=== FormCourier User Enumeration Protection ===
Contributors: densslav
Tags: security, user enumeration, rest api, author archive, login security
Requires at least: 6.0
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 1.1.2
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Blocks common WordPress user enumeration methods and optionally hides public author archives.

== Description ==

FormCourier User Enumeration Protection reduces public exposure of WordPress usernames and author information without disabling the entire REST API.

The plugin:

* Blocks `/wp-json/wp/v2/users` for unauthenticated visitors.
* Blocks individual REST user endpoints such as `/wp-json/wp/v2/users/1`.
* Blocks numeric `?author=ID` enumeration and returns a 404 response.
* Adds an option to hide public `/author/username/` archive pages.
* Removes the core WordPress user sitemap to reduce public author enumeration.
* Replaces revealing WordPress login errors with a generic error message.
* Keeps REST user endpoints available to authenticated users.
* Does not collect, transmit, or share data with external services.

No external account, API key, or third-party service is required.

== Settings ==

Go to **Settings > User Enumeration Protection**.

The **Hide public author archives** option controls whether normal `/author/username/` archive pages are available.

When enabled, public author archive URLs return 404.

When disabled, normal author archives remain available. Numeric `?author=ID` enumeration remains blocked regardless of this setting.

== Installation ==

1. Upload the plugin ZIP from **Plugins > Add New > Upload Plugin**, or upload the plugin folder to `/wp-content/plugins/`.
2. Activate **FormCourier User Enumeration Protection**.
3. Open **Settings > User Enumeration Protection**.
4. Choose whether public author archives should be hidden.

For a quick test, open `/wp-json/wp/v2/users` in a private or incognito browser window. The request should return HTTP 403.

A request such as `/?author=1` should return 404.

== Frequently Asked Questions ==

= Does the plugin disable the WordPress REST API? =

No. It only blocks the core WordPress REST API user endpoints for unauthenticated visitors. Other REST API routes remain available.

= Can I keep author archive pages enabled? =

Yes. Disable **Hide public author archives** in the plugin settings. Normal `/author/username/` pages will remain available, while numeric `?author=ID` enumeration stays blocked.

= Does this plugin change WordPress usernames or passwords? =

No. It does not modify user accounts, usernames, passwords, roles, or capabilities.

= Does this plugin prevent brute-force attacks? =

No. It reduces common user-enumeration signals. Use strong passwords, two-factor authentication, and login rate limiting as separate security measures.

= Does the plugin send any data to FormCourier or another service? =

No. The plugin works locally on the WordPress site and does not send data to external services.

== Privacy ==

This plugin does not collect, store, transmit, or share personal data with any external service.

The plugin stores one WordPress option that controls whether public author archives are hidden. This option is removed when the plugin is uninstalled.

== Changelog ==

= 1.1.2 =
* Added WordPress and PHP requirement headers to the main plugin file.
* Added uninstall cleanup for the plugin setting.
* Expanded the WordPress.org readme with FAQ and privacy information.
* Prepared plugin metadata for WordPress.org directory submission.

= 1.1.1 =
* Removed plugin and author website links from the plugin header.
* Added a direct Settings link on the Plugins screen.

= 1.1.0 =
* Added a settings page under WordPress Settings.
* Added an option to enable or disable public author archives.
* Numeric `?author=ID` enumeration remains blocked regardless of the archive setting.

= 1.0.1 =
* Improved author enumeration blocking to return 404 instead of redirecting.
* Improved compatibility with WordPress plugin checks.

= 1.0.0 =
* Initial release.
