Hacker News new | ask | show | jobs
by claudiulodro 687 days ago
WordPress doesn't consider usernames as a secret[1], so under that logic it is totally fine to say whether a username exists when trying to log in.

[1] https://core.trac.wordpress.org/ticket/20235#comment:7