Ffile2fix
Sign in Get started

How to fix "Your site could not complete a loopback request"

Your site could not complete a loopback request. Loopback requests are used to run scheduled events, and are also used by the built-in editors for themes and plugins to verify code stability. The loopback request to your site failed, this means features relying on them are not currently working as expected. Error: cURL error 28: Operation timed out after 10001 milliseconds with 0 bytes received (http_request_failed)

WordPress tried to send an HTTP request to its own URL from the server and it failed. Site Health reports it because WP-Cron and the theme/plugin file editor depend on these loopback requests. Common causes are a firewall or DNS that blocks the server from reaching itself, a broken SSL chain, or a slow plugin that makes the request time out.

Also appears as: The REST API encountered an error. Error: cURL error 28: Operation timed out · Unable to communicate back with site to check for fatal errors, so the PHP change was reverted. · Error: cURL error 60: SSL certificate problem: unable to get local issuer certificate (http_request_failed) · Error: cURL error 7: Failed to connect to example.com port 443: Connection refused

Common causes

  • The server cannot resolve or reach its own domain (DNS points elsewhere, NAT, or firewall)
  • A security plugin, WAF or Cloudflare rule blocking requests from the server IP
  • Basic authentication (htpasswd) on a staging site blocking the request
  • Incomplete SSL certificate chain or outdated CA bundle on the server
  • A slow plugin or long PHP session lock making the request exceed the timeout
  • session_start() in a plugin keeping the session locked during the request

How to fix it

  1. Test from the server itself. SSH into the server and run curl -I https://example.com/wp-cron.php. A timeout, connection refusal or SSL error here is the same problem WordPress sees.
  2. Fix DNS or hosts entries. If the domain resolves to a different IP from the server, add the correct internal IP to /etc/hosts, or fix the DNS record. Behind NAT the server may need its private IP.
  3. Allow the server's own IP. Whitelist the server IP in your security plugin, ModSecurity, fail2ban or Cloudflare firewall rules, and exclude wp-cron.php and /wp-json/ from rate limits.
  4. Repair the SSL chain. If curl shows error 60, install the full certificate chain (fullchain.pem) in the web server and update the system CA bundle (ca-certificates package).
  5. Find a slow or session-locking plugin. Use the Health Check & Troubleshooting plugin's troubleshooting mode or deactivate plugins one at a time. Plugins that call session_start() without closing the session commonly cause cURL error 28.
  6. Allow loopbacks on protected staging sites. If the site uses basic auth, allow the server IP in the auth rules, for example with Require ip in Apache, so internal requests are not blocked.

Test the loopback from the server

curl -sS -o /dev/null -w '%{http_code} %{time_total}s\n' https://example.com/wp-cron.php
curl -sS -I https://example.com/wp-json/
getent hosts example.com

How to stop it happening again

  • Whitelist the server's own IP in firewalls and security plugins
  • Install the full SSL certificate chain
  • Avoid plugins that hold PHP sessions open
  • Check Tools > Site Health after server or DNS changes

Frequently asked questions

Is the loopback failure serious?

It can be. Scheduled posts, backups and updates that rely on WP-Cron may stop running, and the theme editor cannot verify changes.

Why does the site work for visitors but loopback fails?

Visitors reach the server from outside. The loopback starts on the server itself, where DNS, NAT or firewall rules can behave differently.

Can I just switch to a real cron job?

That fixes scheduled events: set DISABLE_WP_CRON to true and run wp-cron.php from the system cron. The editor and REST API checks still need loopbacks to work.