# insidetrust/statistically-likely-usernames

Wordlists for creating statistically likely username lists for use in password attacks and security testing. Used for pentesting for over 10 years with amazing results.

Repository: https://github.com/insidetrust/statistically-likely-usernames
Canonical: https://ross.abutalabs.com/products/statistically-likely-usernames
Language: Python
License Family: other
Last push: 2026-02-16T17:20:44+00:00

## Health v2 (maintenance only)
Score: 62/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 67, release rhythm 35, longevity 100
- inputs: {"age_days": 3853, "days_push": 198, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1386, forks 163 (observed 2026-08-28T04:04:35.002546+00:00)

## What it is
A collection of wordlists for generating statistically likely usernames for use in password attacks, username enumeration, and authorized security testing. Lists are derived from US Census and Facebook name data and ordered by statistical likelihood.

## Use cases
- generate likely username lists for password spraying
- enumerate valid usernames during a pentest
- run horizontal password attacks against a network
- build custom username wordlists in specific formats
- guess default service and test account names

## When to choose
- you are performing an authorized penetration test and need efficient username guesses
- you want to prioritize username candidates by statistical likelihood
- you need pre-built lists covering common username formats like jsmith or john.smith

## When to avoid
- you need general-purpose password wordlists rather than usernames
- your use case is not authorized security testing
- you need a tool rather than static wordlist data

## Facets
- artifact type: dataset
- maturity: stable
- function: security, data-generation
- domain: security, penetration-testing
- platform: cross-platform
- tags: wordlists, username-enumeration, password-attacks, pentesting, osint

## Member repositories
- insidetrust/statistically-likely-usernames (main) score 62

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:35.002546+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:39:54.622402+00:00, confidence not recorded.
  - readme: https://github.com/insidetrust/statistically-likely-usernames (fetched 2026-08-28T04:04:35.002546+00:00, sha c2f6bb836ce6)
- Data as of 2026-08-30T08:39:29.467469+00:00.
