WordPress 429 Too Many Requests: Fix the Rate Limit (2026)
Disclosure: some links on this page are affiliate links. We may earn a commission at no extra cost to you. How we test and rate hosts.
A 429 is your server slamming the door on excess requests. Something - a bot, a plugin, or a misconfigured cron - is hammering it past the allowed rate. The fix isn't "wait"; it's finding what's making all those requests and shutting it down. Six steps, in order.
1. Identify What's Hammering
The access log names the culprit. In cPanel > Metrics > Raw Access, look for repeating patterns:
- -Hundreds of POSTs to
wp-login.phporxmlrpc.phpfrom rotating IPs = brute force (fix 3) - -Requests to the same URL every few seconds = a plugin polling something (fix 2)
- -Hits from a single user-agent like "AhrefsBot" or "GPTBot" nonstop = crawler abuse (fix 5)
2. Deactivate Plugins
Plugins that call external APIs on every page load - rank trackers, social feeds, some analytics dashboards - trip rate limits fast. Rename wp-content/plugins to plugins_off via FTP, retest, then reactivate one by one. Also check for a runaway cron event: install WP Crontrol and look for a job scheduled every minute that never completes.
3. Lock Down wp-login and XML-RPC
Brute force on wp-login.php is the most common external cause. Three defenses, stack them:
- 1.Install a login limiter (Limit Login Attempts Reloaded) - 4 attempts then lockout
- 2.Restrict wp-login.php by IP in
.htaccessif you have a static IP:<Files wp-login.php> Require ip YOUR.IP.HERE </Files> - 3.Disable XML-RPC unless something needs it - add to
functions.php:add_filter('xmlrpc_enabled', '__return_false');
4. Check Your CDN and Security Rules
Cloudflare Rate Limiting or a security plugin's firewall can 429 legitimate traffic - including you. In Cloudflare: Security > WAF > Rate Limiting Rules; temporarily lower sensitivity or pause the rule to test. Same check in Wordfence/iThemes: the live traffic log shows exactly what got blocked and why.
5. Tame wp-cron and Crawlers
wp-cron fires on every pageview - under a crawler storm, it multiplies requests. Convert it to a real server cron (instructions here) so cron runs on a schedule, not on every hit. For abusive crawlers: throttle in robots.txt with Crawl-delay for polite bots, block the impolite ones by user-agent in your firewall.
6. When the Limit Is Just Too Low
If the 429s fire under normal traffic - admin work, a few editors saving posts - your host's rate limit is undersized for a real site. Ask support for the exact threshold (requests per minute and per IP). If the answer is "tight limits are our security model," that's a plan limitation, not a bug to fix.
Limits That Fit Real Sites
Rate limits should stop bots, not your editors. Bluehost's shared plans handle normal WordPress traffic without tripping 429s - and support can whitelist legitimate IPs when needed. From $3.99/mo.
Get Reliable HostingRelated: 403 forbidden error - hacked site recovery - 502 bad gateway fix - security checklist.
What are you building?
Tell us about your project so we can match the perfect hosting plan.
Hosting Cost Calculator
See exactly how much you'll spend on hosting over time. Compare Bluehost vs popular alternatives and discover your potential savings.
Used to calculate transaction fees (Shopify charges 2% on sales)
Frequently Asked Questions
What causes a 429 error in WordPress?
Your server is rate-limiting requests because something exceeded its threshold: brute-force login attempts on wp-login.php, XML-RPC abuse, a plugin making excessive API calls, wp-cron firing too often, or a crawler hitting the site aggressively.
Is a 429 error dangerous?
The error itself is protective - the server is shedding load. The concern is what's causing it: if it's brute-force bots hammering wp-login, that's an active attack pattern worth blocking, not just a quota to raise.
What's the fastest fix for 429?
Wait a few minutes - rate limits often reset. Then deactivate plugins via FTP (rename wp-content/plugins) and test. If you use Cloudflare, check Security > Rate Limiting rules for an overly aggressive threshold.
Why is wp-login.php causing my 429?
Brute-force bots fire hundreds of login attempts per minute. Fix: restrict wp-login.php by IP in .htaccess, install a login limiter (Limit Login Attempts Reloaded), or move login behind Cloudflare's bot fight mode.
Can a plugin cause a 429 error?
Yes - plugins polling external APIs on every page load (SEO rank trackers, social feeds, analytics dashboards) or broken cron events firing every minute are common culprits. Query Monitor or the server access log shows the repeating request.
How do I stop 429 errors permanently?
Block the abusive traffic at the edge: limit wp-login access, disable XML-RPC if unused, throttle aggressive bots via robots.txt or firewall rules, and make wp-cron a real server cron so it doesn't fire on every pageview.
Ready to launch?
Get Bluehost from $3.99/month with a free domain, free SSL, and 30-day money-back guarantee.
Related Articles
Bluehost vs Competitors: The Technical Deep Dive
We ran 47 benchmarks over 90 days. Here's the raw data on why Bluehost dominates.
Fix ERR_TOO_MANY_REDIRECTS in WordPress (2026): The 6 Real Causes
ERR_TOO_MANY_REDIRECTS means an infinite redirect loop. Match your Site URLs, fix Cloudflare SSL mode, reset .htaccess, kill plugin conflicts - step-by-step with code.
WordPress 403 Forbidden Error: 7 Fixes That Actually Work (2026)
403 means the server understood you but refuses to serve the page. Fix file permissions (755/644), regenerate .htaccess, kill security plugin blocks - in the right order.
Fix 502 Bad Gateway in WordPress (2026): Diagnose First, Then Fix
502 means the gateway got a bad response from your server - usually PHP timeouts, CDN issues, or overload. A 9-step diagnostic workflow from browser checks to server logs.
Fatal Error: Maximum Execution Time Exceeded - 6 Fixes (2026)
max_execution_time kills slow updates at 30-60s. Fix the culprit plugin/theme first, then raise the limit via wp-config, .htaccess or php.ini - with exact code.
HTTP Error Uploading Images in WordPress: 9 Fixes Ranked (2026)
The vague 'HTTP error' on image upload usually means memory limits or Imagick. Fix order: rename the file, bump memory, force GD library, check permissions - with code.