How WordPress Exposes Your Admin Username & How to Fix It!
Home | What’s New | Start Here | Contact
Create a Website Blog
I received an alarming DM from one of my e-buddies, Darren of Small Biz Geek. This is what he said:
Say whaaaaaaaaat?
Now, I'm aware of the common practice of not using "admin" as your username and the nickname issue—always change your admin nickname to something unique to avoid displaying your actual username in comments. But I had already done that, and I wasn't aware of another vulnerability.
There's a significant one Darren discovered: the byline might expose your admin username. He figured out someone's login credentials for a new site just by hovering over their author byline.
All he did was hover over a link in my author byline.
This is how it works: Hover over the name in your byline (if visible), and you'll see a URL like http://yoursite.com/author/[name], where [name] is your admin username. This is dangerous! You're essentially revealing your WordPress admin login to potential hackers.
Hackers use scripts that attempt to guess passwords, often starting alphabetically and moving down the list, including numbers and symbols at the end. This process happens at a rate of millions of attempts per second due to automation. Using simple or dictionary words is a big no-no.
How to Hide Your Username in the Byline
This fix is straightforward and should take only 3-5 minutes:
- Backup your database first.
- Access your cpanel or hosting account control panel.
- Locate PHPMyAdmin or your host's equivalent database software.
- Find your WordPress database and navigate to the "wp_users" table.
- Update the
display_namecolumn for each user (including your admin) with a unique name, removing any potentially revealing information from the byline.
Darren also created a video tutorial explaining this process; follow his instructions for detailed visuals.