Opens in a new tab
Turquoise abstract wavy W logo on a black background
Turquoise abstract wavy W logo on a black background
White WP PowerSuite logo on a black background
White WP PowerSuite logo on a black background
[wpps_ai_summarize]
On This Page
Last updated: 01/09/2026

Block Usernames

Blocks risky default usernames during registration so bots have fewer easy targets.

Overview

Prevent new WordPress accounts from registering or being created with common, predictable, or unwanted usernames.

Block Usernames extends WordPress’s native illegal username system with a ready-made blocklist and your own custom entries. Common usernames such as admin, administrator, root, and support can be reserved automatically, while you can add up to 500 additional usernames based on your site’s requirements.

The protection applies across normal WordPress registration, administrator-created users, REST user creation, username changes, and supported WP PowerSuite account workflows.

Block Usernames is a Free security module in WP PowerSuite.

Solid black square
Solid black square
Who is this for?
  • WordPress sites that allow public user registration
  • WooCommerce, membership, and community websites creating user accounts
  • Agencies applying consistent account security rules across client sites
  • Administrators who want to reserve predictable or sensitive usernames
  • Multi-user websites that need control over which login names can be created

Features

Block Common WordPress Usernames
Automatically reserve common usernames such as admin, administrator, root, test, demo, support, and webmaster.
Create Your Own Username Blocklist
Add up to 500 custom usernames, one per line, to prevent those login names from being assigned to new accounts.
Works With WP PowerSuite OAuth
Supported OAuth Login account workflows also honor the blocklist when assigning WordPress usernames.
Uses WordPress's Native Username Restrictions
Blocked names are added to WordPress's own illegal_user_logins system rather than being enforced only through a custom registration form.

Prevent Predictable WordPress Usernames From Being Created

A WordPress login requires both a username and password. When an account uses an extremely predictable username such as admin, anyone attempting to guess its credentials already has one part of that combination.
That does not mean a username should be treated as a secret or that changing admin suddenly makes an account secure. Strong passwords, Two-Factor Authentication, and appropriate login protections remain far more important. However, there is usually little reason to continue creating privileged or public accounts with obvious generic login names when more distinctive usernames are available.
Block Usernames lets you establish a simple account-naming policy directly in WordPress. Once a username is on the effective blocklist, WordPress will reject it when someone attempts to create or assign that login through supported account-management workflows.
This is particularly useful on sites with public registration, multiple administrators, client-managed accounts, or automated account creation where you cannot personally review every username before it enters the system.

Apply the Blocklist Across WordPress, Not Just One Form

A username restriction is much less useful if it protects only the public registration form.
WordPress accounts can be created or modified through several different interfaces. A visitor may register from the frontend, an administrator can create a user through Users → Add New, an application may create users through REST, and another plugin may use WordPress's normal account APIs.
Block Usernames integrates with WordPress's native illegal_user_logins filter. This is the same username restriction mechanism WordPress itself uses across supported user-creation and username-validation workflows.
As a result, the policy is not tied to one particular form. The same blocked-name list can apply to frontend registration, administrator-created accounts, REST user creation, and supported username changes.
This provides a more consistent rule: if a username has been reserved, supported WordPress account workflows should not assign it.

Use Cases

  • Prevent the admin Username
    Reserve common administrator names so newly created WordPress accounts must use a different login.
  • Public Registration Websites
    Apply a consistent username policy when visitors can create their own WordPress accounts.

Frequently Asked Questions

Related Modules

Tell modern browsers to enforce sensible safety rules—like blocking sneaky scripts and iframe tricks—with strong defaults you can tighten further for HSTS...
Disabled
Disables WordPress application passwords site-wide: blocks REST/XML-RPC login with app tokens and hides the profile UI. Normal account passwords and logged-in REST...
Disabled
Keep a clear record of important dashboard activity—who logged in, what changed, and when—so you can investigate issues or stay audit-ready without...
Disabled
Ask a quick math question, custom prompt, or image check before someone can submit a form or log in. Everything runs on...
Disabled
Remove the dashboard screens that let anyone edit theme or plugin code from the browser—one less disaster if an account is compromised.
Disabled
Removes WordPress version from public HTML generator tags, feed generator output, and the admin footer. Does not change ver= on script and...
Disabled
Stops old-style trackbacks and pingbacks that often bring spam or junk alerts.
Disabled
Bot protection with Cloudflare Turnstile on logins, forms, comments, and WooCommerce—low hassle for real people.
Disabled
Automatically protects visible email addresses and mailto links from basic spam bots by safely encoding them while keeping them clickable for visitors.
Disabled
Google reCAPTCHA on logins, forms, comments, and WooCommerce to block bots and spam signups.
Disabled