev=3735131)

![](https://ps.w.org/formcourier-user-enumeration-protection/assets/icon-256x256.
png?rev=3735131)

# FormCourier User Enumeration Protection

 By [Den Slav](https://profiles.wordpress.org/densslav/)

[Download](https://downloads.wordpress.org/plugin/formcourier-user-enumeration-protection.1.1.2.zip)

 * [Details](https://wordpress.org/plugins/formcourier-user-enumeration-protection/#description)
 * [Reviews](https://wordpress.org/plugins/formcourier-user-enumeration-protection/#reviews)
 *  [Installation](https://wordpress.org/plugins/formcourier-user-enumeration-protection/#installation)
 * [Development](https://wordpress.org/plugins/formcourier-user-enumeration-protection/#developers)

 [Support](https://wordpress.org/support/plugin/formcourier-user-enumeration-protection/)

## Description

FormCourier User Enumeration Protection reduces public exposure of WordPress usernames
and author information without disabling the entire REST API.

The plugin:

 * Blocks `/wp-json/wp/v2/users` for unauthenticated visitors.
 * Blocks individual REST user endpoints such as `/wp-json/wp/v2/users/1`.
 * Blocks numeric `?author=ID` enumeration and returns a 404 response.
 * Adds an option to hide public `/author/username/` archive pages.
 * Removes the core WordPress user sitemap to reduce public author enumeration.
 * Replaces revealing WordPress login errors with a generic error message.
 * Keeps REST user endpoints available to authenticated users.
 * Does not collect, transmit, or share data with external services.

No external account, API key, or third-party service is required.

### Settings

Go to **Settings > User Enumeration Protection**.

The **Hide public author archives** option controls whether normal `/author/username/`
archive pages are available.

When enabled, public author archive URLs return 404.

When disabled, normal author archives remain available. Numeric `?author=ID` enumeration
remains blocked regardless of this setting.

### Privacy

This plugin does not collect, store, transmit, or share personal data with any external
service.

The plugin stores one WordPress option that controls whether public author archives
are hidden. This option is removed when the plugin is uninstalled.

## Installation

 1. Upload the plugin ZIP from **Plugins > Add New > Upload Plugin**, or upload the
    plugin folder to `/wp-content/plugins/`.
 2. Activate **FormCourier User Enumeration Protection**.
 3. Open **Settings > User Enumeration Protection**.
 4. Choose whether public author archives should be hidden.

For a quick test, open `/wp-json/wp/v2/users` in a private or incognito browser 
window. The request should return HTTP 403.

A request such as `/?author=1` should return 404.

## FAQ

### Does the plugin disable the WordPress REST API?

No. It only blocks the core WordPress REST API user endpoints for unauthenticated
visitors. Other REST API routes remain available.

### Can I keep author archive pages enabled?

Yes. Disable **Hide public author archives** in the plugin settings. Normal `/author/
username/` pages will remain available, while numeric `?author=ID` enumeration stays
blocked.

### Does this plugin change WordPress usernames or passwords?

No. It does not modify user accounts, usernames, passwords, roles, or capabilities.

### Does this plugin prevent brute-force attacks?

No. It reduces common user-enumeration signals. Use strong passwords, two-factor
authentication, and login rate limiting as separate security measures.

### Does the plugin send any data to FormCourier or another service?

No. The plugin works locally on the WordPress site and does not send data to external
services.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“FormCourier User Enumeration Protection” is open source software. The following
people have contributed to this plugin.

Contributors

 *   [ Den Slav ](https://profiles.wordpress.org/densslav/)

[Translate “FormCourier User Enumeration Protection” into your language.](https://translate.wordpress.org/projects/wp-plugins/formcourier-user-enumeration-protection)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/formcourier-user-enumeration-protection/),
check out the [SVN repository](https://plugins.svn.wordpress.org/formcourier-user-enumeration-protection/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/formcourier-user-enumeration-protection/)
by [RSS](https://plugins.trac.wordpress.org/log/formcourier-user-enumeration-protection/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.1.2

 * Added WordPress and PHP requirement headers to the main plugin file.
 * Added uninstall cleanup for the plugin setting.
 * Expanded the WordPress.org readme with FAQ and privacy information.
 * Prepared plugin metadata for WordPress.org directory submission.

#### 1.1.1

 * Removed plugin and author website links from the plugin header.
 * Added a direct Settings link on the Plugins screen.

#### 1.1.0

 * Added a settings page under WordPress Settings.
 * Added an option to enable or disable public author archives.
 * Numeric `?author=ID` enumeration remains blocked regardless of the archive setting.

#### 1.0.1

 * Improved author enumeration blocking to return 404 instead of redirecting.
 * Improved compatibility with WordPress plugin checks.

#### 1.0.0

 * Initial release.

## Meta

 *  Version **1.1.2**
 *  Last updated **21 hours ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.0 or higher **
 *  Tested up to **7.1.3**
 *  PHP version ** 7.4 or higher **
 * Tags
 * [author archive](https://wordpress.org/plugins/tags/author-archive/)[login security](https://wordpress.org/plugins/tags/login-security/)
   [rest-api](https://wordpress.org/plugins/tags/rest-api/)[security](https://wordpress.org/plugins/tags/security/)
   [user enumeration](https://wordpress.org/plugins/tags/user-enumeration/)
 *  [Advanced View](https://wordpress.org/plugins/formcourier-user-enumeration-protection/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/formcourier-user-enumeration-protection/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/formcourier-user-enumeration-protection/reviews/)

## Contributors

 *   [ Den Slav ](https://profiles.wordpress.org/densslav/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/formcourier-user-enumeration-protection/)