Skip to content

WordPress hosting problems: how to tell whether the fault is the host or the site

A fault is the host's when it sits in the account, the server, the plan's limits, the mail program or the firewall. It is the site's when it follows a change you made or clears with plugins off. The message on the screen usually says which, and one check settles the rest.

By
WP Ministry
Published

In short

  • Read the message first. A page from the host or a 502, 503 or 504 points at the server. A message in WordPress's own words points at the site.
  • A 500 error, a database error, a 403 and a slow site can come from either side. One check settles each.
  • On shared hosting, reaching a limit can show as slow pages, 500 or 503 errors, or a 508 page.
  • A fault that began with a change you made, shows on one page only, or clears with plugins off is not the host's.
  • Give the host the exact time with its time zone, the address, the exact message, what changed and what you ruled out.
  • Before you move, find out which limit was reached. A faulty plugin moves with the site.

A WordPress problem is the host's when it sits in something only the host controls: the account, the server, the database server, the plan's limits, the mail program or the firewall. It is the site's when it comes from the site's own code and settings: a plugin, the theme, .htaccess or wp-config.php.

The message on the screen usually points to one side. A few symptoms, such as a 500 error or a slow site, can come from either, and one check settles each. The table below has both, with the page that holds each fix.

Start with what you see

If the site is down right now, follow the runbook for the first hour. Its order holds here too: look at the site from a second device on another network, copy the exact message, check the host's status page and your inbox, then write down what changed last.

Three tools help. The site health check asks for one page from outside and shows whether it answers. The HTTP status and redirect checker shows what an address answers, with the status code of every hop. The error message decoder says what a message, or lines from a log, mean.

What you seeUsually points toWhat settles itWhere the fix is
The browser cannot find the addressThe domain or its DNSThe expiry date and DNS records at your registrarSite down runbook
A page saying the account is suspended, or a page that is not your siteThe hosting account or the domainThe host's billing screen, then the registrarBelow: the account or the domain has lapsed
A plain page with 502, 503 or 504The serverThe host's status pageBelow: the server or its database is down or overloaded
A 508 pageThe plan's limitsThe host, asked which limit was reachedBelow: the plan's limits
"500 Internal Server Error"The site first, then the serverA standard .htaccess and an empty debug log leave the hostFix the 500 error
"Error establishing a database connection"EitherThe four database details in wp-config.phpFix the database connection error
"403 Forbidden"EitherWhether it loads on another connection, or fails only when you saveFix the 403 error
"Your connection is not private"The certificateThe code on the warningFix the certificate warning
Email from the site never arrivesThe server's mail program, or the domain's DNS recordsThe "Lost your password?" testFix WordPress not sending email
Every page is slowEitherAn uncached page, timed on a staging copy with plugins offReduce server response time
Uploads or updates failDisk space, or who owns the filesSite HealthFile permissions guide

What WordPress shows you about the server

If you can log in, go to Tools, then Site Health. It has two tabs.

  • Info, under Server, lists the host's settings as WordPress sees them, among them "PHP version", "PHP memory limit", "PHP time limit", "Upload max filesize" and "PHP post max size". WordPress notes there that changes may need your web host's assistance.
  • Info, under Database, shows "Server version" and "Max connections number".
  • Info, under Directories and Sizes, shows the size of the uploads folder, the database and the whole installation.
  • Status runs tests. Those that point at the server are "Your site is running an outdated version of PHP, which requires an update", "Outdated SQL server", a warning that disk space is low and updates may fail, "Your site could not complete a loopback request" and "A scheduled event is late".

If the loopback test fails, ask the host whether the server may make requests to its own address. WordPress uses such requests to run scheduled events.

The Info tab can copy all of this to the clipboard, ready to send to the host.

Faults on the host's side

The account or the domain has lapsed

You see a page that is not your site. On hosts that use the cPanel control panel, its documentation says that visitors to a suspended account get an account suspended message instead of the site, the owner cannot log in to the panel, and the account's mailboxes cannot send.

An expired domain is the registrar's side. Under ICANN's policy the registrar interrupts the domain's DNS for at least the last eight days in which it can still be renewed. If it sends visitors to a page of its own, that page must say the registration has expired and give renewal instructions.

Registrars must send reminders about a month and about a week before a domain expires, so search your inbox. The runbook covers renewing a domain that has lapsed.

Ask the host: why the account was suspended, what lifts the suspension, and whether the files and the database are intact.

The server or its database is down or overloaded

Three status codes say so, and all three are standard HTTP.

  • 503 means the server is not ready to handle the request. MDN gives maintenance and overload as the common causes.
  • 502 means a server acting as a gateway or proxy got an invalid response from the server behind it.
  • 504 means the gateway got no response in time.

MDN says of 502 and 504 that fixing them likely takes investigation by the server's administrators. The exception it names is the visitor's own network, which is why you look from a second one first. The gateway can be the host's own front server, or a CDN or firewall service in front of the site, so check that service's status page too.

An error that comes and goes while nothing on your side changes points the same way. One 503 is WordPress's own: it sends that code with the maintenance message during an update.

For the database connection error, WordPress's documentation names two causes that are the host's: the database has met its quota and been shut down, or the server is down.

Ask the host: whether there is an incident on your server, what the error log shows at the time you noted, and whether the database server restarted or refused connections.

The plan's limits

On shared hosting your site is on a server with many others, and the host holds each account to limits. CloudLinux, server software made so that no single site can bring a server down, documents what a visitor sees at each one.

  • CPU or disk reads and writes: the site answers more slowly.
  • Memory or the number of processes: 500 or 503 errors.
  • Concurrent requests: a 508 page saying the resource limit has been reached.
  • Inodes, a count of the account's files and folders: at the hard limit, nothing more can be written to disk.

That 508 is the software's own use of the number. In the standard, 508 is "Loop Detected" and belongs to WebDAV, so it does not mean your site is stuck in a loop.

When PHP cannot write an upload to disk, WordPress reports "Failed to write file to disk." WordPress's documentation says to take the database's "Error 28", which comes from a temporary folder or cache that is full, to the host.

PHP has limits of its own, which the host sets:

  • memory_limit is the most memory one script may use.
  • max_execution_time is how long a script may run. The default is 30 seconds, and the message is "Maximum execution time of 30 seconds exceeded".
  • upload_max_filesize is the largest file you can upload. post_max_size caps a whole form submission and must be the larger of the two.

On shared hosting you may have to ask the host to raise these. Reaching one does not prove the plan is too small. PHP's manual says the memory limit exists to stop a poorly written script taking all of a server's memory, and a plugin can be that script. How to fix the memory error shows how to find it.

Ask the host: which limit the account reached, at what times, and how often in the last week.

An old PHP or database version

WordPress recommends PHP 8.3 or greater, MariaDB 10.11 or greater or MySQL 8.0 or greater, and HTTPS support. It says older versions have reached their official End Of Life and may expose your site to security vulnerabilities. The WordPress and PHP end-of-life checker shows whether your versions still get security fixes, and until when.

Before you change the PHP version, take a backup and update your plugins and theme. If a page breaks afterward, set the version back and look at the plugin the error names.

Ask the host: which PHP versions the plan offers and where to switch, which database version the account runs, and when it will be upgraded.

Mail the host blocks or limits

WordPress hands each message to PHP's mail() function. PHP's manual says a success from that function means only that the message was accepted for delivery. cPanel's documentation describes a cap a host can set on the emails each domain sends in an hour: messages over it are queued, and past a further margin they fail. Mail that stops in a busy hour is a question for the host. How to fix WordPress not sending email has the test and the lasting fix.

Ask the host: whether the server may send mail for your account, whether there is an hourly cap, and whether it was reached at the time you noted.

A firewall rule that blocks a real request

The sign is a 403 that appears only when you save a post, upload a file or send a form, or only on your own connection. Where a host's firewall uses the OWASP Core Rule Set, that project's documentation explains why: its rules are generic and know nothing about the application behind them, so a genuine request can match one in error. The log records the ID of the rule that matched, and that rule can be excluded without changing the others. How to fix the 403 Forbidden error covers the causes on your side.

Ask the host: whether your IP address is blocked, which rule matched the request at that time, and whether it can be excluded for your site.

Backups you assumed the host keeps

WordPress's documentation says most hosts back up the whole server, and that asking for a copy of your site takes time. Find out before you need one: how often backups are taken, how long each is kept, whether they hold both the database and the files, and whether you can restore or download one yourself. WordPress suggests at least three to five recent backups, kept in different places. Copies held only at the host can be out of reach when the account is suspended.

Signs it is not the host

  • It began with a change you made: an update, a new plugin, an edited file. Undo that change first. The runbook for a failed update has the order.
  • It happens on one page, or one kind of page. Different pages run different code, and a server that is down fails them all.
  • The message is in WordPress's own words, such as "There has been a critical error on this website." The server answered and WordPress ran. See the white screen of death. The database connection message is the exception.
  • It clears with the plugins off. Make a staging copy and follow how to find a plugin conflict.

How to write to the host

Support staff can read logs you cannot. Give them what they need to find the right line:

  • the exact time it happened, with your time zone;
  • the full address that failed;
  • the exact message, word for word, with any code on it;
  • what changed recently, or that nothing did;
  • what you have already ruled out;
  • your IP address, if only you are refused.

Then ask questions that have an answer. Here is a message to copy. Replace the words in capitals.

text
Subject: SYMPTOM on DOMAIN since TIME (TIME ZONE)

My site DOMAIN shows this message:

EXACT MESSAGE

Address: FULL ADDRESS OF THE PAGE
First seen: DATE, TIME, TIME ZONE
How often: EVERY REQUEST, OR COMES AND GOES
My IP address: YOUR IP ADDRESS
Changed recently: WHAT CHANGED, OR NOTHING
Already ruled out: WHAT YOU CHECKED

Could you tell me:
1. What do the server's error logs show for this site at that time?
2. Has the account reached a limit: memory, processes, CPU, disk space or inodes?
3. Is anything blocked by your firewall for this address or for my IP address?

When the plan itself is the problem

It is time to move, or to buy a larger plan, when:

  • the host confirms the account reaches its limits in ordinary traffic, and you have ruled out a faulty plugin;
  • an uncached page stays slow on a staging copy with every plugin off;
  • the host cannot offer the PHP or database version WordPress recommends;
  • the same outage keeps returning and your questions get no specific answer.

A larger plan at the same host may be enough: WordPress's documentation says more CPU and memory can make a big difference. Before you choose a new host, ask what limits the plan sets and what a visitor sees when one is reached, which PHP and database versions it runs, how backups are taken and restored, whether a staging copy is included, and whether the server may send mail.

If you would rather not carry the site across yourself, our WordPress migration service moves one WordPress site from one host to another and tests the copy on the new host before the DNS is changed.

Keep the old plan active until the DNS change has reached every visitor, and find out where your mailboxes live before you cancel it.

Common questions

The host says the server is fine. What now?

Ask for the lines from the error log at the time you gave them. If there are none, test a staging copy with every plugin off. If the fault clears there, it is the site's.

Why does the site fail only at busy times?

Something counted at one moment is running out: concurrent requests, processes, or connections to the database. Ask the host which limit was reached before you pay for a larger plan.

I renewed the domain, or changed its DNS. Why is the site still down for some people?

Each DNS record carries a TTL, the time a resolver may keep its copy before it asks again. Until that time runs out, some visitors still get the old answer. Cloudflare's documentation adds that a device's own DNS cache can take longer still.

More on this subject

Not sure what is wrong?

Tell us what you see. We reply with the cause and a fixed quote, and the diagnosis is free.