WordPress OSINT, maintenance or security needs? Reach out!
TLDWP

Plugin: stop-user-enumeration (Used by 21,178 domains)

Stop User Enumeration

πŸ‘€ fullworks πŸ“¦ v1.7.7 πŸ”— Plugin Homepage

Stop User Enumeration is a security plugin designed to detect and prevent hackers scanning your site for user login names.

User Enumeration is a type of attack where nefarious parties can probe your website to discover your login name. This is often a pre-cursor to brute-force password attacks. Stop User Enumeration helps block this initial attack and allows you to log IPs launching these attacks to block further attacks in the future.

Tools like WPSCAN are designed for use by ethical hackers and make efforts to find user login names. Ethical hackers ask permission first, this plugin is designed to reduce the tools when used without permission and when used in conjunction with fail2ban can block those attempts at the firewall.

If you are on a VPS or dedicated server, as the attack IP is logged, you can use (optional additional configuration) fail2ban to block the attack directly at your server’s firewall, a very powerful solution for VPS owners to stop brute force attacks as well as DDoS attacks.

If you don’t have access to install fail2ban ( e.g. on a Shared Host ) you can still use this plugin.

The plugin can stop the user id being leaked by the oEmbed API call.

Since WordPress 4.5 user data can also be obtained by API calls without logging in, this is a WordPress feature, but if you don’t need it to get user data, this
plugin will restrict and log that too.

Since WordPress 5.5 sitemaps are generated by core WP ( wp-sitemap.xml ) which includes a user/author sitemap that exposes the user id. You can enable / disable this in the plugin settings.

PHP 8.4 compatible

Tested on PHP 8.4

Features Include

  • Blocks user enumeration requests by GET or POST
  • Syslogs a block so Fail2Ban can be used to block an IP
  • Optionally blocks REST API user requests for non authorized users
  • Optionally removes author sitemap
  • Optionally removes author from OEMBED
  • Optionally removes numbers from comment authors

Privacy

This plugin includes an optional email feature for plugin news and updates. When enabled:

  • Your email address may be sent to https://fullworksplugins.com for important plugin updates and security notices
  • This is completely optional and requires your explicit consent via the opt-in form in the plugin settings
  • No data is collected or transmitted without your permission
  • You can opt-out at any time from the plugin settings
  • No other personal data is collected or transmitted to external services

The plugin logs attempted user enumeration attacks locally using WordPress’s standard logging system:
* IP addresses of potential attackers are logged locally for security monitoring
* These logs remain on your server and are not transmitted to any external service
* Logs can be used with fail2ban or similar tools for enhanced security

For more information about data handling, please visit https://fullworksplugins.com/privacy-policy/

DomainExposuresHeadersLast Checked
v*t*c*i*e*.s*l*t.a*n*s.si (WP 6.9.4) βœ… F 2026-06-22 06:45:27
s*l*.s*l*t.a*n*s.si (WP 6.9.4) βœ… F 2026-06-22 06:45:27
l*s*o*e*.s*l*t.a*n*s.si (WP 6.9.4) βœ… F 2026-06-22 06:45:27
o*v*d*m.s*l*t.a*n*s.si (WP 6.9.4) βœ… F 2026-06-22 06:45:27
s*l*v*d*m.s*l*t.a*n*s.si (WP 6.9.4) βœ… F 2026-06-22 06:45:27
v*t*c.s*l*v*d*m.si (WP 6.9.4) βœ… F 2026-06-22 06:45:27
s*l*.s*l*v*d*m.si (WP 6.9.4) βœ… F 2026-06-22 06:45:27
l*s*o*e*.s*l*v*d*m.si (WP 6.9.4) βœ… F 2026-06-22 06:45:27
z*v*d.s*l*v*d*m.si (WP 6.9.4) βœ… F 2026-06-22 06:43:09
t*c*a*a*.be (WP 7.0) βœ… F 2026-06-22 06:09:10
w*r*s*i*a*e*.de βœ… F 2026-06-22 05:14:41
t*l*r*s.org βœ… F 2026-06-22 04:48:15
c*u*t*c*r*u*t.org (WP 6.9.1) βœ… F 2026-06-22 02:41:43
s*b*u*i*.w*.a*i*a*e*t.it βœ… B 2026-06-22 02:34:50
e*a*m*s*o*-*e*c*r.s*l*t.a*n*s.si βœ… F 2026-06-22 02:31:28
e*a*m*s*1*s*e*c*r.s*l*t.a*n*s.si βœ… F 2026-06-22 02:31:19
s*e*m*r*s*u*.s*l*t.a*n*s.si βœ… F 2026-06-22 02:31:18
k*j*g*m*z*i*a.s*l*t.a*n*s.si βœ… F 2026-06-22 02:31:18
m*j*v*t*o*a*d*o*o*n*s*.s*l*t.a*n*s.si βœ… F 2026-06-22 02:31:18
o*s*n*u*d*k.s*l*t.a*n*s.si (WP 6.9.4) βœ… F 2026-06-22 02:31:18
e*e*k.s*l*t.a*n*s.si βœ… F 2026-06-22 02:31:18
a*t*g*u*n*l*c*.de (WP 7.0) βœ… F 2026-06-21 22:12:06
a*e.i*f*r.org βœ… F 2026-06-21 22:02:56
k*f*i*z*t*p*a*a*t*n*o.nl (WP 6.7.2) βœ… F 2026-06-21 21:08:26
p*i*o*o*o*d*l*e*o*t*.com (WP 7.0) βœ… F 2026-06-21 19:26:00
t*u*0*5.s*l*t.a*n*s.si (WP 6.9.4) βœ… F 2026-06-21 19:16:36
t*u.s*l*t.a*n*s.si (WP 6.9.4) βœ… F 2026-06-21 19:16:36
o*s*n*j*r*e*.s*l*t.a*n*s.si (WP 6.9.4) βœ… F 2026-06-21 19:16:35
h*p.s*l*t.a*n*s.si (WP 6.9.4) βœ… F 2026-06-21 19:15:17
a*v*a*n*t*c*a*.c*m.ar βœ… F 2026-06-21 17:51:28
l*j*e*s*.u*.e*u.pl βœ… F 2026-06-21 17:36:23
c*s*-*o*k*h*p*.org (WP 7.0) βœ… F 2026-06-21 16:38:24
a*o*i*u*i*p*n*n*e.it βœ… A 2026-06-21 15:48:20
s*a*e*a*e*.c*.uk βœ… F 2026-06-21 15:11:03
d*i*.a*q.br (WP 7.0) βœ… B 2026-06-21 15:07:32
f*o*e*s.t*m*.edu βœ… D 2026-06-21 15:03:31
h*m*d*s*g*e*.hu (WP 6.8.5) βœ… D 2026-06-21 14:06:59
m*h.g*b.ve πŸ”“ F 2026-06-21 13:39:22
r*c*e*w*r*.org (WP 7.0) βœ… F 2026-06-21 13:13:07
g*e*a*s*i*v*a*t*o*g.nl (WP 6.9.4) βœ… D 2026-06-21 13:07:43
h*t*r*.net (WP 7.0) βœ… F 2026-06-21 12:45:42
w*l*o*f*i*d*r*a*r*e*-*d*s*e*.de (WP 6.9.4) βœ… F 2026-06-21 12:09:43
c*n*f*s*i*a*s.c*m.br βœ… F 2026-06-21 10:25:54
w*l*y*e*l*s*a*e.o*.ca βœ… F 2026-06-21 10:25:36
n*t*o.se (WP 6.9.4) βœ… F 2026-06-21 09:10:12
b*o*.s*n*s*e*e*-*a*u*.be βœ… F 2026-06-21 08:31:08
7*c*t.a*h.e*u.pl (WP 7.0) βœ… F 2026-06-21 07:46:16
8*c*t.a*h.e*u.pl (WP 7.0) βœ… F 2026-06-21 07:46:16
b*t*r*n.pl βœ… D 2026-06-21 07:43:00
a*e.s*i.t*g*a*.at (WP 7.0) βœ… D 2026-06-21 07:33:10
l*g*m*x.io (WP 6.9.4) βœ… A 2026-06-21 07:31:46
o*d.t*o*t*a*h*r*s*e*o.ru (WP 6.5.5) βœ… F 2026-06-21 02:57:10
e*i*i*n*s*l*r*o.com (WP 6.5.8) βœ… F 2026-06-21 02:37:47
b*v*z*o*l*.nl βœ… B 2026-06-21 02:14:04
i*o*a*i*-*e*h*i*k.be (WP 6.8.2) βœ… F 2026-06-21 02:07:56
d*f.info (WP 6.8) βœ… F 2026-06-21 01:41:36
p*n*i*e*s*r*i*e*a*t*o*.nl (WP 7.0) βœ… F 2026-06-21 00:31:42
p*y*e*t.r*t*i*m*s*c.com βœ… D 2026-06-20 23:51:33
p*s*o*t*r*k*z*b*s*.s*l*t.a*n*s.si (WP 6.9.4) βœ… F 2026-06-20 23:27:23
p*s*o*e*r*i*a.s*l*t.a*n*s.si (WP 6.9.4) βœ… F 2026-06-20 23:27:23
t*b*r*o*a*e*.s*l*t.a*n*s.si (WP 6.9.4) βœ… F 2026-06-20 23:27:23
a*i*e*.hu (WP 7.0) βœ… F 2026-06-20 23:03:01
e*t*d*a*t*s.u*r.edu (WP 7.0) βœ… C 2026-06-20 22:34:13
v*i*o*.org βœ… C 2026-06-20 21:10:22
z*e*w*-*o*t.nl βœ… F 2026-06-20 20:40:12
a*t*.my (WP 6.9.4) βœ… F 2026-06-20 20:39:06
a*e*l*u*s.se (WP 7.0) βœ… F 2026-06-20 20:35:53
e*g*h*s*i*g.com (WP 6.9.4) βœ… A 2026-06-20 19:51:18
a*a*o*d*.n*t.cn βœ… C 2026-06-20 19:50:56
z*p*5*l*w*c*.pl (WP 6.7.5) βœ… F 2026-06-20 19:43:21
t*e*c*n*r*l*e*.net (WP 7.0) βœ… C 2026-06-20 19:11:08
g*m*a*i*a*b*e*i*e.si βœ… F 2026-06-20 19:09:39
c*m*n*.l*r*a.a*.it βœ… D 2026-06-20 17:31:25
c*o*s*r*a*i*g*t*g*i*e.d*m*n*.tv βœ… F 2026-06-20 17:29:05
v*r*i*a.com βœ… F 2026-06-20 16:33:23
k*e.i*f*r.org βœ… F 2026-06-20 14:42:08
b*u*b*r*e*-*u*i*a*t*n.de βœ… D 2026-06-20 13:32:04
s*e*i*l*y*o*d*.c*m.au (WP 6.7.5) βœ… F 2026-06-20 13:27:52
l*c*a*e*a*s*r*.a*a*c*.com βœ… B 2026-06-20 11:10:29
w*c*l*n*.net (WP 7.0) βœ… F 2026-06-20 11:08:14
c*m*n*n*j*m*s.i*m*o*d.c*.uk βœ… B 2026-06-20 11:03:48
c*o*e*a*d.i*m*o*d.c*.uk βœ… B 2026-06-20 11:03:48
r*m*e*a*a*d.s*.u*.edu (WP 7.0) βœ… F 2026-06-20 10:57:46
s*k*s.de (WP 7.0) βœ… B 2026-06-20 10:50:43
r*d*o*r*m.rs (WP 7.0) βœ… F 2026-06-20 10:09:04
s*u*i*p*s*e*.nl (WP 7.0) βœ… F 2026-06-20 09:53:47
a*g*l*q*e*t*i*.nl (WP 7.0) βœ… F 2026-06-20 09:22:20
l*r*m*r*r*a*d*r*m*n*.c*.uk βœ… D 2026-06-20 08:04:12
w*n*h*s*e*c*f*e*s*h*o*.c*.uk (WP 6.8.5) βœ… F 2026-06-20 07:23:22
v*z*u*g*a*j*n*m*.rs (WP 7.0) βœ… F 2026-06-20 06:25:48
m*t*o*4.nl βœ… C 2026-06-20 06:09:36
i*c*m*.com βœ… F 2026-06-20 06:09:22
a*m*t*e*a*o*a.net βœ… F 2026-06-20 05:54:14
r*z*m*a*o*r*v*.cz βœ… F 2026-06-20 05:28:42
t*a*e*g*o*.it βœ… A 2026-06-20 04:55:09
p*r*e*t*m.work (WP 6.6.5) βœ… F 2026-06-20 04:38:42
m*n*g*m*n*s*l*t*o*.nl (WP 6.6.5) βœ… F 2026-06-20 04:38:42
r*n*o*m*r*y.org (WP 7.0) βœ… F 2026-06-20 04:29:13
o*-*e*r*v*e.si (WP 6.9.4) βœ… F 2026-06-20 03:39:30
s*m*f*c*s.com (WP 6.9.4) βœ… F 2026-06-20 02:58:35

Top 50 Plugins

Plugin Count
elementor 1,882,876
contact-form-7 1,856,074
elementor-pro 1,094,432
woocommerce 848,744
revslider 643,124
jetpack 481,366
js_composer 451,122
wp-rocket 350,775
gravityforms 326,098
essential-addons-for-elementor-lite 311,691
complianz-gdpr 271,721
cookie-law-info 244,201
instagram-feed 237,408
google-site-kit 230,914
sitepress-multilingual-cms 230,599
google-analytics-for-wordpress 221,854
elementskit-lite 220,541
header-footer-elementor 218,486
bluehost-wordpress-plugin 192,610
gutenberg 167,143
gutenberg-core 166,574
cookie-notice 162,362
litespeed-cache 143,013
the-events-calendar 139,315
wpforms-lite 133,916
gtranslate 133,635
astra-sites 122,971
popup-maker 120,743
tablepress 117,263
woocommerce-payments 116,033
coblocks 103,863
honeypot 102,441
astra-addon 98,925
duracelltomi-google-tag-manager 98,073
wp-smushit 97,427
all-in-one-seo-pack 96,908
layerslider 95,366
bb-plugin 93,293
megamenu 91,277
premium-addons-for-elementor 90,458
akismet 88,583
mailchimp-for-wp 87,016
cleantalk-spam-protect 86,271
woocommerce-gateway-stripe 85,916
ml-slider 85,358
borlabs-cookie 84,341
wp-pagenavi 83,686
fusion-builder 83,000
ewww-image-optimizer 82,162
smart-slider-3 81,554

Top 50 Themes

Theme Count
hello-elementor 643,853
Divi 534,207
astra 440,149
flatsome 150,511
generatepress 136,499
Avada 129,452
pub 114,790
twentytwentyfour 113,255
sydney 108,766
oceanwp 87,059
kadence 82,810
enfold 75,162
salient 69,136
twentyseventeen 59,140
h4 58,772
bb-theme 56,716
betheme 54,411
blocksy 53,536
cocoon-master 52,931
dt-the7 48,114
twentytwentyfive 46,609
neve 41,432
Avada-Child-Theme 39,093
woodmart 34,663
gox 34,535
bridge 34,125
twentytwentyone 33,488
lightning 32,581
twentytwenty 31,549
voxel 29,231
swell 29,223
Impreza 27,834
bricks 27,131
sinatra 26,366
twentytwentythree 25,139
Newspaper 25,107
kubio 22,381
twentytwentytwo 20,615
uncode 20,068
twentysixteen 19,431
epik-redesign 19,302
storefront 18,651
pro 18,269
Total 15,397
extendable 15,157
yith-wonder 14,147
hello-theme-child-master 14,046
yootheme 13,615
themify-ultra 13,575
hestia 13,559