I'm not trying to give you bad rep' or anything, just wanted to know.
But, the full path isn't really a security vulnerability you know?
It's easy to get a username from any Linux account, host normally use the first six letters of the domain, so it's quite easy.
Also, say a game's name is "unknown", people choose that name as the user account, ad hosts shortens it, making it "unknow" - simple.
Just a few words of advice, it's just not professional to have script errors on your website, but is secure in most ways to display a username, depending on the hosting providers server setup.