Common causes
- Too many simultaneous PHP requests (the Entry Processes limit, often 20-30) because pages are uncached or slow
- Bot traffic or brute-force attacks on wp-login.php or xmlrpc.php
- Slow external calls or database queries keeping PHP processes open longer than needed
- Heavy cron jobs, backups or WP-Cron firing on every page load
- A plugin or script stuck in a loop consuming CPU or memory
- A site that has simply outgrown its shared hosting plan
How to fix it
- Read Resource Usage in cPanel. Open cPanel > Resource Usage (or hPanel's Order Usage on Hostinger) and check which limit faulted: EP (entry processes), CPU, PMEM (memory) or NPROC. This tells you whether the issue is concurrency, CPU or memory.
- Check the access log for bots. Look at Raw Access or Visitors for a single IP or user agent making many requests, especially to wp-login.php, xmlrpc.php or search URLs. Block it in .htaccess, the firewall or Cloudflare.
- Enable full-page caching. Use LiteSpeed Cache, WP Super Cache or a CDN so most visits are served without running PHP. This is the biggest single fix for EP limits.
- Replace WP-Cron with a real cron job. Add define('DISABLE_WP_CRON', true); to wp-config.php and schedule wp-cron.php every 5-15 minutes in cPanel Cron Jobs.
- Find the heavy plugin or script. Disable plugins one at a time, or use the slow log and Query Monitor, to find code with long-running queries or external calls.
- Upgrade if usage is legitimate. If real traffic consistently hits limits after caching, move to a plan with higher limits or a VPS.
.htaccess (block xmlrpc.php floods)
<Files xmlrpc.php>
Require all denied
</Files>
# wp-config.php
# define('DISABLE_WP_CRON', true);
# cPanel cron: */10 * * * * php /home/USER/public_html/wp-cron.php >/dev/null 2>&1 How to stop it happening again
- Keep full-page caching and a CDN active at all times
- Rate-limit or block login and XML-RPC endpoints
- Schedule backups and heavy cron jobs for low-traffic hours