WPThumbs
Themes Plugins By purpose By industry Best-of lists Fix it guides
Free Plugin by mgm security partners GmbH v1.5.0

WP Author Security

Protect against user enumeration attacks on author pages and other places where valid user names can be obtained.

WP Author Security

The facts

Rating
5★ from 2
Active installs
400+
Price
Free
Last updated
12 Apr 2023
Added
Aug 2020
Requires WP
4.7
Tested up to
WP 6.2.11
Requires PHP
7.4
Downloads
6,927

Our analysis

AI-assisted

WP Author Security is a WordPress plugin designed to protect against user enumeration attacks on author pages and other areas where valid usernames can be exposed. It offers the ability to disable author pages entirely or only display them when an author has published at least one post. The plugin also neutralises error messages on login and password recovery forms to prevent attackers from determining if a username exists.

This plugin is particularly useful for site owners who want to enhance security by limiting the exposure of sensitive author information, thereby reducing the risk of social engineering and brute force attacks. It is suited for any WordPress site where author privacy is a concern.

Best for: This plugin suits WordPress site owners concerned about author privacy and security.

What it does well

  • Protects against user enumeration attacks
  • Disables author pages or limits their visibility
  • Neutralises error messages on login and password recovery
  • Removes author names from various public endpoints
  • Free to use from the WordPress.org directory

Where it falls short

  • Does not handle author name display on posts
  • Limited information on additional features

Verdict

WP Author Security provides essential protections for author information, making it a useful tool for enhancing site security, though it has some limitations in functionality.

From the developer

mgm security partners GmbH's own description of WP Author Security, lightly tidied.

WP Author Security is a lightweight but powerful plugin to protect against user enumeration attacks on author pages and other places where valid user names can be obtained.

By default, WordPress will display some sensitive information on author pages.
The author page is typically called by requesting the URI https://yourdomain.tld/?author=<id> or with permalinks https://yourdomain.tld/author/<username>.
The page will include (depending on your theme) the full name (first and last name) as well as the username of the author which is used to log in to WordPress.

In some cases, it is not wanted to expose this information to the public. An attacker is able to brute force valid IDs or valid usernames. This information might be used for further attacks like social engineering attacks or log in brute force attacks with gathered usernames.
However, when using the plugin and you disable author pages completely it must be noted that you need to take care that your active theme will not display the author name itself on posts like “Posted by admin” or something like that. This is something the plugin will not handle (at the moment).

By using the extension, you are able to disable the author pages either completely or display them only when the author has at least one published post. When the page is disabled the default 404 error page of the active theme is displayed.

In addition, the plugin will also protect other locations which are commonly used by attackers to gather valid user names. These are:

  • The REST API for users which will list all users with published posts by default.
    https://yourdomain.tld/wp-json/wp/v2/users
  • The log in page where different error messages will indicate whether an entered user name or mail address exists or not. The plugin will display a neutral error message independently whether the user exists or not.
  • The password forgotten function will also allow an attacker to check for the existence of a user. As for the log in page the plugin will display a neutral message even when the user does not exists.
  • Requesting the feed endpoint /feed of your blog will also allow others to see the username or display name of the author. The plugin will remove the name from the result list.
  • WordPress supports so-called oEmbeds. This is a technique to embed a reference to a post into another post. However, this reference will also contain the author name and a direct link to the profile page. The plugin will also remove the name and link here.
  • Since WordPress 5.5 a default sitemap can be reached via /wp-sitemap.xml. This sitemap will disclose the usernames of all authors. If this should not be disclosed you are able to disable this feature of WordPress.

Read the full description on the official page →

Tagged as

Alternatives

Other plugins for securing a site.

Really Simple Security

Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vuln...

Free 3M+ installs 4.9★ (8,862)
Wordfence Security

Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by our 24-hour team....

Free 5M+ installs 4.7★ (4,983)
Akismet Anti-spam: Spam Protection

The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam sol...

Free 5M+ installs 4.7★ (1,186)
Loginizer

Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.

Free 1M+ installs 4.8★ (1,030)
Safe SVG

Enable SVG uploads and sanitize them to stop XML/SVG vulnerabilities in your WordPress website.

Free 1M+ installs 4.9★ (79)
All-In-One Security

Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plu...

Free 1M+ installs 4.7★ (1,715)