WordPress OSINT, maintenance or security needs? Reach out!
TLDWP

Plugin: stop-user-enumeration (Used by 18,189 domains)

Stop User Enumeration

πŸ‘€ fullworks πŸ“¦ v1.7.7 πŸ”— Plugin Homepage

Stop User Enumeration is a security plugin designed to detect and prevent hackers scanning your site for user login names.

User Enumeration is a type of attack where nefarious parties can probe your website to discover your login name. This is often a pre-cursor to brute-force password attacks. Stop User Enumeration helps block this initial attack and allows you to log IPs launching these attacks to block further attacks in the future.

Tools like WPSCAN are designed for use by ethical hackers and make efforts to find user login names. Ethical hackers ask permission first, this plugin is designed to reduce the tools when used without permission and when used in conjunction with fail2ban can block those attempts at the firewall.

If you are on a VPS or dedicated server, as the attack IP is logged, you can use (optional additional configuration) fail2ban to block the attack directly at your server’s firewall, a very powerful solution for VPS owners to stop brute force attacks as well as DDoS attacks.

If you don’t have access to install fail2ban ( e.g. on a Shared Host ) you can still use this plugin.

The plugin can stop the user id being leaked by the oEmbed API call.

Since WordPress 4.5 user data can also be obtained by API calls without logging in, this is a WordPress feature, but if you don’t need it to get user data, this
plugin will restrict and log that too.

Since WordPress 5.5 sitemaps are generated by core WP ( wp-sitemap.xml ) which includes a user/author sitemap that exposes the user id. You can enable / disable this in the plugin settings.

PHP 8.4 compatible

Tested on PHP 8.4

Features Include

  • Blocks user enumeration requests by GET or POST
  • Syslogs a block so Fail2Ban can be used to block an IP
  • Optionally blocks REST API user requests for non authorized users
  • Optionally removes author sitemap
  • Optionally removes author from OEMBED
  • Optionally removes numbers from comment authors

Privacy

This plugin includes an optional email feature for plugin news and updates. When enabled:

  • Your email address may be sent to https://fullworksplugins.com for important plugin updates and security notices
  • This is completely optional and requires your explicit consent via the opt-in form in the plugin settings
  • No data is collected or transmitted without your permission
  • You can opt-out at any time from the plugin settings
  • No other personal data is collected or transmitted to external services

The plugin logs attempted user enumeration attacks locally using WordPress’s standard logging system:
* IP addresses of potential attackers are logged locally for security monitoring
* These logs remain on your server and are not transmitted to any external service
* Logs can be used with fail2ban or similar tools for enhanced security

For more information about data handling, please visit https://fullworksplugins.com/privacy-policy/

DomainExposuresHeadersLast Checked
i*c*n*i*a*l.com (WP 6.9.4) βœ… F 2026-05-07 23:06:45
e*o*e*h.fr βœ… C 2026-05-07 23:06:08
b*s*-*n*r*i*s.fr βœ… C 2026-05-07 23:06:08
p*o*f*f*o*p*i*n*e.com βœ… B 2026-05-07 23:03:59
m*d*e*h*v*n*o*t*a*e.com βœ… F 2026-05-07 23:03:44
t*e*b*a*h*a*k.com βœ… A 2026-05-07 23:02:13
c*a*c*i*a.com βœ… F 2026-05-07 22:59:43
p*a*-*-*o.com βœ… A 2026-05-07 22:58:51
d*4*h.t*m*.edu βœ… D 2026-05-07 22:51:08
s*o*t*o*l*c*i*e.com βœ… F 2026-05-07 22:49:13
e*j*f*r*n*i*s.com (WP 6.9.4) βœ… F 2026-05-07 22:46:36
e*j*r*l*a*c*s*r*e*n*.com (WP 6.8.3) βœ… D 2026-05-07 22:46:36
r*k*a*v*k*t*n.no βœ… F 2026-05-07 22:45:35
b*r*t*n*.no (WP 6.9.4) βœ… F 2026-05-07 22:45:35
c*n*r*a*s*n*g*e*s.com βœ… B 2026-05-07 22:41:51
g*y*e*l*y*e*w*r*.com βœ… F 2026-05-07 22:41:49
p*o*t*m*r*e*i*g.com βœ… B 2026-05-07 22:41:36
m*d*s*.com (WP 6.9.4) βœ… F 2026-05-07 22:39:41
c*y*e*i*d*s*r*e*.com (WP 6.9.4) βœ… B 2026-05-07 22:30:35
s*o*t*i*s*n*e*r*n*a*d*.com βœ… F 2026-05-07 22:29:33
m*d*i*y*c*e*c*.com βœ… F 2026-05-07 22:29:18
i*a*c*p*a*e*.com βœ… C 2026-05-07 22:25:32
m*d*d*n*m*f*m*l*f*r*.com βœ… F 2026-05-07 22:24:48
s*o*t*v*l*e*o*s.com βœ… F 2026-05-07 22:22:25
s*o*t*u*o*.com βœ… F 2026-05-07 22:22:25
i*a*t*o*i*i*s.com βœ… B 2026-05-07 22:19:50
s*y*e*c*v*d*e*t.org (WP 6.9.4) βœ… A 2026-05-07 22:18:43
c*n*o*m*n*e*h*c*i*g.com (WP 6.5.8) βœ… F 2026-05-07 22:14:49
1*-*8.com βœ… D 2026-05-07 22:13:28
c*u*c*s*o*t*w*.com (WP 6.8.1) βœ… F 2026-05-07 22:13:15
s*o*t*h*p*o*u*i*n*.com βœ… D 2026-05-07 22:11:27
c*n*l*e*c*w*.com βœ… D 2026-05-07 22:08:01
c*n*l*e*c*w*a*t*s*r*t*g*e*.com βœ… D 2026-05-07 22:08:01
c*n*l*e*c*w*a*t*m*n*g*m*n*.com βœ… D 2026-05-07 22:08:01
c*n*l*e*c*s*i*.com βœ… A 2026-05-07 22:08:01
i*s.u*a.edu βœ… F 2026-05-07 22:06:45
s*o*t*d*l*r*n*a*s.com βœ… A 2026-05-07 22:05:02
c*n*l*e*c*f*y*h*p.com βœ… F 2026-05-07 22:03:58
c*n*l*e*c*a*v*s*r*.com βœ… D 2026-05-07 22:03:57
l*g*r*a*e*o*a*.rs (WP 6.9.4) βœ… F 2026-05-07 22:02:16
s*r*-*r*c.com (WP 6.9.4) βœ… F 2026-05-07 21:54:09
v*r*o*t*a*i*d*a*e*l*r*.com βœ… A 2026-05-07 21:52:59
s*r*e*.com βœ… F 2026-05-07 21:49:53
l*r*s*a*r*t*u*d*f*r*a*.com (WP 6.8.5) βœ… F 2026-05-07 21:49:35
p*b*i*e*.es βœ… F 2026-05-07 21:48:27
s*o*t*u*l*a*m*.com βœ… C 2026-05-07 21:45:21
s*o*t*r*s*i*o*e.com βœ… B 2026-05-07 21:39:31
e*g*y*s*p*t*e*t*n*i*f*r*a*i*n.com (WP 6.8.5) βœ… C 2026-05-07 21:32:35
o*r*s*a*a*.f*p.p*.g*v.br (WP 6.9.4) βœ… F 2026-05-07 21:28:51
a*r*m*t*o*o*o*y.org (WP 6.9.4) βœ… F 2026-05-07 21:25:31
g*w*i.com (WP 6.9.4) βœ… F 2026-05-07 21:24:06
b*a*m*n*w*o*f*o*r*.com βœ… F 2026-05-07 21:20:35
g*w*r*a*t*p*o*e*t*o*.com βœ… B 2026-05-07 21:13:24
b*a*l*e*h*a*i*g.com βœ… F 2026-05-07 21:07:58
b*a*k*y*.com βœ… F 2026-05-07 21:07:57
b*o*h*i*e.us βœ… F 2026-05-07 21:07:06
i*a*o*m*r*c*n*l*b*f*i.com βœ… F 2026-05-07 21:04:53
e*u*o*m.u*i.n*t.th βœ… F 2026-05-07 20:55:35
c*n*i*s*e*u.com βœ… A 2026-05-07 20:53:42
c*u*s*e*n*r*d*r.com (WP 6.8.2) βœ… F 2026-05-07 20:53:36
v*r*t*t*x.com (WP 6.9.4) βœ… F 2026-05-07 20:53:22
p*t*u*l*r*i*t*n*.com βœ… F 2026-05-07 20:46:46
p*t*u*l*r*h*t*l*.com βœ… F 2026-05-07 20:46:46
p*t*u*l*r*i*c*n*a*i.com βœ… F 2026-05-07 20:46:46
p*t*u*l*r.com βœ… F 2026-05-07 20:46:46
d*g*d*.si βœ… F 2026-05-07 20:45:49
s*o*t*v*n*d*m.com βœ… F 2026-05-07 20:43:20
p*t*o*a*i*s.com βœ… A 2026-05-07 20:40:23
b*a*t*h*a*i*g*i*s.com βœ… F 2026-05-07 20:38:11
b*a*t*a*d*o*o*y.com βœ… F 2026-05-07 20:38:11
c*n*e*t*e*e*t*l*n*i*g.com βœ… F 2026-05-07 20:36:25
e*p*o*e.g*a*e*a*d.edu βœ… D 2026-05-07 20:29:02
e*s*e*n*n*a*i*w*t*r*r*n*.com βœ… F 2026-05-07 20:27:39
u*u*i*c.c*.jp βœ… D 2026-05-07 20:14:35
p*t*l*m*s*a*e*.com βœ… D 2026-05-07 20:14:13
i*a*i*n*o*d*n*i*e*t*r*.com (WP 6.9.4) βœ… F 2026-05-07 20:09:56
g*i*d*s*r*e*.c*m.au βœ… F 2026-05-07 20:08:29
i*a*i*n*o*k*a*l*a*e*v*r.com βœ… C 2026-05-07 20:02:36
1*x*o*.com βœ… F 2026-05-07 19:59:37
1*x*e*.com βœ… F 2026-05-07 19:59:37
g*u*e*o*s*.com (WP 6.8.2) βœ… F 2026-05-07 19:55:37
x*l*r*t*.tech (WP 6.8.2) βœ… F 2026-05-07 19:51:47
t*t*n.tech βœ… B 2026-05-07 19:48:43
m*c*e*e*p*o*e.com βœ… C 2026-05-07 19:48:43
v*r*f*m*o.com βœ… C 2026-05-07 19:45:50
i*a*i*c*n*i.com βœ… A 2026-05-07 19:41:20
b*a*r*d*n*a*c*b*u*s.com (WP 6.9.4) βœ… F 2026-05-07 19:36:16
t*r*y*a*g.com (WP 6.9.4) βœ… F 2026-05-07 19:34:54
h*d*a*r*x*.com βœ… F 2026-05-07 19:31:31
h*r*t*g*b*t*n*c*l*.co (WP 6.9.4) βœ… F 2026-05-07 19:31:21
a*s*n*r*o*k.com βœ… F 2026-05-07 19:28:03
c*n*x*o*e*r*s*r*o.com (WP 6.8.5) βœ… F 2026-05-07 19:24:22
e*r*s*r*p*e.cz (WP 6.5.2) βœ… A 2026-05-07 19:22:39
a*t*h*a*t*b*n*f*t*.com (WP 6.8.1) βœ… D 2026-05-07 19:16:44
b*a*s*a*e.org (WP 6.9.4) βœ… F 2026-05-07 19:16:10
f*e*l*n*e.n*u*-*e*r*t*n*.fr (WP 6.9.4) βœ… D 2026-05-07 19:13:25
b*a*.tech βœ… A 2026-05-07 19:12:24
f*i*n*s*f*h*e*r*h.eu (WP 6.7.5) βœ… D 2026-05-07 19:08:27
v*r*c*e*k.com (WP 6.9.4) βœ… A 2026-05-07 19:07:03
v*r*a*o.com βœ… B 2026-05-07 19:03:27

Top 50 Plugins

Plugin Count
elementor 1,875,532
contact-form-7 1,779,128
elementor-pro 1,074,952
woocommerce 868,172
revslider 645,412
jetpack 452,788
js_composer 438,071
wp-rocket 328,852
essential-addons-for-elementor-lite 291,674
gravityforms 257,139
complianz-gdpr 233,452
header-footer-elementor 229,770
instagram-feed 229,176
google-analytics-for-wordpress 222,702
cookie-law-info 220,254
google-site-kit 218,586
elementskit-lite 215,698
gutenberg-core 213,741
sitepress-multilingual-cms 207,223
bluehost-wordpress-plugin 197,566
gutenberg 153,110
wpforms-lite 152,154
astra-sites 144,672
litespeed-cache 134,714
cookie-notice 132,576
gtranslate 128,082
the-events-calendar 122,940
coblocks 118,985
popup-maker 115,143
woocommerce-payments 102,337
tablepress 97,535
astra-addon 95,905
bb-plugin 95,367
LayerSlider 94,369
wp-smushit 94,121
premium-addons-for-elementor 90,350
mailchimp-for-wp 88,725
honeypot 88,565
duracelltomi-google-tag-manager 88,497
akismet 85,982
cleantalk-spam-protect 85,844
all-in-one-seo-pack 84,383
woocommerce-gateway-stripe 83,211
megamenu 81,481
fusion-builder 79,549
formidable 77,759
smart-slider-3 76,735
creative-mail-by-constant-contact 76,448
ewww-image-optimizer 75,322
creame-whatsapp-me 74,510

Top 50 Themes

Theme Count
hello-elementor 625,758
Divi 524,345
astra 466,421
pub 145,751
Avada 123,569
flatsome 119,802
generatepress 117,450
oceanwp 85,885
kadence 78,977
h4 78,540
enfold 70,137
salient 67,134
bb-theme 58,964
twentytwentyfour 57,742
twentyseventeen 55,857
cocoon-master 54,485
blocksy 52,858
betheme 52,658
twentytwentyfive 49,673
dt-the7 45,127
neve 39,230
woodmart 36,626
Avada-Child-Theme 35,539
twentytwentyone 34,073
bridge 33,380
gox 33,160
twentytwenty 30,426
lightning 29,744
swell 28,527
twentytwentythree 26,863
Impreza 25,130
bricks 25,084
Newspaper 22,317
twentytwentytwo 21,763
epik-redesign 20,426
pro 18,461
uncode 18,293
twentysixteen 18,266
storefront 18,119
extendable 17,893
sydney 16,519
yith-wonder 15,780
Total 14,597
themify-ultra 14,338
hestia 12,909
twentynineteen 12,554
twentyfifteen 12,547
porto 12,429
yootheme 12,278
thrive-theme 12,062