On This Page
On This Page
Block Usernames
Overview
Prevent new WordPress accounts from registering or being created with common, predictable, or unwanted usernames.
Block Usernames extends WordPress’s native illegal username system with a ready-made blocklist and your own custom entries. Common usernames such as admin, administrator, root, and support can be reserved automatically, while you can add up to 500 additional usernames based on your site’s requirements.
The protection applies across normal WordPress registration, administrator-created users, REST user creation, username changes, and supported WP PowerSuite account workflows.
Block Usernames is a Free security module in WP PowerSuite.

- WordPress sites that allow public user registration
- WooCommerce, membership, and community websites creating user accounts
- Agencies applying consistent account security rules across client sites
- Administrators who want to reserve predictable or sensitive usernames
- Multi-user websites that need control over which login names can be created
Features
Block Common WordPress Usernames
Create Your Own Username Blocklist
Works With WP PowerSuite OAuth
Uses WordPress's Native Username Restrictions
Use Cases
- Prevent the admin UsernameReserve common administrator names so newly created WordPress accounts must use a different login.
- Public Registration WebsitesApply a consistent username policy when visitors can create their own WordPress accounts.
Frequently Asked Questions
What does Block Usernames do?
It prevents selected usernames from being assigned through supported WordPress registration, user creation, REST, and username-change workflows.
Which usernames are blocked by default?
The default list includes:
admin, administrator, root, test, demo, support, and webmaster.Can I disable the default list?
Yes. You can turn it off and use only your own custom blocked usernames.
No. Blocking admin also blocks Admin and ADMIN.Can I add custom usernames?
Yes. You can add up to 500 custom entries, one username per line.
Is matching case-sensitive?
No. Blocking admin also blocks Admin and ADMIN.
Will blocking admin also block admin1?
No. Matching is exact after WordPress username sanitization.
Does it work with public WordPress registration?
Yes. The module integrates with WordPress’s native illegal-login system used by supported registration workflows.
Does it apply to Users → Add New?
Yes. Administrator-created accounts also respect the blocked username list.
Does it apply to REST user creation?
Yes. Supported REST user creation uses the same WordPress username restriction.
Does it work with Username Changer?
Yes. WP PowerSuite’s Username Changer will not assign a username that is currently blocked.
Does it work with WP PowerSuite OAuth login?
Yes. Supported OAuth account creation and username assignment honor the effective blocked username list.
What happens if an existing user already has a blocked username?
Nothing happens to that account. Existing users are not renamed, disabled, deleted, or logged out.
Can an existing admin user still sign in?
Yes. This module controls username assignment, not authentication for existing accounts.
Can WP PowerSuite automatically rename existing blocked usernames?
No. Review those accounts separately and use Username Changer when an intentional username change is appropriate.
Does it block similar-looking usernames?
Not automatically. The module uses exact matching and does not attempt to detect Unicode homoglyphs or visually similar names. Add any additional spellings you want blocked.
Does this prevent brute-force attacks?
No. Use Limit Login Attempts for repeated password attempts and consider Two-Factor Authentication for stronger account protection.
Does it hide usernames from author URLs?
No. Use Hide Author URLs or Disable Author Archives depending on whether public author archives should remain available.
Does it restrict REST API user enumeration?
No. Use Disable REST API when anonymous core REST access should be restricted.
Is Block Usernames free?
Yes. Block Usernames is a Free module included with WP PowerSuite.


