Hide WordPress Usernames Without Removing Author Pages
- WordPress author archives are useful on genuine multi-author websites.
- Readers may want to click an author's name, see their previous work, browse additional pages of posts, or subscribe to an author feed. Disabling author archives entirely would remove that functionality.
- The problem is that WordPress author URLs can reveal predictable user identifiers.
- A standard URL might look like:
<example.com/author/johnsmith//> - If that slug corresponds closely to a username or another account identifier, the public URL can provide unnecessary information to bots and visitors.
- Hide Author URLs takes a middle-ground approach. The author archive remains available, but its public route no longer needs to expose the normal author slug.
- Instead, WP PowerSuite assigns the user a random hexadecimal identifier and uses that identifier throughout supported public author URLs.
Keep SEO and Author Navigation Intact
- Obfuscating an author URL is different from disabling it.
- The author archive still exists as a normal public WordPress page, so websites that intentionally maintain author profiles and author-based content navigation can continue using them.
- WordPress-generated author links are updated to use the new obfuscated URL. Pagination and author feeds also follow the same public identifier.
- This makes the module particularly suitable for blogs, magazines, editorial sites, and other multi-author WordPress websites where author archives provide useful content but exposing the original slug is unnecessary.
- Because enabling the module changes live author URLs, existing links to old author paths will stop working. This should therefore be treated as a URL-structure change rather than a purely cosmetic setting.
Replace Predictable Slugs With Random IDs
- Each WordPress user receives a random 10-character hexadecimal slug.
- Instead of:
the public URL becomes something similar to:</author/editor-name/>< /author/7f3a91d2c4/> - The identifier is generated from random data rather than being derived from the username, email address, display name, or user ID.
- Existing users are backfilled automatically in controlled batches, while newly registered users receive an identifier when their account is created.
- Unknown random IDs return a 404, and ordinary non-hex author names no longer resolve to author archives while the module is enabled.
Reduce Basic WordPress User Enumeration
- One common WordPress enumeration technique involves trying author IDs through requests such as:
<?author=1> - WordPress may normally resolve that ID to an author archive, indirectly revealing account information.
- With Hide Author URLs enabled, these numeric author requests do not expose the obfuscated archive. They are redirected to the homepage instead.
- The module also changes the slug value exposed through supported REST user responses to the randomized identifier.
- If WP PowerSuite's Disable REST API (Public) module is not enabled, Hide Author URLs additionally blocks anonymous requests to the WordPress users REST endpoint. Logged-in users can still access appropriate REST user information, but the public slug remains obfuscated.
- This provides useful hardening, but it should not be treated as complete protection against every possible form of WordPress user enumeration.
Hide the URL, Not the Author
- The module deliberately focuses on the author URL.
- It does not hide the author's display name from blog posts, comments, author boxes, structured data, theme templates, or other visible areas of the website.
- It also does not rename WordPress usernames, change login credentials, or alter account permissions.
- This distinction is important. The goal is not to make a public author anonymous. The goal is to prevent the public archive URL itself from directly exposing the normal WordPress author slug.
- If you do not want author pages to exist at all, Disable Author Archives is the more appropriate module.
Hide Author URLs or Disable Author Archives?
- WP PowerSuite offers both options because different websites have different requirements.
- Use Hide Author URLs when author archives are valuable and should remain accessible, but you want their public slugs obfuscated.
- Use Disable Author Archives when the site does not need public author archives at all.
- The two modules conflict and should not be enabled together.
- For example, a multi-author publication may benefit from Hide Author URLs because readers still need author pages. A business website with only internal staff accounts may be better suited to Disable Author Archives.



