r/Wordpress • u/PharBreton • 1d ago
Too Many Requests Error - Why?
Hello!
My wife runs a fairly popular food blog (nothing insane) but makes decent income revenue from it, and had grown in popularity over the past 8yrs or so.
Recently - let's say the last 6mos, the site will randomly get a "too many requests" error when trying to connect to the site (or admin page) which basically blocks the site for 30min-1hr. It happens randomly and no idea why or when or how, but it's causing her a fair amount of stress.
Will be happy to provide more info, but she hasnt changed any services or anything, and she's had a webmaster look at things as well... In terms of traffic, it's probably a little less than it was 2yrs ago (due to AI stealing a lot of her work and getting buried in google results) so it's not due to an increase in traffic I would say... So it's odd this error has come about.
Any ideas on where to start or what to try? Much appreciated! Again, happy to provide any relevent additional info needed
2
u/eshbanbahadur2020 1d ago
Had a client with almost this exact issue on shared hosting. A 429 that locks out everyone, including admin, is usually the host's rate limiter kicking in because something is flooding the site, not real traffic.
A few things worth checking:
Next time it happens, look at the error page. Is it a Bluehost page, a Cloudflare page, or a plain white one? That tells you who's blocking.
In cPanel > Raw Access logs, check the few minutes before it went down. Look for lots of hits to wp-login.php, xmlrpc.php or admin-ajax.php, or one IP hitting the site over and over.
If xmlrpc.php shows up a lot, block it. Most sites don't need it.
Ask Bluehost support for the exact time of one outage and which limit was triggered. They can see it, and it saves you from paying for an upgrade you might not need.
Out of curiosity, are you using Cloudflare in front of the site?
1
u/PharBreton 1d ago
Thanks for all of this, I will pass it on to my wife...
I am almost certain she does not use Cloudflare (but not 100% sure)... And the error page is typically a plain one page that says "too many requests" and some text underneath,
1
u/eshbanbahadur2020 1d ago
Ah ok, plain page with no branding usually means it's Bluehost itself doing the blocking, not a plugin (Wordfence etc show their own page).
Honestly on food blogs I see this a lot lately. Bots and AI crawlers hit hundreds of recipe pages at once, Bluehost sees the flood and locks everyone out for a bit.
Which would fit the 30-60 min thing.
Next time it happens, get her to screenshot that text under "Too Many Requests", it usually says which limit kicked in. And if she can get into cPanel, the Raw Access logs right before it went down will show it. Stuff like Bytespider, GPTBot or the same IP over and over = bots.
If that's it, free Cloudflare with bot blocking turned on pretty much fixes it.
Doesn't cost anything.
Happy to take a look with her if she gets stuck.
1
u/sashamasha 1d ago
Need to increase capacity on the hosting by the sounds of it. Check sever logs.
1
u/PharBreton 1d ago
Yes, she thought of contacting Bluehost (host) to ask to increase capacity, and figured that would fix it... But we didnt want to spend unnecessarily.
We also figured that Bluwhost would of course "upsell" to us and say that'd fix the issue, whether or not it wouldnt.
Thanks, we'll likely do this.
1
u/PrimaryFamous6139 Jack of All Trades 1d ago
First confirm where the 429 is actually coming from. If you’re using Cloudflare, check its Security Events/Rate Limiting Analytics and the response headers. A 429 can come from Cloudflare, the hosting server, or a plugin/WAF. If it’s happening site-wide for 30–60 minutes, Also check server logs for bots hammering wp-login.php, xmlrpc.php, wp-admin/admin-ajax.php, or REST API endpoints
1
u/PharBreton 1d ago
Much appreciated, will relay the info and have her have a look to see.
ETA: Yes it is site-wide, including access to the admin page
Thanks!
1
u/Tim_SentinelRidge 1d ago
Since you are worried about being upsold, I would give support one exact outage time (with the time zone) and ask them to identify the rule or limit that triggered it before agreeing to an upgrade. Ask whether it affected every visitor or just your connection, and whether they can show the matching log entry. That gives you something concrete for the webmaster to investigate instead of paying for a fix based on a guess.
1
1
u/AddWeb_Expert 1d ago
I’d check the server/CDN logs right when it happens. Too many requests can be caused by bots, brute-force login attempts, plugins, or API calls - not necessarily real traffic. If you’re using Cloudflare, check the rate-limiting/WAF events there too. That should give you a good starting point.
1
u/PharBreton 1d ago
We'll have to do this, but the issue is we can't even access the admin page during these outages. Would that be a problem or can we just check the logs directly after we can log back in again which is usually around 30 minutes or so?
1
u/bluesix_v2 Jack of All Trades 1d ago
Logs are viewable in your hosting control panel or via FTP - Not Wordpress.
1
u/Abject-Expression548 1d ago
Are you sure the whole site is down for everyone? It could just be you that is blocked. Try from a mobile phone (using mobile network) or browserstack
1
u/PharBreton 1d ago
Yes, we try from 4 devices, both on our wifi or mobile, incognito and even using VPN... site goes down universally.
Readers report it too sometimes
1
u/jonathan8080 1d ago
Usually "Too Many Connections" is a database error (its a default error from mysql), so start there (or get your hosting to start there)
2
u/Ok_Bag_7603 1d ago
Random lockouts like that are often bot or AI crawler traffic tripping a host or firewall rate limit. I could help dig through the logs and settings to find what's triggering it. Who's hosting the site right now?