Title: EnumGuard
Author: Alex Hedström
Published: <strong>19. 9. 2026</strong>
Last modified: 19. 9. 2026

---

Prohledat pluginy

![](https://s.w.org/plugins/geopattern-icon/enumguard.svg)

# EnumGuard

 Autor: [Alex Hedström](https://profiles.wordpress.org/alexhedstrom/)

[Stáhnout](https://downloads.wordpress.org/plugin/enumguard.1.0.0.zip)

 * [Podrobnosti](https://cs.wordpress.org/plugins/enumguard/#description)
 * [Hodnocení](https://cs.wordpress.org/plugins/enumguard/#reviews)
 *  [Instalace](https://cs.wordpress.org/plugins/enumguard/#installation)
 * [Vývojáři](https://cs.wordpress.org/plugins/enumguard/#developers)

 [Podpora](https://wordpress.org/support/plugin/enumguard/)

## Popis

EnumGuard is a focused WordPress plugin that stops attackers from confirming that
a username or user ID exists. WordPress still prints those signals by default; EnumGuard
closes the usual paths without hiding display names on posts.

Under Settings  EnumGuard you get three tabs:

 * Protections — overview of which discovery paths are closed
 * Settings — toggles and custom login / reset messages
 * About — plugin info

Protections covered:

 * Author ID queries (`?author=1`) that would otherwise redirect to the author archive
 * Author archives and their feeds
 * Author archive links printed in HTML
 * `author-{id}` / `author-{nicename}` body, post, and comment CSS classes
 * Core users sitemap (`/wp-sitemap-users-1.xml`)
 * Unauthenticated `/wp-json/wp/v2/users` (including `?rest_route=`)
 * REST `_embed` author payloads and author link headers
 * Login error messages that distinguish “bad username” from “bad password”
 * Lost-password responses (same confirmation whether the account exists)
 * oEmbed `author_url` / `author_name`
 * XML-RPC user-listing methods, with an optional full XML-RPC disable
 * Author sitemaps and author archive URLs from Yoast, Rank Math, and The SEO Framework

Recommended protections ship enabled. Gutenberg still reaches the users REST API
for logged-in editors. Display names stay visible. Login and reset protections also
cover WooCommerce forms when WooCommerce is active. XML-RPC can be turned off completely
if you do not need Jetpack, pingbacks, or the WordPress mobile app.

## Instalace

 1. Upload the `enumguard` folder to the `/wp-content/plugins/` directory.
 2. Activate the plugin through the Plugins menu in WordPress.
 3. Open Settings  EnumGuard to review protections.

## Nejčastější dotazy

### Will authors still show on posts?

Yes. Display names stay in content. EnumGuard stops login slugs, author archive 
URLs, and existence oracles—not bylines.

### Does this break the block editor?

No. Logged-in users who can edit posts or list users still reach `/wp/v2/users`.
Guests get a generic 404.

### What about WooCommerce?

Login and lost-password protections apply to the WooCommerce account forms as well
as wp-login.php. Bylines and display names are unchanged.

### What about the WordPress mobile app?

The app uses `wp.getUsersBlogs`. That method is removed while “XML-RPC user methods”
is on. Turn that protection off if you need the app. Do not enable “Disable XML-
RPC.”

### Can I keep author archives for a magazine site?

Yes. Disable “Author archives” and “Author archive links” on the Settings tab. Keep
author ID queries blocked so `?author=1` cannot reveal the nicename.

### Does uninstall remove settings?

Yes. Uninstall deletes EnumGuard options on the current site, and on every site 
in a multisite network.

## Recenze

Pro tento plugin nejsou žádné recenze.

## Autoři

EnumGuard je otevřený software. Následující lidé přispěli k vývoji tohoto pluginu.

Spolupracovníci

 *   [ Alex Hedström ](https://profiles.wordpress.org/alexhedstrom/)

[Přeložte “EnumGuard” do svého jazyka.](https://translate.wordpress.org/projects/wp-plugins/enumguard)

### Zajímá vás vývoj?

[Prohledejte kód](https://plugins.trac.wordpress.org/browser/enumguard/), podívejte
se do [SVN repozitáře](https://plugins.svn.wordpress.org/enumguard/), nebo se přihlaste
k[ odběru protokolu vývoje](https://plugins.trac.wordpress.org/log/enumguard/) pomocí
[RSS](https://plugins.trac.wordpress.org/log/enumguard/?limit=100&mode=stop_on_copy&format=rss).

## Přehled změn

#### 1.0.0

 * Initial release.

## Meta

 *  Verze **1.0.0**
 *  Poslední aktualizace **před 1 týdnem**
 *  Aktivních instalací **10+**
 *  Verze WordPressu ** 6.3 nebo novější **
 *  Testováno až do WordPressu **7.1.2**
 *  Verze PHP ** 7.4 nebo novější **
 *  Jazyk
 * [English (US)](https://wordpress.org/plugins/enumguard/)
 * Štítků
 * [login](https://cs.wordpress.org/plugins/tags/login/)[rest-api](https://cs.wordpress.org/plugins/tags/rest-api/)
   [security](https://cs.wordpress.org/plugins/tags/security/)[user enumeration](https://cs.wordpress.org/plugins/tags/user-enumeration/)
   [xml-rpc](https://cs.wordpress.org/plugins/tags/xml-rpc/)
 *  [Podrobnosti](https://cs.wordpress.org/plugins/enumguard/advanced/)

## Hodnocení

Zatím nebyly zadány žádné recenze.

[Vaše hodnocení](https://wordpress.org/support/plugin/enumguard/reviews/#new-post)

[Zobrazit všechny recenze](https://wordpress.org/support/plugin/enumguard/reviews/)

## Spolupracovníci

 *   [ Alex Hedström ](https://profiles.wordpress.org/alexhedstrom/)

## Podpora

Potřebujete pomoc?

 [Fórum podpory](https://wordpress.org/support/plugin/enumguard/)