Skip to content
WP Cloud
WP Cloud
    • For Hosts
    • For Agencies
    • For Registrars
    • For Native Hosting
    • Performance
    • Security
    • Real-Time Automated Failover
    • Vertical Scaling and Bursting
    • WordPress Management
    • PanelAlpha Integration: White-Label WordPress Control Panel for Hosts
    • EasyEngine Panel Integration: Visual WordPress Management for WP Cloud
    • FAQs
    • WP Cloud API
    • Partner Portal
    • Documentation
    • New Partner Guide
    • Pressable
    • Convesio
    • Porkbun
    • PanelAlpha
    • Ivapix
    • UNC Greensboro
    • Impressive Hosting
    • Blog
    • Performance Benchmarks
  • Connect With Us
  • Login ↗
Start Here ↗
  • Solutions

    • For Hosts
    • For Agencies
    • For Registrars
    • For Native Hosting
    • Featured Partners

    Features

    • Performance
    • Security
    • Real-Time Automated Failover
    • Vertical Scaling and Bursting
    • WordPress Management

    Integrations

    • PanelAlpha Integration
    • Easy Engine Panel Integration

    Resources

    • FAQs
    • WP Cloud API
    • Partner Portal
    • Documentation
    • New Partner Guide
  • Case Studies
    • PressableA case study about how WP Cloud supports Pressable to power millions of page views daily.
    • Convesio
    • Porkbun
    • PanelAlpha
    • Ivapix
    • UNC Greensboro
    • Newspack
    • Inverse Paradox
  • Insights
    • Podcast
    • BlogWP Cloud blog page with latest news and updates about the platform.
    • Performance Benchmarks
  • Connect With Us
  • Login ↗
Start Here ↗

Browse

    • WP Cloud platform overview
    • Onboard and launch with WP Cloud
    • WP Cloud Partner Portal
    • Get support from WP Cloud
    • WP Cloud glossary
    • Manage and secure API keys
    • Client SSH
    • WP Cloud API quick start
    • Webhooks
    • Run bulk tasks across sites
      • Manage site domains and aliases
      • Domain verification records
      • TLS certificates
      • Manage custom TLS certificates
      • Cloudflare and WP Cloud
    • Clone a site
    • Configure resources, site type, and billing with site meta
    • Delete a site
    • Persistent data
    • Staging sites
    • Migrate a site to WP Cloud
      • SSH and SFTP access models
      • Client SSH
      • User SSH and SFTP access
      • Database credentials
      • phpMyAdmin
      • ABSPATH
      • Default wp-config.php
      • Site constants
      • Configure redirects and headers with custom-redirects.php
      • Akismet and Jetpack
      • Blocked and unsupported plugins
      • PHP lifecycle and supported versions
      • Symlinks and managed software
      • WordPress versions
      • Install Composer and WP-CLI packages
      • Manage platform software with WP-CLI
      • Useful WP-CLI commands
    • Transactional email
    • WordPress multisite
    • Cron scheduling
    • Decoupled and headless WordPress
    • Repair Yoast indexables
      • Page Cache
      • Edge Cache
      • Object Cache
      • Image transformation
      • Offload image sub-sizes
    • Configure lightweight 404s for static files
      • DDoS protection
      • Defensive Mode
      • Rate limiting
      • Network and web application firewalls
      • Bot protection
      • Password protection
      • HTTP and security headers
      • PHP filesystem access permissions
      • Scan a site for malware
    • Backups overview
    • Create an on-demand backup
    • Restore a backup
    • Jetpack backups
      • Error logs
      • Web server logs
    • Metrics
    • Application performance monitoring
    • Automated failover
    • IP ranges
    • Origin and edge servers
    • Server specifications and settings
    • EasyEngine integration
    • PanelAlpha integration
      • White labelling and co-marketing WP Cloud
      • WP Cloud logos
      • Terms of Service & Compliance
      • Prohibited content
      • Copyright infringement and takedown notifications
    • WP Cloud billing
    • WP Cloud for agencies and site networks
    • WP Cloud partner support options
    • Troubleshoot Page and Edge Cache
    • Troubleshoot HTTP 429 and 599 errors
    • WP Cloud HTTP status codes
    • Troubleshoot site performance
    • Cache slow database queries
    • Troubleshoot duplicate core files, wp-config.php, and wp-admin 403 errors
    • Troubleshoot email delivery
    • Troubleshoot PDF thumbnail generation
    • Troubleshoot TLS certificate provisioning
Documentation/Security/Traffic protection/Rate limiting

Rate limiting

LAST UPDATED

3 months ago

    WP Cloud rate limiting protects individual sites and the platform from excessive requests, abusive automation, and traffic that consumes too many resources. A matching request can receive an HTTP 429 response instead of reaching WordPress.

    Some HTTP 429 responses are expected and need no change. Investigate when a limit blocks a legitimate visitor, monitoring check, search crawler, API client, webhook, or other customer workflow.

    How requests can be classified

    WP Cloud can classify traffic using several request characteristics rather than relying on an IP address alone. Depending on the traffic and the rule, signals can include:

    • Request rate from a source.
    • URI or route patterns.
    • User agent.
    • Proxy characteristics.
    • Connection signals.
    • Other repeated request characteristics.

    Limits can apply to a request pattern, a site, or a broader platform rule. WP Cloud may also add a manual rule for a known abusive pattern. Exact rules and thresholds can change as traffic changes, so do not build an application that depends on a particular undocumented limit.

    Legitimate automation, webhooks, monitoring tools, and API clients should send a specific, accurate User-Agent header. Requests without a User-Agent, or with a generic value commonly associated with abusive traffic, provide fewer signals that distinguish them from abuse and have a higher chance of matching a rate limit. A User-Agent does not bypass rate limiting or prove the request's identity.

    HTTP 429 responses

    A true HTTP 429 is shown to the client and recorded as 429 in web server logs and Metrics. WP Cloud hosts can retrieve request logs through the Web Server Logs API endpoint. A true HTTP 429 means the request matched a rate limit. A specific browser, user agent, function, URI pattern, or request signature may be making too many requests.

    The visitor-facing rate-limit page can also represent a WP Cloud resource-limit event recorded internally as HTTP 599. Do not assume every visible 429 is an ordinary request-rate limit. Troubleshoot HTTP 429 and 599 errors explains how to distinguish the recorded statuses using logs and current metrics.

    A group of true HTTP 429 responses can also accompany a DDoS attack or repeated requests for missing pages and assets. See DDoS protection for the platform protections and additional controls available during an attack. If the logs contain many 404 responses, follow Check for expensive 404 responses.

    Bots and crawlers

    It is normal to see occasional 429 responses from scanners, SEO crawlers, and malicious bots. No action is usually needed when the site and legitimate traffic continue to work.

    If an authorized crawler is limited:

    1. Confirm its user agent, source, affected URLs, and incident time in web server logs.
    2. Reduce its crawl rate and add delay or backoff after an HTTP 429.
    3. Check for a loop, repeated missing URL, or configuration that creates more requests than intended.
    4. Verify that the tool identifies itself correctly. A user agent alone does not prove that a request came from the named service.
    5. Contact WP Cloud Support only when the legitimate workflow remains blocked after correcting the client behavior.

    Do not change the site’s public behavior to accommodate unwanted bots. During a larger attack, use Defensive Mode and preserve request samples for the incident review.

    Review rate limiting in logs and Metrics

    Use the Web Server Logs API endpoint to retrieve request-level details such as URLs, user agents, source addresses, and HTTP statuses. Use the Time Series Metrics endpoint or the WP Cloud host portal for the same time range as the incident. Useful dimensions include is_rate_limited and rate_limit_reason. Group them with dimensions such as path, http_user_agent, http_status, or wp_admin_ajax_action to find the affected traffic. Logs show the individual requests; Metrics show the pattern over time. Use both when the impact is not clear.

    Previous Defensive Mode
    Next Network and web application firewalls

    Related Guides

    • DDoS protection

      Learn how WP Cloud routes, filters, and mitigates denial-of-service traffic before it reaches WordPress.

      1 Min.

      READ

    • Defensive Mode

      Use an on-demand browser challenge to reduce unwanted automated traffic during a bot or DDoS…

      3 Min.

      READ

    • Network and web application firewalls

      Understand WP Cloud inbound access, outbound firewall rules, and web application firewall responses.

      2 Min.

      READ

    On this page

      Contact support

      Contact us with Support issues and questions related to WP Cloud, the WP Cloud Atomic API, API-key IP allow list changes, Station, and more.

      Check the FAQs

      Have questions? Please visit our FAQ to learn more.

      An Automattic venture

      Work With Us

      Press

      Privacy Policy

      © 2021-2026 Automattic Inc.

      Notifications