Recommended Free Tools
Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
To restrict usernames in WordPress, choose the validation path that actually creates the account. On a standard site, add a denylist with the illegal_user_logins filter and use registration_errors or register_post for custom rules. WordPress multisite has a separate signup validator and filters. Plugins can add pattern, character, and length settings, but may not affect administrator-created users or membership forms that bypass WordPress’s normal hooks.
Decide what you are trying to restrict
There are two different jobs:
- Future registrations: prevent visitors from choosing names that are reserved, misleading, or incompatible with your naming policy.
- An existing administrator login: rename an obvious account such as
admin. This is account hardening, not registration validation.
Restricting a name does not make an account secret. The WordPress Hosting Handbook states that usernames and user IDs are not considered private or secure information; the password verifies identity. Use strong, unique passwords, two-factor authentication, and login throttling as security controls.
Standard WordPress registration
For the normal WordPress registration route, register_new_user() validates the submitted username before creating the account. It exposes two useful extension points:
Free tools Windows power users keep installed
One-click scans. No signup required.
register_postlets code inspect or alter registration data during processing.registration_errorsreceives the accumulatedWP_Error. Adding an error aborts registration.
Use illegal_user_logins for a straightforward list of names that nobody may register. Put the code in a site-specific plugin or a child theme’s maintained code file rather than editing WordPress core.
#1 Best Overall
<?php
add_filter( 'illegal_user_logins', function ( $usernames ) {
$usernames[] = 'admin';
$usernames[] = 'administrator';
$usernames[] = 'support';
$usernames[] = 'security';
return array_unique( $usernames );
} );
Use lowercase entries and test the actual registration form. A denylist only addresses exact names; it does not automatically block variations such as admin-team or support1.
Block patterns, characters, or length
For rules beyond a fixed list, attach a callback to registration_errors. The callback should add a clear message to the supplied WP_Error object when the username fails your policy.
<?php
add_filter( 'registration_errors', function ( $errors, $sanitized_user_login, $user_email ) {
if ( preg_match( '/^support(?:[-_]|$)/i', $sanitized_user_login ) ) {
$errors->add( 'username_reserved', 'Usernames beginning with “support” are reserved.' );
}
if ( ! preg_match( '/^[a-z0-9._-]+$/i', $sanitized_user_login ) ) {
$errors->add( 'username_characters', 'Use only letters, numbers, periods, underscores, and hyphens.' );
}
return $errors;
}, 10, 3 );
Choose a rule that matches your site’s identity and accessibility needs. Overly broad pattern checks can reject legitimate names, while a short denylist cannot enforce a complete naming standard. Test duplicate names, uppercase input, whitespace, non-Latin characters, and error display on the public form.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Rank #2
WordPress multisite signup
Multisite does not use exactly the same signup path as a single site. wpmu_validate_user_signup() performs its own checks, including stripping whitespace, validating the username character set, checking illegal names stored in the network options, and applying multisite filters.
The documented multisite defaults reserve these names:
| Reserved by the documented multisite defaults | Why this matters |
|---|---|
www, web, root, admin |
Common infrastructure or administrative names |
main, invite, administrator |
Names used by network or administrative functions |
These are defaults in the documented multisite validation path, not a promise that every registration plugin enforces the same set. If your network uses a custom signup form, verify that it calls the multisite validator and that your filters run.
Multisite implementation checklist
- Confirm that the site is a network installation and identify whether users sign up through the built-in network flow.
- Use the multisite validation filters, including
wpmu_validate_user_signup, for network-specific rules. - Review the network’s illegal-name option and add names that your organization reserves.
- Test signup as an unauthenticated visitor and confirm that the error appears before account creation.
- Retest after activating membership or community plugins; their forms may implement their own validation.
When a plugin is appropriate
A plugin is useful when non-developers need an administration screen for naming policy. The plugin listing for Restrict Usernames describes controls for reserved prefixes and patterns, spaces, required substrings, and minimum or maximum length.
That listing also states two important limits: the plugin applies to visitor self-registration, not users created in wp-admin, and some membership plugins can bypass the checks and hooks on which it relies. Its displayed tested version, WordPress 4.9.29, is an old compatibility declaration, so check the plugin’s current release, support activity, and compatibility with your installed WordPress version before relying on it.
Restrict Usernames Emails Characters advertises configurable restrictions for usernames, email addresses, and symbols. Its changelog includes a low-risk security fix and historical tested-version statements. Inspect the current release and support history rather than treating those historical declarations as present-day compatibility evidence.
Rank #4
Plugin selection checklist
- Does it validate the exact form your visitors use?
- Does it apply to only self-registration, or also accounts created by administrators and imports?
- Can it express your rule: denylist, character set, prefix, required text, or length?
- Is it maintained for your WordPress and PHP versions?
- Does it return a usable error instead of silently changing the submitted username?
- Can you disable it safely and recover accounts if it conflicts with a membership plugin?
Renaming an existing administrator account
Blocking future use of admin does not rename an account that already exists. For an existing, easily guessed administrator login, the WordPress hardening guidance recommends renaming the administrative account. Plan a recovery route first: keep another verified administrator account or a tested recovery method, and take a database backup.
A database-level rename can be performed by updating the user record’s user_login value, but the exact SQL depends on your table prefix and database tooling. Do not paste a generic query without replacing the prefix and confirming the target user. Afterward, sign out and confirm that the new login works, scheduled tasks and integrations still authenticate, and no plugin stores the old login as a required identifier.
Renaming improves the account’s naming policy, but it is not a substitute for a strong password, two-factor authentication, least-privilege roles, and rate-limited login protection.
Best Value
Why a hidden username is not a security boundary
Many WordPress sites expose user information through standard endpoints such as /wp-json/wp/v2/users, depending on configuration and plugins. The Hosting Handbook explicitly says that a username identifies an account; password verification establishes that the person signing in is authorized. Therefore, do not claim that a unique or hidden username prevents password attacks.
Prioritize these controls instead:
- Use a long, unique password stored in a password manager.
- Enable two-factor authentication for administrators.
- Limit login attempts or use a reputable throttling control.
- Remove unused administrator accounts and review roles regularly.
- Keep WordPress, plugins, and themes updated.
Troubleshooting failed restrictions
The rule works on one form but not another
The second form probably uses a plugin-specific registration process or bypasses the core hooks. Identify the code path, then use that plugin’s documented validation API or replace the form with one that invokes WordPress validation.
Administrators can still create a blocked name
Many restriction plugins intentionally cover visitor self-registration only. Enforce the same policy in your administrator workflow, or add an administrative validation layer; do not assume a public-registration plugin governs wp-admin account creation.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchUsers receive no useful error
Ensure your callback adds a WP_Error entry and returns the object. Check that the callback priority and accepted argument count match the hook, then test with debugging enabled in a staging site.
Multisite accepts a name that single-site testing rejected
Check which signup function is running. Multisite validation has its own defaults and filters, and a custom network form may not call it.
Quick Recap
Recommended decision path
| Your situation | Best starting point | Principal limitation |
|---|---|---|
| Built-in single-site registration | illegal_user_logins; add registration_errors for complex rules |
Only affects flows that use core registration |
| WordPress multisite signup | wpmu_validate_user_signup() and multisite filters |
Custom signup plugins may bypass the path |
| Non-developer needs configurable patterns | A maintained restriction plugin | Coverage and compatibility are flow-specific |
| Existing obvious administrator login | Careful account rename with a recovery route | Does not hide the username or replace authentication controls |
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

