WordPress OSINT, maintenance or security needs? Reach out!
TLDWP

Plugin: stop-user-enumeration (Used by 18,057 domains)

Stop User Enumeration

πŸ‘€ fullworks πŸ“¦ v1.7.7 πŸ”— Plugin Homepage

Stop User Enumeration is a security plugin designed to detect and prevent hackers scanning your site for user login names.

User Enumeration is a type of attack where nefarious parties can probe your website to discover your login name. This is often a pre-cursor to brute-force password attacks. Stop User Enumeration helps block this initial attack and allows you to log IPs launching these attacks to block further attacks in the future.

Tools like WPSCAN are designed for use by ethical hackers and make efforts to find user login names. Ethical hackers ask permission first, this plugin is designed to reduce the tools when used without permission and when used in conjunction with fail2ban can block those attempts at the firewall.

If you are on a VPS or dedicated server, as the attack IP is logged, you can use (optional additional configuration) fail2ban to block the attack directly at your server’s firewall, a very powerful solution for VPS owners to stop brute force attacks as well as DDoS attacks.

If you don’t have access to install fail2ban ( e.g. on a Shared Host ) you can still use this plugin.

The plugin can stop the user id being leaked by the oEmbed API call.

Since WordPress 4.5 user data can also be obtained by API calls without logging in, this is a WordPress feature, but if you don’t need it to get user data, this
plugin will restrict and log that too.

Since WordPress 5.5 sitemaps are generated by core WP ( wp-sitemap.xml ) which includes a user/author sitemap that exposes the user id. You can enable / disable this in the plugin settings.

PHP 8.4 compatible

Tested on PHP 8.4

Features Include

  • Blocks user enumeration requests by GET or POST
  • Syslogs a block so Fail2Ban can be used to block an IP
  • Optionally blocks REST API user requests for non authorized users
  • Optionally removes author sitemap
  • Optionally removes author from OEMBED
  • Optionally removes numbers from comment authors

Privacy

This plugin includes an optional email feature for plugin news and updates. When enabled:

  • Your email address may be sent to https://fullworksplugins.com for important plugin updates and security notices
  • This is completely optional and requires your explicit consent via the opt-in form in the plugin settings
  • No data is collected or transmitted without your permission
  • You can opt-out at any time from the plugin settings
  • No other personal data is collected or transmitted to external services

The plugin logs attempted user enumeration attacks locally using WordPress’s standard logging system:
* IP addresses of potential attackers are logged locally for security monitoring
* These logs remain on your server and are not transmitted to any external service
* Logs can be used with fail2ban or similar tools for enhanced security

For more information about data handling, please visit https://fullworksplugins.com/privacy-policy/

DomainExposuresHeadersLast Checked
c*v*s*e*h*r*m*b*l*.com βœ… B 2026-05-03 06:11:14
c*v*s*e*h*r*c*e*i*c*r*.com βœ… B 2026-05-03 06:11:14
c*v*s*e*h*r*a*p.com βœ… B 2026-05-03 06:11:14
d*s*h*g*b*.de βœ… F 2026-05-03 06:10:19
s*n*e*u*g*m*k*e*.com (WP 6.9.4) βœ… F 2026-05-03 06:09:44
s*m*l*c*t*o*d.com βœ… F 2026-05-03 06:08:40
g*n*r*l*i*a*i*g.com (WP 6.9.4) βœ… F 2026-05-03 06:03:24
g*a*d*o*a*.net βœ… C 2026-05-03 06:02:56
j*e*o*9.w*e*g*n*.com βœ… F 2026-05-03 06:01:56
m*p*a*a*i*n*.com βœ… A 2026-05-03 06:01:22
m*p*a*a*i*n.com βœ… A 2026-05-03 06:01:21
m*p*e*t*l*.com βœ… A 2026-05-03 06:01:20
s*n*b*l*s*a*d*a*a*i*n*.com βœ… A 2026-05-03 05:58:41
g*r*e*s*a*e*q*a*i*y.org βœ… D 2026-05-03 05:57:26
m*p*a*a*i.com βœ… A 2026-05-03 05:56:28
m*p*x*e*i*n*e.com βœ… A 2026-05-03 05:56:28
w*k*s*a*f*n*.com βœ… A 2026-05-03 05:56:04
w*k*.com βœ… A 2026-05-03 05:56:03
u*m*s*e*v*r.com βœ… F 2026-05-03 05:55:13
s*e*g*r*n*m*r*i*a*u*s*.ch βœ… F 2026-05-03 05:55:11
c*n*-*y*i*b.org βœ… F 2026-05-03 05:54:30
p*m*u*p*y*a*.com βœ… F 2026-05-03 05:50:30
c*v*e*a*o*u*i*n*.com βœ… F 2026-05-03 05:44:55
b*l*e*r*.com βœ… F 2026-05-03 05:44:45
n*w*s*t*k*.pl βœ… F 2026-05-03 05:43:49
i*a*o*n*e*i*g.com βœ… B 2026-05-03 05:43:23
n*v*-*e*e*a*s*o*a*.cz (WP 6.1.6) ⚠️ C 2026-05-03 05:37:35
s*n*u*n*t*a*d*b*i.com (WP 6.9.4) βœ… A 2026-05-03 05:36:20
p*t*o*e*e*.com (WP 6.8.2) βœ… D 2026-05-03 05:34:04
p*s*m*m*d*.c*.uk βœ… A 2026-05-03 05:26:51
z*e*-*e*v*c*s.de (WP 6.9.4) βœ… A 2026-05-03 05:26:35
a*r*a*a*o*o*n*.com (WP 6.9.4) βœ… F 2026-05-03 05:26:23
h*p*f*r*u*t*c*.org βœ… F 2026-05-03 05:23:26
f*l*s*i*v*c*t*o*.com βœ… A 2026-05-03 05:20:56
w*k*s*r*f*i*c*n*d*.com βœ… F 2026-05-03 05:19:37
w*k*s*i*e.com βœ… F 2026-05-03 05:19:36
m*m*a*a*i*n*e*t*l*.com βœ… A 2026-05-03 05:08:32
b*v*r*h*v*n*e*s.nl (WP 6.9.4) βœ… F 2026-05-03 05:03:54
s*m*r*i*u*p*r*c*i*.nl (WP 6.9.4) βœ… F 2026-05-03 05:03:54
u*i*n*o*l*g*c*n*e*t*.org (WP 6.9.4) βœ… D 2026-05-03 05:02:52
s*n*i*e*f*d*c*a*y*e*v*c*s.com βœ… C 2026-05-03 05:00:19
b*l*a*d*e*s*r*b*n*.com (WP 6.9.4) βœ… F 2026-05-03 04:59:10
c*g*c*-*o*r*a*.u*i*o*n*b*u*c*.de βœ… F 2026-05-03 04:58:43
d*s*r*i*s*t*r*.com (WP 6.9.4) βœ… B 2026-05-03 04:57:20
a*r*n*l*n*d*g*t*l*a*k*t*n*.com (WP 6.9.4) βœ… F 2026-05-03 04:51:09
d*a*s.org βœ… F 2026-05-03 04:50:56
g*o*f*o*p*r*h*s*n*.org βœ… F 2026-05-03 04:50:03
p*c*e*a*.org βœ… D 2026-05-03 04:49:26
m*c*a*o*u*e*a*.com βœ… F 2026-05-03 04:47:33
a*k*r*a*.ai βœ… C 2026-05-03 04:45:46
t*r*a*a*o*n*a*i*n.org βœ… C 2026-05-03 04:38:20
d*a*o*o*i*i*a*.u*r.edu (WP 6.9.4) βœ… C 2026-05-03 04:37:30
s*n*i*n*s*r*t*g*b*o*.com βœ… B 2026-05-03 04:35:12
s*n*i*n*s*u*d*a*s.com (WP 6.7.5) βœ… C 2026-05-03 04:35:12
g*l*t*l*.dk βœ… F 2026-05-03 04:30:01
w*r*-*a*i*y*c*a*h.de (WP 6.9.4) βœ… F 2026-05-03 04:22:23
f*l*f*n*t*o*e*g.com βœ… F 2026-05-03 04:18:10
i*r*m*d*a.com (WP 6.9.4) βœ… B 2026-05-03 04:13:45
u*i*e*h.eu (WP 6.9.4) βœ… D 2026-05-03 04:10:20
n*w*i*e*h*r*t*.c*.uk βœ… F 2026-05-03 04:10:02
c*u*k*a*d*e*l*n*s.com (WP 6.9.4) βœ… C 2026-05-03 04:09:38
c*u*k*t*r*.com (WP 6.9.4) βœ… C 2026-05-03 04:09:38
s*n*a*a*t*e*s*o*s.com βœ… F 2026-05-03 04:06:20
f*e*s*m*n*i*l*r*.ca βœ… D 2026-05-03 04:06:19
p*o*e*t*e*e*i*.us βœ… F 2026-05-03 04:00:27
m*c*u*c.com (WP 6.9.4) βœ… C 2026-05-03 03:59:08
c*n*r*l*-*a*a*l*n*a.n*u*-*e*r*t*n*.fr (WP 6.9.4) βœ… D 2026-05-03 03:58:17
u*i*e*s*i*e*u*o*u*.com βœ… F 2026-05-03 03:57:38
u*i*e*c*t*d*c*.w*e*g*n*p*w*r*d.com βœ… F 2026-05-03 03:57:38
t*n*i*t*p*.org (WP 6.9.4) βœ… F 2026-05-03 03:57:07
m*b*l*p*n*h.ca (WP 6.8.5) βœ… B 2026-05-03 03:52:35
f*l*e*p*r*f*i*p*r*.com βœ… D 2026-05-03 03:52:25
p*t*t*g*o*.com (WP 6.9) βœ… F 2026-05-03 03:51:11
6*g.c*.uk βœ… D 2026-05-03 03:50:54
a*o*e.a*s*e*d*m*m*.nl βœ… C 2026-05-03 03:46:19
f*l*c*n*a*t.com βœ… A 2026-05-03 03:44:29
i*o*c*l*e*t*o*.com βœ… A 2026-05-03 03:40:55
o*d*i*e*-*r*e*r*c*s.de βœ… A 2026-05-03 03:40:51
w*j*m*s*a*t.com βœ… F 2026-05-03 03:39:33
u*h*a*t*t*k.com (WP 6.9.1) βœ… B 2026-05-03 03:39:26
p*l*u*e*c*p*n*t*r*.com βœ… F 2026-05-03 03:38:01
d*u*s*h*t*l*k*m*t*o*u*i*n*.hu βœ… D 2026-05-03 03:36:57
s*r*o*.de (WP 6.9.4) βœ… D 2026-05-03 03:35:43
u*h*v*l*a*e*y*r*e*i.com (WP 6.6.2) βœ… F 2026-05-03 03:35:06
s*i*n*k*o*f.com βœ… A 2026-05-03 03:34:41
c*t*t*i*-*r*k*u.be (WP 6.9.4) βœ… F 2026-05-03 03:33:45
c*t*t*i*j*l*s*a*o*.be (WP 6.9.4) βœ… F 2026-05-03 03:33:45
w*n*e*s*o*t*a*a*t*e*b*e*e*.nl (WP 6.9.4) βœ… F 2026-05-03 03:33:45
o*s*s*o*o*p*a*s.org (WP 6.9.4) βœ… F 2026-05-03 03:27:49
h*u*e*o*a*o*e.org βœ… F 2026-05-03 03:23:35
u*g*a*u*e*.com βœ… B 2026-05-03 03:22:58
c*t*u*a*v*n*o.com βœ… F 2026-05-03 03:22:53
c*t*u*a*v*n*i.com βœ… F 2026-05-03 03:22:53
e*l*e*c*e*s*o*r*.com βœ… F 2026-05-03 03:21:36
w*i*a*d.com βœ… A 2026-05-03 03:18:56
u*g*o*a*f*u*d*i*s.com βœ… A 2026-05-03 03:18:15
u*g*o*n*r*e*p*c.com βœ… A 2026-05-03 03:13:51
u*g*o*n*r*e*.com βœ… A 2026-05-03 03:13:51
s*g*a*u*e*e*m*e*l*y.com βœ… F 2026-05-03 03:13:16
p*r*i*s*n*r*a*m*p.org βœ… F 2026-05-03 03:12:55

Top 50 Plugins

Plugin Count
elementor 1,838,086
contact-form-7 1,755,144
elementor-pro 1,055,714
woocommerce 848,956
revslider 634,780
jetpack 451,922
js_composer 432,611
wp-rocket 325,209
essential-addons-for-elementor-lite 286,981
gravityforms 255,614
complianz-gdpr 232,317
instagram-feed 226,802
header-footer-elementor 223,646
google-analytics-for-wordpress 219,084
cookie-law-info 218,164
google-site-kit 215,434
elementskit-lite 209,962
sitepress-multilingual-cms 206,539
gutenberg-core 203,904
bluehost-wordpress-plugin 195,469
gutenberg 153,062
wpforms-lite 147,243
astra-sites 139,452
cookie-notice 132,048
litespeed-cache 131,019
gtranslate 126,140
the-events-calendar 122,698
coblocks 115,311
popup-maker 114,366
woocommerce-payments 103,608
tablepress 97,355
astra-addon 94,373
bb-plugin 93,750
LayerSlider 93,148
wp-smushit 92,842
premium-addons-for-elementor 88,552
honeypot 88,395
duracelltomi-google-tag-manager 87,860
mailchimp-for-wp 86,836
all-in-one-seo-pack 85,531
akismet 85,296
cleantalk-spam-protect 84,888
woocommerce-gateway-stripe 82,028
megamenu 80,786
fusion-builder 78,846
formidable 77,021
smart-slider-3 75,792
creative-mail-by-constant-contact 75,475
ewww-image-optimizer 74,700
gravityformsrecaptcha 73,531

Top 50 Themes

Theme Count
hello-elementor 615,415
Divi 516,935
astra 453,978
pub 139,150
Avada 122,597
flatsome 118,599
generatepress 116,465
oceanwp 84,450
kadence 77,740
h4 74,243
enfold 69,545
salient 66,354
bb-theme 57,778
twentytwentyfour 56,530
twentyseventeen 55,433
cocoon-master 53,821
betheme 52,009
blocksy 51,703
twentytwentyfive 47,925
dt-the7 44,685
neve 38,731
Avada-Child-Theme 35,542
woodmart 35,498
twentytwentyone 33,608
bridge 33,062
gox 32,997
twentytwenty 30,108
lightning 29,565
swell 28,057
twentytwentythree 26,343
Impreza 25,004
bricks 24,787
Newspaper 22,079
twentytwentytwo 21,414
epik-redesign 20,222
pro 18,255
uncode 18,160
twentysixteen 18,150
storefront 17,890
extendable 17,583
sydney 16,401
yith-wonder 15,402
Total 14,419
themify-ultra 14,077
hestia 12,774
twentynineteen 12,453
porto 12,203
yootheme 12,150
twentyfifteen 12,094
thrive-theme 11,829