Technical

WordPress 429 Too Many Requests: Fix the Rate Limit (2026)

By Daniel Reyes•October 8, 2026•3 min read

Disclosure: some links on this page are affiliate links. We may earn a commission at no extra cost to you. How we test and rate hosts.

Our top pick for most WordPress sites
Bluehost: free domain, free SSL, 24/7 support, 30-day money-back guarantee.
Check Bluehost Deal →

A 429 is your server slamming the door on excess requests. Something - a bot, a plugin, or a misconfigured cron - is hammering it past the allowed rate. The fix isn't "wait"; it's finding what's making all those requests and shutting it down. Six steps, in order.

1. Identify What's Hammering

The access log names the culprit. In cPanel > Metrics > Raw Access, look for repeating patterns:

  • -Hundreds of POSTs to wp-login.php or xmlrpc.php from rotating IPs = brute force (fix 3)
  • -Requests to the same URL every few seconds = a plugin polling something (fix 2)
  • -Hits from a single user-agent like "AhrefsBot" or "GPTBot" nonstop = crawler abuse (fix 5)

2. Deactivate Plugins

Plugins that call external APIs on every page load - rank trackers, social feeds, some analytics dashboards - trip rate limits fast. Rename wp-content/plugins to plugins_off via FTP, retest, then reactivate one by one. Also check for a runaway cron event: install WP Crontrol and look for a job scheduled every minute that never completes.

3. Lock Down wp-login and XML-RPC

Brute force on wp-login.php is the most common external cause. Three defenses, stack them:

  1. 1.Install a login limiter (Limit Login Attempts Reloaded) - 4 attempts then lockout
  2. 2.Restrict wp-login.php by IP in .htaccess if you have a static IP:
    <Files wp-login.php> Require ip YOUR.IP.HERE </Files>
  3. 3.Disable XML-RPC unless something needs it - add to functions.php:
    add_filter('xmlrpc_enabled', '__return_false');

4. Check Your CDN and Security Rules

Cloudflare Rate Limiting or a security plugin's firewall can 429 legitimate traffic - including you. In Cloudflare: Security > WAF > Rate Limiting Rules; temporarily lower sensitivity or pause the rule to test. Same check in Wordfence/iThemes: the live traffic log shows exactly what got blocked and why.

5. Tame wp-cron and Crawlers

wp-cron fires on every pageview - under a crawler storm, it multiplies requests. Convert it to a real server cron (instructions here) so cron runs on a schedule, not on every hit. For abusive crawlers: throttle in robots.txt with Crawl-delay for polite bots, block the impolite ones by user-agent in your firewall.

6. When the Limit Is Just Too Low

If the 429s fire under normal traffic - admin work, a few editors saving posts - your host's rate limit is undersized for a real site. Ask support for the exact threshold (requests per minute and per IP). If the answer is "tight limits are our security model," that's a plan limitation, not a bug to fix.

Limits That Fit Real Sites

Rate limits should stop bots, not your editors. Bluehost's shared plans handle normal WordPress traffic without tripping 429s - and support can whitelist legitimate IPs when needed. From $3.99/mo.

Get Reliable Hosting

Related: 403 forbidden error - hacked site recovery - 502 bad gateway fix - security checklist.

Find Your Perfect Hosting Plan

What are you building?

Tell us about your project so we can match the perfect hosting plan.

Question 1 of 425% complete
Interactive Tool

Hosting Cost Calculator

See exactly how much you'll spend on hosting over time. Compare Bluehost vs popular alternatives and discover your potential savings.

Used to calculate transaction fees (Shopify charges 2% on sales)

Shopify Basic (3yr)
$1,044
Bluehost (3yr)
$444
You Save
$600
58% less than Shopify Basic

Frequently Asked Questions

What causes a 429 error in WordPress?

Your server is rate-limiting requests because something exceeded its threshold: brute-force login attempts on wp-login.php, XML-RPC abuse, a plugin making excessive API calls, wp-cron firing too often, or a crawler hitting the site aggressively.

Is a 429 error dangerous?

The error itself is protective - the server is shedding load. The concern is what's causing it: if it's brute-force bots hammering wp-login, that's an active attack pattern worth blocking, not just a quota to raise.

What's the fastest fix for 429?

Wait a few minutes - rate limits often reset. Then deactivate plugins via FTP (rename wp-content/plugins) and test. If you use Cloudflare, check Security > Rate Limiting rules for an overly aggressive threshold.

Why is wp-login.php causing my 429?

Brute-force bots fire hundreds of login attempts per minute. Fix: restrict wp-login.php by IP in .htaccess, install a login limiter (Limit Login Attempts Reloaded), or move login behind Cloudflare's bot fight mode.

Can a plugin cause a 429 error?

Yes - plugins polling external APIs on every page load (SEO rank trackers, social feeds, analytics dashboards) or broken cron events firing every minute are common culprits. Query Monitor or the server access log shows the repeating request.

How do I stop 429 errors permanently?

Block the abusive traffic at the edge: limit wp-login access, disable XML-RPC if unused, throttle aggressive bots via robots.txt or firewall rules, and make wp-cron a real server cron so it doesn't fire on every pageview.

Ready to launch?

Get Bluehost from $3.99/month with a free domain, free SSL, and 30-day money-back guarantee.

Start for $3.99 →

Related Articles