FormCourier User Enumeration Protection
Blocks common WordPress user enumeration methods and optionally hides public author archives.
Solid choice
FormCourier User Enumeration Pr… is a solid plugin choice in 2026, with a few things worth checking first. Was last updated 2 days ago, and scores 64/100 on our health check.
- Actively developed — last update 2 days ago
- Tested with the latest WordPress (7.1)
- Small user base (<10 active installs)
- Very few reviews so far
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where FormCourier User Enumeratio… stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| author archive | >100 |
| login security | >100 |
| rest-api | >100 |
| security | >100 |
| user enumeration | #38 |
About FormCourier User Enumeration Protection
From the official readme · v1.1.2Description
FormCourier User Enumeration Protection reduces public exposure of WordPress usernames and author information without disabling the entire REST API.
The plugin:
- Blocks
/wp-json/wp/v2/usersfor unauthenticated visitors. - Blocks individual REST user endpoints such as
/wp-json/wp/v2/users/1. - Blocks numeric
?author=IDenumeration and returns a 404 response. - Adds an option to hide public
/author/username/archive pages. - Removes the core WordPress user sitemap to reduce public author enumeration.
- Replaces revealing WordPress login errors with a generic error message.
- Keeps REST user endpoints available to authenticated users.
- Does not collect, transmit, or share data with external services.
No external account, API key, or third-party service is required.
Settings
Go to Settings > User Enumeration Protection.
The Hide public author archives option controls whether normal /author/username/ archive pages are available.
When enabled, public author archive URLs return 404.
When disabled, normal author archives remain available. Numeric ?author=ID enumeration remains blocked regardless of this setting.
Privacy
This plugin does not collect, store, transmit, or share personal data with any external service.
The plugin stores one WordPress option that controls whether public author archives are hidden. This option is removed when the plugin is uninstalled.
Installation
- Upload the plugin ZIP from Plugins > Add New > Upload Plugin, or upload the plugin folder to
/wp-content/plugins/. - Activate FormCourier User Enumeration Protection.
- Open Settings > User Enumeration Protection.
- Choose whether public author archives should be hidden.
For a quick test, open /wp-json/wp/v2/users in a private or incognito browser window. The request should return HTTP 403.
A request such as /?author=1 should return 404.
Frequently asked questions
Does the plugin disable the WordPress REST API?
No. It only blocks the core WordPress REST API user endpoints for unauthenticated visitors. Other REST API routes remain available.
Can I keep author archive pages enabled?
Yes. Disable Hide public author archives in the plugin settings. Normal /author/username/ pages will remain available, while numeric ?author=ID enumeration stays blocked.
Does this plugin change WordPress usernames or passwords?
No. It does not modify user accounts, usernames, passwords, roles, or capabilities.
Does this plugin prevent brute-force attacks?
No. It reduces common user-enumeration signals. Use strong passwords, two-factor authentication, and login rate limiting as separate security measures.
Does the plugin send any data to FormCourier or another service?
No. The plugin works locally on the WordPress site and does not send data to external services.
Changelog
1.1.2
- Added WordPress and PHP requirement headers to the main plugin file.
- Added uninstall cleanup for the plugin setting.
- Expanded the WordPress.org readme with FAQ and privacy information.
- Prepared plugin metadata for WordPress.org directory submission.
1.1.1
- Removed plugin and author website links from the plugin header.
- Added a direct Settings link on the Plugins screen.
1.1.0
- Added a settings page under WordPress Settings.
- Added an option to enable or disable public author archives.
- Numeric
?author=IDenumeration remains blocked regardless of the archive setting.
1.0.1
- Improved author enumeration blocking to return 404 instead of redirecting.
- Improved compatibility with WordPress plugin checks.
1.0.0
- Initial release.
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
Best FormCourier User Enumeration… alternatives
All author archive plugins →FAQ
FormCourier User Enumeration Protec…: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Oct 10, 2026
Is FormCourier User Enumeration Pr… free?
Yes. FormCourier User Enumeration Pr… is free to download and use from the official WordPress.org plugin directory.
Is FormCourier User Enumeration Pr… safe to use in 2026?
FormCourier User Enumeration Pr… is a solid plugin choice in 2026, with a few things worth checking first. Was last updated 2 days ago, and scores 64/100 on our health check.
How many websites use FormCourier User Enumeration Pr…?
FormCourier User Enumeration Pr… is active on <10 WordPress websites and has been downloaded 84 times since it launched in October 2026. It was downloaded 83 times in the last 30 days.
Does FormCourier User Enumeration Pr… work with WordPress 7.1?
Yes. The developer has tested FormCourier User Enumeration Pr… up to WordPress 7.1.3, the latest release. It requires WordPress 6.0 or newer.
What PHP version does FormCourier User Enumeration Pr… need?
FormCourier User Enumeration Pr… requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was FormCourier User Enumeration Pr… last updated?
The latest version, 1.1.2, was released on October 8, 2026 (2 days ago).
Who makes FormCourier User Enumeration Pr…?
FormCourier User Enumeration Pr… is developed and maintained by Den Slav.
What are the best alternatives to FormCourier User Enumeration Pr…?
The most popular alternatives to FormCourier User Enumeration Pr… are WP Author Slug (3K+ installs) and SmartUpWorld Feed & Author… (<10 installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card