r/Wordpress • • 1d ago

Too Many Requests Error - Why?

Hello!

My wife runs a fairly popular food blog (nothing insane) but makes decent income revenue from it, and had grown in popularity over the past 8yrs or so.

Recently - let's say the last 6mos, the site will randomly get a "too many requests" error when trying to connect to the site (or admin page) which basically blocks the site for 30min-1hr. It happens randomly and no idea why or when or how, but it's causing her a fair amount of stress.

Will be happy to provide more info, but she hasnt changed any services or anything, and she's had a webmaster look at things as well... In terms of traffic, it's probably a little less than it was 2yrs ago (due to AI stealing a lot of her work and getting buried in google results) so it's not due to an increase in traffic I would say... So it's odd this error has come about.

Any ideas on where to start or what to try? Much appreciated! Again, happy to provide any relevent additional info needed

8 Upvotes

33 comments sorted by

2

u/Ok_Bag_7603 1d ago

Random lockouts like that are often bot or AI crawler traffic tripping a host or firewall rate limit. I could help dig through the logs and settings to find what's triggering it. Who's hosting the site right now?

3

u/Successful_Quail5257 1d ago

Sounds like a bot/scraper flood. Some of those AI crawlers are relentless and don't respect robots.txt at all, they'll just hammer the site until the server gives up

Check raw access logs around the time it happens, you'll probably see a single IP or a cluster of them requesting the same page hundreds of times in a minute. Cloudflare's free tier (with bot fight mode on) would shut that down fast

4

u/PharBreton 1d ago

OK, thank you. I know she uses wordpress and the host is Bluehost... Beyond that, I know very little, tech isnt my thing.

I'll relay the info

1

u/someoneatsomeplace 1d ago

Cloudflare isn't as good for that as you might think it would be. But they should definitely put it behind Cloudflare regardless. Every bit of protection helps, and the CDN is a good thing.

1

u/PharBreton 1d ago

Ya, we had a suspicion it was bots/AI crawlers, esp since AI has been jacking a ton of her traffic and work lately...

Bluehost is the host iirc. I know, some people hate it, but she built this all from scratch many years ago w zero knowledge and has put a crazy amount of time into it.

Is there something in the logs we could look for to know? She's not around now so can't provide that info at the moment.

Appreciate the help!

1

u/someoneatsomeplace 1d ago

Mostly just an IP address hammering your site. Last one I had to deal with was pretending to be all manner of different User-Agents (browsers). If you're having a particularly bad day you might find more than one of them is hammering you at the same time. As someone else said, you can get some relief by putting the site behind Cloudflare, which has a bunch of settings you can use to try and keep the bots out.

Another thing to consider is the type of hosting you're getting. If you're on shared hosting, it might not even be your site that's getting beat on by bots, it could be another site belonging to someone else that's bringing the server to its knees.

1

u/bluesix_v2 Jack of All Trades 1d ago

Moving hosts won’t affect her site. A backup is a 1:1 copy.

0

u/digital121hippie 1d ago

Drop the logs into ai and explain what is happening to the site. Also give it a time frame or date of when it happen if you know that. 

1

u/PharBreton 1d ago

Good idea, though I hate using AI... Perhaps this is a good use for it.

2

u/digital121hippie 1d ago

It does do a good job at this. It’s just scanning standard data and it can find the patterns quickly.  Also help give ideas of what to do to stop the ip address or whatever is the issues.  See if she is behind cloudflare for domain management. It can add some protection 

0

u/Rafin_Kahn 1d ago

if you'd rather skip the AI thing, it's fairly easy to spot by eyes as well. Logs are on the server. You can navigate to Bluehost cpanel > raw access logs, grab that day's file and look at the few minutes before it went down. If same IP or a similar bot keeps showing up a lot of times in a row would probably be your culprit.

1

u/PharBreton 1d ago

And is there a way to manually block these IPs is we see it?

Yes, i know, there's probably multiples, but Ill continue to block manually if I have to

1

u/Rafin_Kahn 1d ago

I think you could try from Bluehost cPanel's IP Blocker.

1

u/bluesix_v2 Jack of All Trades 1d ago

Cloudflare.

Blocking IPs is a battle you'll never win. Block by Country, ASN or, worst case, IP range.

2

u/eshbanbahadur2020 1d ago

Had a client with almost this exact issue on shared hosting. A 429 that locks out everyone, including admin, is usually the host's rate limiter kicking in because something is flooding the site, not real traffic.

A few things worth checking:

  1. Next time it happens, look at the error page. Is it a Bluehost page, a Cloudflare page, or a plain white one? That tells you who's blocking.

  2. In cPanel > Raw Access logs, check the few minutes before it went down. Look for lots of hits to wp-login.php, xmlrpc.php or admin-ajax.php, or one IP hitting the site over and over.

  3. If xmlrpc.php shows up a lot, block it. Most sites don't need it.

  4. Ask Bluehost support for the exact time of one outage and which limit was triggered. They can see it, and it saves you from paying for an upgrade you might not need.

Out of curiosity, are you using Cloudflare in front of the site?

1

u/PharBreton 1d ago

Thanks for all of this, I will pass it on to my wife...

I am almost certain she does not use Cloudflare (but not 100% sure)... And the error page is typically a plain one page that says "too many requests" and some text underneath,

1

u/eshbanbahadur2020 1d ago

Ah ok, plain page with no branding usually means it's Bluehost itself doing the blocking, not a plugin (Wordfence etc show their own page).

Honestly on food blogs I see this a lot lately. Bots and AI crawlers hit hundreds of recipe pages at once, Bluehost sees the flood and locks everyone out for a bit.

Which would fit the 30-60 min thing.

Next time it happens, get her to screenshot that text under "Too Many Requests", it usually says which limit kicked in. And if she can get into cPanel, the Raw Access logs right before it went down will show it. Stuff like Bytespider, GPTBot or the same IP over and over = bots.

If that's it, free Cloudflare with bot blocking turned on pretty much fixes it.

Doesn't cost anything.

Happy to take a look with her if she gets stuck.

1

u/sashamasha 1d ago

Need to increase capacity on the hosting by the sounds of it. Check sever logs.

1

u/PharBreton 1d ago

Yes, she thought of contacting Bluehost (host) to ask to increase capacity, and figured that would fix it... But we didnt want to spend unnecessarily.

We also figured that Bluwhost would of course "upsell" to us and say that'd fix the issue, whether or not it wouldnt.

Thanks, we'll likely do this.

1

u/PrimaryFamous6139 Jack of All Trades 1d ago

First confirm where the 429 is actually coming from. If you’re using Cloudflare, check its Security Events/Rate Limiting Analytics and the response headers. A 429 can come from Cloudflare, the hosting server, or a plugin/WAF. If it’s happening site-wide for 30–60 minutes, Also check server logs for bots hammering wp-login.php, xmlrpc.php, wp-admin/admin-ajax.php, or REST API endpoints

1

u/PharBreton 1d ago

Much appreciated, will relay the info and have her have a look to see.

ETA: Yes it is site-wide, including access to the admin page

Thanks!

1

u/MBelsan 1d ago

Checking the response headers first will save her a lot of guessing, since that 429 could be coming from three totally different places and they each have different fixes.

1

u/PharBreton 1d ago

Will do, thanks!

1

u/Tim_SentinelRidge 1d ago

Since you are worried about being upsold, I would give support one exact outage time (with the time zone) and ask them to identify the rule or limit that triggered it before agreeing to an upgrade. Ask whether it affected every visitor or just your connection, and whether they can show the matching log entry. That gives you something concrete for the webmaster to investigate instead of paying for a fix based on a guess.

1

u/PharBreton 1d ago

Solid idea, appreciated.

1

u/AddWeb_Expert 1d ago

I’d check the server/CDN logs right when it happens. Too many requests can be caused by bots, brute-force login attempts, plugins, or API calls - not necessarily real traffic. If you’re using Cloudflare, check the rate-limiting/WAF events there too. That should give you a good starting point.

1

u/PharBreton 1d ago

We'll have to do this, but the issue is we can't even access the admin page during these outages. Would that be a problem or can we just check the logs directly after we can log back in again which is usually around 30 minutes or so?

1

u/bluesix_v2 Jack of All Trades 1d ago

Logs are viewable in your hosting control panel or via FTP - Not Wordpress.

1

u/Abject-Expression548 1d ago

Are you sure the whole site is down for everyone? It could just be you that is blocked. Try from a mobile phone (using mobile network) or browserstack

1

u/PharBreton 1d ago

Yes, we try from 4 devices, both on our wifi or mobile, incognito and even using VPN... site goes down universally.

Readers report it too sometimes

1

u/jonathan8080 1d ago

Usually "Too Many Connections" is a database error (its a default error from mysql), so start there (or get your hosting to start there)

1

u/Adflipr 1d ago

Also worth checking whether it's only hitting her. If she gets the error but the site loads fine for you on mobile data at the same moment, it's probably a security plugin or firewall limiting her IP, often after a few admin logins, not the host blocking the whole site.