EnumGuard is a focused WordPress plugin that stops attackers from confirming that a username or user ID exists. WordPress still prints those signals by default; EnumGuard closes the usual paths without hiding display names on posts.
Under Settings EnumGuard you get three tabs:
Protections covered:
?author=1) that would otherwise redirect to the author archiveauthor-{id} / author-{nicename} body, post, and comment CSS classes/wp-sitemap-users-1.xml)/wp-json/wp/v2/users (including ?rest_route=)_embed author payloads and author link headersauthor_url / author_nameRecommended protections ship enabled. Gutenberg still reaches the users REST API for logged-in editors. Display names stay visible. Login and reset protections also cover WooCommerce forms when WooCommerce is active. XML-RPC can be turned off completely if you do not need Jetpack, pingbacks, or the WordPress mobile app.