Stop User Enumeration
View on WordPress.orgScores higher than 91% of indexed plugins
About
Helps secure your site against hacking attacks through detecting User Enumeration
Security History
What It Does
Stop User Enumeration blocks attackers from probing your WordPress site to discover valid usernames through author archives, REST API endpoints, and other common information disclosure vectors. Once installed, it requires no configuration; it silently intercepts enumeration requests and returns errors instead of leaking user data. It is a narrow, single-purpose security fix rather than a full security suite.
Who It's For
This plugin is best suited for site owners who want a lightweight, set-and-forget defence against username harvesting without installing a heavy security suite. It pairs well with fail2ban environments and sites that already handle authentication through other means but want to close off an easy reconnaissance vector. Small business sites, blogs, and membership platforms worried about targeted brute force will get good value here.
Who Should Skip It
If you already run Wordfence, Sucuri, or a comparable WAF with built-in user enumeration blocking, this plugin is redundant and adds no measurable protection. Sites on managed WordPress hosts like WordPress.com or Pressable, where enumeration is blocked at the edge, do not need it either.
The Bottom Line
Stop User Enumeration does one thing and does it well, with a near-perfect user rating, current compatibility, and zero configuration required. The lack of support thread activity is a minor worry, though it likely reflects the plugin's simplicity rather than neglect. Recommended as a low-cost belt-and-suspenders layer, especially if your main security plugin does not cover enumeration.
Related Plugins
Pick this if you want broader hardening, including SSL enforcement and login protections, rather than a single-purpose enumeration block.
Choose Wordfence when you need a full firewall, malware scanning, and built-in enumeration blocking in one heavyweight package.
Go with Jetpack if you want security, backups, and performance bundled together, and do not mind a feature-rich, subscription-based plugin.
Pick AIOS if you prefer a free, all-in-one security suite with a friendly interface and built-in user enumeration defences.
Safe SVG does not overlap directly; it addresses a different vulnerability (SVG uploads) and is not a real alternative to this plugin.