How to Fix WordPress Updating Failed Publishing Failed Error
This WordPress block editor error means your REST API is being blocked, preventing posts…
WordPress 429 Too Many Requests Error
A 429 Too Many Requests error means something — your browser, a plugin, or a bot — sent too many HTTP requests to your server in a short time window. Once a set threshold is crossed, the server stops processing new requests and starts rejecting them with a 429 response instead.
In WordPress, this error usually shows up in one of two ways: visitors see a 429 page when browsing your site, or you spot it in your browser’s DevTools Network tab when a plugin or REST API call gets throttled. Either way, the underlying mechanism is rate limiting — a traffic control system designed to protect your server from being overwhelmed.
The tricky part is that the 429 can originate from several different layers: your hosting provider, Cloudflare, a security plugin, or even a third-party API your plugins connect to. Identifying the exact source is your first job before touching anything else.
X-RateLimit-*, cf-ray (Cloudflare), or any server-specific header that names the rate-limiting party.
You should see: A response header that points to your host, Cloudflare, or a specific plugin as the source of the throttle.
You should see: The offending rule listed with its trigger count and the matched path, making it clear which URLs are being blocked.
You should see: The 429 responses stop appearing for your IP immediately after saving settings and clearing your site cache.
wp-config.php to stop WordPress from triggering cron tasks on every page load:
define('DISABLE_WP_CRON', true);
Then add a proper server-side cron via cPanel or SSH that calls wp-cron.php on a set schedule:
*/1 * * * * wget -q -O - https://yoursite.com/wp-cron.php?doing_wp_cron >/dev/null 2>&1
You should see: Fewer simultaneous PHP processes in your server stats and a noticeable drop in 429 frequency.
You should see: The flood of 429 responses in DevTools disappear when the offending plugin is deactivated.
You should see: Written confirmation from support that the limit was raised, followed by the error no longer appearing.
Get free WordPress & AI tips
Join 500+ readers. No spam, unsubscribe anytime.
Not necessarily. While a spike of 429s on the login page can signal a brute force attempt, most cases are caused by your own plugins or cron jobs making too many internal requests. Check your server logs before assuming malicious intent — the source is usually something you installed yourself.
Yes, temporarily. Rate limits are time-based, so the 429 typically clears once the current request window resets — usually within a minute to an hour depending on the rule. But without fixing the root cause, the same threshold will be hit again and the error will keep returning.
It can if Googlebot is getting rate-limited while crawling your site. Check Google Search Console under Coverage for crawl errors and consider adding Google’s crawl IP ranges to your whitelist in Cloudflare or your security plugin so the bot is never blocked.
Open DevTools, switch to the Network tab, and filter by Fetch or XHR while your site loads with the plugin active. You can also install Query Monitor — it surfaces REST API calls and labels them by the plugin that triggered each one, making the culprit obvious in seconds.