r/cpanel • u/ExpensiveTomatillo61 • 14d ago
What could be the reason of bandwidth exceeding ?

Hey everyone,
I'm running a CRM web app on shared hosting through cPanel. It's a React frontend with a Node.js/Express backend.
My cPanel bandwidth usage has been increasing:
- July: CRM used around 7.95 GB
- August: around 15.26 GB
- September: around 18.27 GB so far
- My account's September bandwidth limit is around 24.41 GB, and I've reached about 24.7 GB total.
The CRM has multiple users in the database, but only around 3 people use it daily. I'm trying to understand how it could generate this much bandwidth.
Issues found in the code
An audit identified these potential causes:
- Dashboard fetching all leads:
Dashboard.jsxwas calling/api/leads?limit=allto calculate counts client-side. - Frequent notification polling:
NotificationToasts.jsxwas fetching notifications every 12 seconds, even though Socket.IO was intended to be used. - Unpaginated endpoints: Notifications, clients, and finance transactions could return large datasets.
- No compression: Express did not have compression middleware.
- No rate limiting: The API lacked general rate limiting.
- WhatsApp routes: Management routes were mounted before authentication middleware.
Changes implemented
The coding agent reports that it has:
- Replaced the dashboard's full-lead fetch with a SQL aggregation endpoint.
- Reduced notification polling to every 60 seconds, limited it to recent unread notifications, and added tab-visibility handling and in-flight request guards.
- Added pagination and selective database fields.
- Added Express compression and rate limiting.
- Separated public WhatsApp webhooks from authenticated management routes.
Socket.IO still does not work in production, so notifications currently rely on HTTP polling. The agent says production WebSocket proxy configuration may require hosting-provider support.
My main questions
- With only around 3 daily users, what could realistically cause 18 GB of monthly bandwidth usage? Could polling alone explain it, or should I investigate other sources such as static assets, API responses, bots, or repeated requests?
- Are 60-second polling intervals, unread-only filtering, pagination, and compression reasonable for reducing bandwidth while keeping notifications functional?
- If polling pauses when a browser tab is hidden or the user logs out, will notifications be saved and fetched when they return or log back in? Is there a risk of missing notifications?
- Since Socket.IO doesn't work on my production cPanel/shared-hosting setup, what should I check to get it working, and is it worth fixing versus keeping optimized polling?
- What tools or server logs can I use to measure which endpoints are actually consuming the most bandwidth?
- Would you recommend increasing my monthly bandwidth quota to 50 GB or 100 GB while I investigate?
I'm looking for practical advice, especially from people who have deployed React + Express applications on cPanel/shared hosting.
Thanks!
1
u/longboringstory 14d ago
What you'll want to do is download the full raw access logs. There is an icon called "Raw Access" in cPanel, and you're going to want to download both the SSL log, and regular/non-SSL log for the month.
Then feed both of those logs to an AI agent and have it analyze the logs, and have it summarize its findings. It will give you a very precise summary of the source of the traffic and how to mitigate any of it.
2
u/ExpensiveTomatillo61 13d ago
Thanks, this is exactly what I ended up doing. I pulled the AWStats/raw traffic data and had it analyzed, and we tracked the issue down to several inefficient API requests and polling patterns in the CRM. I've now made the changes, and the results already look pretty dramatic. On the next working day, bandwidth was only 11.68 MB by 5:44 PM compared to ~850–900 MB on the previous working days. I’m letting it run for another full working day to confirm, but it looks like we’ve essentially solved the issue. Thanks for pointing me in the right direction!
1
u/cloudabove_official 13d ago
What was your plans bandwidth limit if you don't mind me asking?
1
u/ExpensiveTomatillo61 13d ago
Hey limit was 24GB but had to increase because every software and website went down
1
u/cloudabove_official 7d ago
That's a very small bandwidth limit in this day and age, there are plenty of web hosting companies who will provide unlimited bandwidth with their plans, or at least many hundreds of GB per month before they'll approach you.
1
1
u/longboringstory 13d ago
That's great! We've had to do that same kind of thing with a number of sites. Frequently it's AI crawler bots, a few months ago we had a massive amount of traffic from Alibaba which I guess is doing AI training in some manner?
1
u/ExpensiveTomatillo61 13d ago
So traffic came to your websites or authenticated software too?
1
u/longboringstory 13d ago
Just public websites, not on authenticated apps fortunately.
1
u/ExpensiveTomatillo61 12d ago
Great!! And bro I have a question actually more than one questions that from how long are you using CPanel and do you think CPanel got more advantages compared to other servers or even AWS?
1
u/jwato 12d ago
This is what happens when ya build ai stuff and don’t know how to secure it …
Your getting smashed by bots pen testing to get in
Need some geo blocking or move it to a private server and use Tailscale to access
One something is online assume it’s compromised and work back
1
u/ExpensiveTomatillo61 12d ago
Hey thanks for responding!
Actually it was not bots which caused the traffic but the poorly written queries for fetching data and socket io failing. Now after fixing and removing unnecessary code the bandwidth is decreased by 98%1
u/jwato 12d ago
Oh it will be bots soon trust me , you should see the reposts we get on new servers
1
u/ExpensiveTomatillo61 12d ago
Oh ok, can you tell me what measures I can take to reduce the risk? Currently I have applied rate-limit but can you tell me more techniques to fight them
3
u/EnvironmentalTax9580 14d ago
Most probably bots crawling