by fullworks
4.9 (130 reviews)
Stop User Enumeration
Helps secure your site against hacking attacks through detecting User Enumeration
Tested up to WP 6.9 (Current: 7.0.2)
v1.7.7
Current Version v1.7.7
Updated 7 months ago
Last Update on 15 Dec, 2025
Refreshed 16 hours ago
Last Refreshed on
Rank
#725
+1 this week
Active Installs
50K+
—
No change
KW Avg Position
37.8
—
No change
Downloads
1.3M
+158 today
Support Resolved
0%
—
No change
Rating
98%
Review 4.9 out of 5
4.9
(130 reviews)
Next Milestone 60K
50K+
60K+
29
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro
Unlock Exact Install Count
See the precise estimated active installs for this plugin, calculated from real-time ranking data.
- Exact install estimates within tiers
- Track install growth over time
- Milestone progress predictions
Need 2,990 more installs to reach 60K+
Rank Changes
Current
#725
Change
Best
#
Downloads Growth
Downloads
Growth
Peak
Upgrade to Pro
Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.
Upgrade NowReviews & Ratings
4.9
130 reviews
Overall
98%
5
126
(97%)
4
2
(2%)
3
1
(1%)
2
0
(0%)
1
1
(1%)
Tracked Keywords
Showing 4 of 4| Keyword | Position | Change | Type | Updated |
|---|---|---|---|---|
| user enumeration | 1 | — | Tag | 17 hours ago |
| fail2ban | 3 | — | Tag | 17 hours ago |
| wpscan | 3 | — | Tag | 17 hours ago |
| security | 144 | — | Tag | 17 hours ago |
Unlock Keyword Analytics
Track keyword rankings, search positions, and discover new ranking opportunities with a Pro subscription.
- Full keyword position tracking
- Historical ranking data
- Competitor keyword analysis
Track This Plugin
Get detailed analytics, keyword tracking, and position alerts delivered to your inbox.
Start Tracking FreePlugin Details
- Version
- 1.7.7
- Last Updated
- Dec 15, 2025
- Requires WP
- 6.3+
- Tested Up To
- 6.9
- PHP Version
- 7.4 or higher
- Author
- fullworks
Support & Rating
- Rating
- ★ ★ ★ ★ ★ 4.9
- Reviews
- 130
- Support Threads
- 0
- Resolved
- 0%
Keywords
Upgrade to Pro
Unlock keyword rankings, search positions, and detailed analytics with a Pro subscription.
Upgrade NowSimilar Plugins
Adminify – White Label, Admin Menu Editor, Login Customizer
7K+ installs
#2,730
Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits
30K+ installs
#988
LiteSpeed Cache
7M+ installs
#5
Akismet Anti-spam: Spam Protection
5M+ installs
#7
Wordfence Security - Firewall, Malware Scan, and Login Security
5M+ installs
#11
Frequently Asked Questions
Common questions about Stop User Enumeration
Yes, but the default ones are fine for most cases This doesn't work with PHP 5.6 or 7.1 ! This plugin does not support PHP less than 7.4. You really need to sort out your hosting, running version of software way past its supported end of life is a security risk.
Yes
A .htaccess solution is insufficient for several reasons, but most published posts on the subject do not cover POST blocking, REST API blocking and inadvertently block admin users access. And don't log the IP to a firewall, the major benefit!
If a comment is left by someone just giving a number that comment would be forbidden, as it is assumed a hack attempt, but the plugin has a bit of code that strips out numbers from comment author namesa1 Also usernames containing numbers may not work in the front end. Additionally the default rule for Rest APi is anything with users in it, so other plugins may set up endpoints.
There are two filters stop_user_enumeration_rest_stop_match set to /users/i by default and stop_user_enumeration_rest_allowed_match set to simple-jwt-login by default ( to allow that plugin's endpoints ) Developer Hooks and Filters The following hooks and filters are available for developers: Filters: * stop_user_enumeration_rest_stop_match - Modify the pattern used to detect REST API user queries (default: /users/i) * stop_user_enumeration_rest_allowed_match - Add exceptions to the REST API blocking rules (default: /simple-jwt-login/i) * stop_user_enumeration_ip - Filter the detected IP address before logging or processing (useful for integration with CDNs or proxies) * stop_user_enumeration_should_block - Determine if a request should be blocked based on IP or other conditions (return false to allow the request) Actions: * stop_user_enumeration_attempt - Triggered when user enumeration attempt is detected and logged (passes the IP address as parameter) These hooks enable add-on features like limit login attempts, block lists, WAF notifications, and integration with external services like Cloudflare.
No, but fail2ban will allow you to block IP addresses at your VPS / Dedicated server firewall that attempt user enumeration.
An fail2ban config file, wordpress-userenum.conf is found in the plugin directory stop-user-enumeration/fail2ban/filter.d
An example jail.local is found in plugin directory stop-user-enumeration/fail2ban
You can report security bugs through the Patchstack Vulnerability Disclosure Program. The Patchstack team help validate, triage and handle any security vulnerabilities. Report a security vulnerability.