{"id":382822,"date":"2026-10-08T16:32:48","date_gmt":"2026-10-08T16:32:48","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/formcourier-user-enumeration-protection\/"},"modified":"2026-10-08T16:32:39","modified_gmt":"2026-10-08T16:32:39","slug":"formcourier-user-enumeration-protection","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/formcourier-user-enumeration-protection\/","author":20030558,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.1.2","stable_tag":"1.1.2","tested":"7.1.3","requires":"6.0","requires_php":"7.4","requires_plugins":null,"header_name":"FormCourier User Enumeration Protection","header_author":"Den Slav","header_description":"Blocks common WordPress user enumeration methods and optionally hides public author archives.","assets_banners_color":"033060","last_updated":"2026-10-08 16:32:39","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"","rating":0,"author_block_rating":0,"active_installs":0,"downloads":73,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.1.2":{"tag":"1.1.2","author":"densslav","date":"2026-10-08 16:32:39","revision":3735131}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3735131,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3735131,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3735131,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3735131,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.1.2"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[38486,1229,23853,600,46130],"plugin_category":[54],"plugin_contributors":[275956],"plugin_business_model":[],"class_list":["post-382822","plugin","type-plugin","status-publish","hentry","plugin_tags-author-archive","plugin_tags-login-security","plugin_tags-rest-api","plugin_tags-security","plugin_tags-user-enumeration","plugin_category-security-and-spam-protection","plugin_contributors-densslav","plugin_committers-densslav"],"banners":{"banner":"https:\/\/ps.w.org\/formcourier-user-enumeration-protection\/assets\/banner-772x250.png?rev=3735131","banner_2x":"https:\/\/ps.w.org\/formcourier-user-enumeration-protection\/assets\/banner-1544x500.png?rev=3735131","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/formcourier-user-enumeration-protection\/assets\/icon-128x128.png?rev=3735131","icon_2x":"https:\/\/ps.w.org\/formcourier-user-enumeration-protection\/assets\/icon-256x256.png?rev=3735131","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>FormCourier User Enumeration Protection reduces public exposure of WordPress usernames and author information without disabling the entire REST API.<\/p>\n\n<p>The plugin:<\/p>\n\n<ul>\n<li>Blocks <code>\/wp-json\/wp\/v2\/users<\/code> for unauthenticated visitors.<\/li>\n<li>Blocks individual REST user endpoints such as <code>\/wp-json\/wp\/v2\/users\/1<\/code>.<\/li>\n<li>Blocks numeric <code>?author=ID<\/code> enumeration and returns a 404 response.<\/li>\n<li>Adds an option to hide public <code>\/author\/username\/<\/code> archive pages.<\/li>\n<li>Removes the core WordPress user sitemap to reduce public author enumeration.<\/li>\n<li>Replaces revealing WordPress login errors with a generic error message.<\/li>\n<li>Keeps REST user endpoints available to authenticated users.<\/li>\n<li>Does not collect, transmit, or share data with external services.<\/li>\n<\/ul>\n\n<p>No external account, API key, or third-party service is required.<\/p>\n\n<h3>Settings<\/h3>\n\n<p>Go to <strong>Settings &gt; User Enumeration Protection<\/strong>.<\/p>\n\n<p>The <strong>Hide public author archives<\/strong> option controls whether normal <code>\/author\/username\/<\/code> archive pages are available.<\/p>\n\n<p>When enabled, public author archive URLs return 404.<\/p>\n\n<p>When disabled, normal author archives remain available. Numeric <code>?author=ID<\/code> enumeration remains blocked regardless of this setting.<\/p>\n\n<h3>Privacy<\/h3>\n\n<p>This plugin does not collect, store, transmit, or share personal data with any external service.<\/p>\n\n<p>The plugin stores one WordPress option that controls whether public author archives are hidden. This option is removed when the plugin is uninstalled.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin ZIP from <strong>Plugins &gt; Add New &gt; Upload Plugin<\/strong>, or upload the plugin folder to <code>\/wp-content\/plugins\/<\/code>.<\/li>\n<li>Activate <strong>FormCourier User Enumeration Protection<\/strong>.<\/li>\n<li>Open <strong>Settings &gt; User Enumeration Protection<\/strong>.<\/li>\n<li>Choose whether public author archives should be hidden.<\/li>\n<\/ol>\n\n<p>For a quick test, open <code>\/wp-json\/wp\/v2\/users<\/code> in a private or incognito browser window. The request should return HTTP 403.<\/p>\n\n<p>A request such as <code>\/?author=1<\/code> should return 404.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20the%20plugin%20disable%20the%20wordpress%20rest%20api%3F\"><h3>Does the plugin disable the WordPress REST API?<\/h3><\/dt>\n<dd><p>No. It only blocks the core WordPress REST API user endpoints for unauthenticated visitors. Other REST API routes remain available.<\/p><\/dd>\n<dt id=\"can%20i%20keep%20author%20archive%20pages%20enabled%3F\"><h3>Can I keep author archive pages enabled?<\/h3><\/dt>\n<dd><p>Yes. Disable <strong>Hide public author archives<\/strong> in the plugin settings. Normal <code>\/author\/username\/<\/code> pages will remain available, while numeric <code>?author=ID<\/code> enumeration stays blocked.<\/p><\/dd>\n<dt id=\"does%20this%20plugin%20change%20wordpress%20usernames%20or%20passwords%3F\"><h3>Does this plugin change WordPress usernames or passwords?<\/h3><\/dt>\n<dd><p>No. It does not modify user accounts, usernames, passwords, roles, or capabilities.<\/p><\/dd>\n<dt id=\"does%20this%20plugin%20prevent%20brute-force%20attacks%3F\"><h3>Does this plugin prevent brute-force attacks?<\/h3><\/dt>\n<dd><p>No. It reduces common user-enumeration signals. Use strong passwords, two-factor authentication, and login rate limiting as separate security measures.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20send%20any%20data%20to%20formcourier%20or%20another%20service%3F\"><h3>Does the plugin send any data to FormCourier or another service?<\/h3><\/dt>\n<dd><p>No. The plugin works locally on the WordPress site and does not send data to external services.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.1.2<\/h4>\n\n<ul>\n<li>Added WordPress and PHP requirement headers to the main plugin file.<\/li>\n<li>Added uninstall cleanup for the plugin setting.<\/li>\n<li>Expanded the WordPress.org readme with FAQ and privacy information.<\/li>\n<li>Prepared plugin metadata for WordPress.org directory submission.<\/li>\n<\/ul>\n\n<h4>1.1.1<\/h4>\n\n<ul>\n<li>Removed plugin and author website links from the plugin header.<\/li>\n<li>Added a direct Settings link on the Plugins screen.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>Added a settings page under WordPress Settings.<\/li>\n<li>Added an option to enable or disable public author archives.<\/li>\n<li>Numeric <code>?author=ID<\/code> enumeration remains blocked regardless of the archive setting.<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>Improved author enumeration blocking to return 404 instead of redirecting.<\/li>\n<li>Improved compatibility with WordPress plugin checks.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release.<\/li>\n<\/ul>","raw_excerpt":"Blocks common WordPress user enumeration methods and optionally hides public author archives.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/382822","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=382822"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/densslav"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=382822"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=382822"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=382822"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=382822"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=382822"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=382822"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}