Sikora Block Author Enumeration
Stops bots from discovering usernames through ?author= URLs, the REST API, and oEmbed, while keeping admin author links working.
by Sikora Collective · github.com/sikoracollective/sikora-block-author-enumeration
Install
No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:
wp plugin install https://github.com/sikoracollective/sikora-block-author-enumeration/archive/refs/heads/main.zipBlocks author enumeration via ?author= URLs, REST users, oEmbed, sitemaps, and XML-RPC, while keeping admin author filters working.
| Contributors | sikoracollective |
| Tags | security, author enumeration, rest-api, xml-rpc, privacy |
| Requires at least | 5.0 |
| Tested up to | 6.8 |
| Requires PHP | 7.0 |
| Stable tag | 2.2.0 |
| License | GPLv2 or later |
| Author | Sikora Collective |
readme.txtis the source of truth for plugin directory metadata and documentation. This file mirrors it for GitHub.
Description
Sikora Block Author Enumeration stops bots from discovering WordPress usernames through common enumeration vectors, without breaking the block editor or normal author archives.
The problem
By default, WordPress redirects https://example.com/?author=1 to https://example.com/author/<username>/. By incrementing the number, bots can collect every valid username on a site, then use them in brute-force or credential-stuffing attacks against wp-login.php.
The REST API, oEmbed, the users sitemap, and XML-RPC author methods give away the same information through other doors.
What this plugin does
- Blocks
?author=and?author_name=on the front end with a301redirect to the homepage. Values are never read or output; presence is enough. Encoded and array forms such as?author=1a,?author=1,2, and?author[]=1are blocked too. Pretty permalink author archives (/author/jane/) keep working. - Hides REST
/wp/v2/usersroutes from anyone without theedit_postscapability (anonymous visitors and subscribers get404). Authors, editors, and administrators keep the routes for the block editor. Users withoutlist_usersonly see authors with REST-visible published posts, andslug/linkare stripped from responses. - Removes leaking oEmbed fields.
author_urlis always removed.author_nameis removed when it matches the user's login or nicename (case-insensitive). Distinct display names are left in place. - Disables the core users sitemap so
/wp-sitemap-users-1.xmlis not generated. - Removes XML-RPC listing methods
wp.getUsersandwp.getAuthors. Other XML-RPC features (includingwp.getUsersBlogsfor mobile apps) stay available. - Rewrites admin author filter links from
author=<id>toauthor_name=<slug>onedit.phpandupload.php, so host firewalls that block?author=no longer return403for administrators.
What it does not affect
The front-end block runs on template_redirect (priority 1), so these stay untouched:
- The WordPress admin dashboard
admin-ajax.phpand WP-Cron- The REST API (for example
/wp-json/wp/v2/posts?author=1used by the block editor)
Other enumeration vectors (not covered)
This plugin does not disable public author archives. Usernames or slugs can also be exposed through:
- Author archive URLs such as
/author/<slug>/(left working on purpose) - Author archive links or body classes in themes
- Login error messages that distinguish bad usernames from bad passwords
For full coverage, combine this plugin with a firewall or security plugin where needed. Also make sure each user's Display name differs from their login username.
Security notes
- Exits immediately if the file is accessed directly (outside WordPress).
- Never reads, outputs, or stores the
authororauthor_namevalue; it only checks whether the parameter is present (including via the raw query string). - Uses
wp_safe_redirect(), which only redirects to the site's own host. - Admin author-link rewrites require
edit_postsorupload_files, and only apply to same-sitewp-adminedit.php/upload.phpURLs. Rewritten links are escaped withesc_url(). - Includes an
index.phpfile to discourage directory listing of the plugin folder.
There are no settings. The plugin works as soon as it is activated.
Installation
Upload through the dashboard
- Download the plugin zip.
- In WordPress, go to Plugins → Add New → Upload Plugin.
- Choose the zip, click Install Now, then Activate.
Manual (FTP/SFTP)
- Copy the
sikora-block-author-enumerationfolder intowp-content/plugins/. - Activate it under Plugins in the dashboard.
Frequently Asked Questions
Will this break the block editor?
No. REST requests such as /wp-json/wp/v2/posts?author=1 are not redirected. Users who can edit posts still have access to the users routes the author selector needs.
Do author archive pages still work?
Yes. Pretty permalinks like /author/jane/ are left alone on purpose.
Why do my admin "filter by author" links use author_name?
Some hosts (including SiteGround) block URLs that contain author= followed by a number before WordPress loads. The plugin rewrites those admin links to author_name=<slug> so the list still filters correctly.
What if ?author=1 returns 403 instead of 301?
Your host's firewall is blocking the request before WordPress runs. That still protects you. Try ?author=1a to reach the plugin.
How can I verify it works?
Use the automated test runner in the tests directory. From the plugin root:
./tests/run-tests.sh https://example.com
The site URL is required. An author slug is optional. The script runs the checks documented in tests/TESTING.md, prints pass/fail results, and writes tests/test-report.html. Prefer your site's canonical URL (for example https://www.example.com). See tests/TESTING.md for accepted status codes, optional flags, and notes about host firewalls or SEO plugins.
Changelog
2.2.0
- Adds
tests/run-tests.shandtests/TESTING.mdfor automated verification with an HTML report. - FAQ verification steps now point to the test runner instead of duplicating curl commands.
- Plugin display name is Sikora Block Author Enumeration (without the Security suffix).
2.1.0
- Disables the core users sitemap provider.
- Removes XML-RPC
wp.getUsersandwp.getAuthorsmethods. - Strips oEmbed
author_namewhen it matches the login or nicename. - Hardens REST user responses: without
list_users, limit queries to published authors and removeslug/link. - Detects author parameters in the raw
QUERY_STRING(encoded /[]forms). - Admin author-link rewrites require
edit_postsorupload_files. - Uses plain-text plugin Author plus Author URI instead of HTML in the header.
2.0.0
- Blocks front-end
?author_name=requests the same way as?author=, closing a slug-based enumeration bypass. - Restricts REST
/wp/v2/usersroutes to users withedit_posts, so subscribers can no longer enumerate usernames. - Admin author-link rewrites only apply to same-site
wp-adminedit.php/upload.phpURLs.
1.3.0
- Rewrites admin author filter links (
edit.phpandupload.php) fromauthor=<id>toauthor_name=<slug>, so host firewalls that block?author=no longer return a 403.
1.2.0
- Removes
author_urlfrom oEmbed responses.
1.1.0
- Hides the
/wp/v2/usersREST API routes from visitors who aren't logged in.
1.0.1
- Fixed bypasses (
?author=1a,?author=1,2,?author[]=1) by blocking every request with anauthorparameter. - Moved from
inittotemplate_redirectso REST API requests, and with them the block editor, are no longer redirected. - Switched to
wp_safe_redirect().
1.0.0
- Initial release.
Upgrade Notice
2.2.0
Adds an automated test runner under tests/. Verification docs point there; no settings changes.
2.1.0
Hardens REST, oEmbed, sitemaps, and XML-RPC author listing. No settings to configure; activate and go.