WPThumbs
Themes Plugins By purpose By industry Best-of lists Fix it guides
Free Plugin by fullworks v1.7.7

Stop User Enumeration

Helps secure your site against hacking attacks through detecting User Enumeration

Stop User Enumeration

The facts

Rating
4.9★ from 132
Active installs
50k+
Price
Free
Last updated
15 Dec 2025
Added
Aug 2013
Requires WP
6.3
Tested up to
WP 6.9.7
Requires PHP
7.4
Downloads
1,383,224

Our analysis

AI-assisted

Stop User Enumeration is a WordPress security plugin that aims to prevent user enumeration attacks, where attackers try to discover login names. It blocks requests that could reveal user information and logs the IP addresses of potential attackers for future monitoring and blocking. The plugin is suitable for users who want to enhance their site's security against brute-force attacks and protect sensitive login information.

The plugin offers various features, including blocking user enumeration requests, logging attempts for use with fail2ban, and options to restrict user data exposure through the REST API and author sitemaps. It is designed for both VPS and shared hosting environments, making it accessible for different types of WordPress users.

Best for: This plugin is best for WordPress site owners looking to improve their security against user enumeration attacks.

What it does well

  • Blocks user enumeration requests
  • Logs IP addresses of potential attackers
  • Compatible with fail2ban for enhanced security
  • Options to restrict user data exposure
  • Works on both VPS and shared hosting

Where it falls short

  • No detailed information on user interface or setup process
  • Limited information on compatibility with other plugins or themes

Verdict

Stop User Enumeration provides essential security features for WordPress users concerned about unauthorized access. It is a practical solution for enhancing site protection.

From the developer

fullworks's own description of Stop User Enumeration, lightly tidied.

Stop User Enumeration is a security plugin designed to detect and prevent hackers scanning your site for user login names.

User Enumeration is a type of attack where nefarious parties can probe your website to discover your login name. This is often a pre-cursor to brute-force password attacks. Stop User Enumeration helps block this initial attack and allows you to log IPs launching these attacks to block further attacks in the future.

Tools like WPSCAN are designed for use by ethical hackers and make efforts to find user login names. Ethical hackers ask permission first, this plugin is designed to reduce the tools when used without permission and when used in conjunction with fail2ban can block those attempts at the firewall.

If you are on a VPS or dedicated server, as the attack IP is logged, you can use (optional additional configuration) fail2ban to block the attack directly at your server’s firewall, a very powerful solution for VPS owners to stop brute force attacks as well as DDoS attacks.

If you don’t have access to install fail2ban ( e.g. on a Shared Host ) you can still use this plugin.

The plugin can stop the user id being leaked by the oEmbed API call.

Since WordPress 4.5 user data can also be obtained by API calls without logging in, this is a WordPress feature, but if you don’t need it to get user data, this
plugin will restrict and log that too.

Since WordPress 5.5 sitemaps are generated by core WP ( wp-sitemap.xml ) which includes a user/author sitemap that exposes the user id. You can enable / disable this in the plugin settings.

PHP 8.4 compatible

Tested on PHP 8.4

Features Include

  • Blocks user enumeration requests by GET or POST
  • Syslogs a block so Fail2Ban can be used to block an IP
  • Optionally blocks REST API user requests for non authorized users
  • Optionally removes author sitemap
  • Optionally removes author from OEMBED
  • Optionally removes numbers from comment authors

Privacy

This plugin includes an optional email feature for plugin news and updates. When enabled:

  • Your email address may be sent to https://fullworksplugins.com for important plugin updates and security notices
  • This is completely optional and requires your explicit consent via the opt-in form in the plugin settings
  • No data is collected or transmitted without your permission
  • You can opt-out at any time from the plugin settings
  • No other personal data is collected or transmitted to external services

The plugin logs attempted user enumeration attacks locally using WordPress’s standard logging system:
* IP addresses of potential attackers are logged locally for security monitoring
* These logs remain on your server and are not transmitted to any external service
* Logs can be used with fail2ban or similar tools for enhanced security

Read the full description on the official page →

Tagged as

Alternatives

Other plugins for securing a site.

Really Simple Security

Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vuln...

Free 3M+ installs 4.9★ (8,862)
Wordfence Security

Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by our 24-hour team....

Free 5M+ installs 4.7★ (4,983)
Akismet Anti-spam: Spam Protection

The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam sol...

Free 5M+ installs 4.7★ (1,186)
Loginizer

Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.

Free 1M+ installs 4.8★ (1,030)
Safe SVG

Enable SVG uploads and sanitize them to stop XML/SVG vulnerabilities in your WordPress website.

Free 1M+ installs 4.9★ (79)
All-In-One Security

Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plu...

Free 1M+ installs 4.7★ (1,715)