Stop User Enumeration icon

Stop User Enumeration

by fullworks

View on WordPress.org
83 Quality Score
Active Installs
21/30

With 50,000 active installs and a niche security focus, it sits well below general-purpose plugins but is solidly adopted within its category.

Update Freshness
25/25

Last updated in December 2025 and tested against WordPress 6.9.4, the plugin is clearly current and actively maintained.

User Rating
15/15

A 98 out of 100 rating across 130 reviews is exceptional and indicates very high user satisfaction.

Support Health
8/15

Zero support threads, both opened and resolved, means there is no public track record to evaluate; the score is essentially a default.

WP Compatibility
15/15

Full marks for working on WordPress 6.3 through 6.9.4 with PHP 7.4, covering the vast majority of installations in 2026.

Scores higher than 91% of indexed plugins

About

Helps secure your site against hacking attacks through detecting User Enumeration

Active Installs 50k+
Rating ★★★★½ 4.9/5
Last Updated 2026-09-03 3:17pm GMT
Requires WordPress 6.3+
Tested Up To 7.1
Requires PHP 7.4+

Security History

8 known vulnerabilities, all patched
2 High 6 Medium

Most recent: June 26, 2025

View details ▸

Powered by Wordfence Intelligence

What It Does

Stop User Enumeration blocks attackers from probing your WordPress site to discover valid usernames through author archives, REST API endpoints, and other common information disclosure vectors. Once installed, it requires no configuration; it silently intercepts enumeration requests and returns errors instead of leaking user data. It is a narrow, single-purpose security fix rather than a full security suite.

Who It's For

This plugin is best suited for site owners who want a lightweight, set-and-forget defence against username harvesting without installing a heavy security suite. It pairs well with fail2ban environments and sites that already handle authentication through other means but want to close off an easy reconnaissance vector. Small business sites, blogs, and membership platforms worried about targeted brute force will get good value here.

Who Should Skip It

If you already run Wordfence, Sucuri, or a comparable WAF with built-in user enumeration blocking, this plugin is redundant and adds no measurable protection. Sites on managed WordPress hosts like WordPress.com or Pressable, where enumeration is blocked at the edge, do not need it either.

The Bottom Line

Stop User Enumeration does one thing and does it well, with a near-perfect user rating, current compatibility, and zero configuration required. The lack of support thread activity is a minor worry, though it likely reflects the plugin's simplicity rather than neglect. Recommended as a low-cost belt-and-suspenders layer, especially if your main security plugin does not cover enumeration.

Tags

fail2ban security user enumeration wpscan