Skip to content

Why Does WordPress Use So Much CPU?

Divide the high CPU usage of WordPress between traffic, bot, PHP, wp-cron, plugin, and MySQL, and find the real factor before you know it.

Author Bipida Editorial Team Published
Share this article

The CPU only says that the processor is busy; it doesn't say which request or service is to blame. Real traffic, bot, wp-cron, a plugin loop, PHP workers, query database or even backup and compression can create a similar pattern. RayStarts may temporarily down the chart while eliminating the most important evidence.

Quick action:Record startup time, user processes, load, traffic, and log requests. First, maintain the critical service by targeting malicious agents; then find the relevant URL, job, or query. Blocking all users, removing plugins, or increasing the number of detection servers is not considered an unrealistic process.

Is the CPU really a necklace?

See CPU numbers alongside average load, core number, iowait, memory, swap, and latency. High load can include expected I/O. In shared hosts, too, throttling or CPU share may not be comparable to a dedicated VPS. A one-minute, fifteen-minute gap indicates a short spike or steady pressure.

uptime
top
ps -eo pid,ppid,cmd,%mem,%cpu --sort=-%cpu

These commands are read-only. Take a snapshot several times during an event; an example may show a short job that is too important. Clear the command line and system user name before publicly sharing.

Which process uses CPU?

The dominant processThe path of inspection.
php-fpmURL, access log, slowlog, plugins and requests
mysqld/mariadbdActive query, slow query, lock and index
cron / php CLIName of the hook, job, row and cover run
backup/compressionTiming, priority and run window
Unknown processExecutable path, parent and security check

If you see an unknown process or unexpected execution, do not immediately assume it is a virus file or blindly delete it. Record evidence, path, owner, parent process and persistence and check security.

Real traffic, bot or attack?

Summarize the access log based on the URL, IP, user-agent, status and request rate. An endpoint such as search, login, XML-RPC, REST or a URL without cache may create an inappropriate load. IP is not just a metric of identity and the user-agent can be falsified; the model and effect of the request are important.

Rate restrictions on CDN or web server should be applied on a specified path and with real user testing. Geo-blocking or average challenge may disrupt the authorized crawler, webhook, payment gateway, or API. Do not publish credential and query string sensitive in public reports.

PHP-FPM and the application for spending

If PHP workers are dominant, the access log has response time, and the PHP-FPM slowlog can request the slow to approach the stack. The slowlog should be set to timeout and secure path and its overhead measured. Increasing worker leads to more concurrent processing, but if the CPU is saturated it may worsen the competition row.

The page that is cached may be lightweight for unknown users and heavyweight for the user who logs in.The slow guide to wp-adminFollow him.

wp-cron and the same job folders

Backup, scan, email, product sync, and clearance may be run simultaneously. An unlocked cron or a job that takes longer than its interval can create multiple folders. Enter the hook name, start time, duration, and final result.

Manually running all events or deleting a row without recognizing the effect, there is a risk of repeating an email and losing a job. Batch the job, fix the lock and retry, and move the heavy work to the right time. Replacing wp-cron with system cron is only when the call, monitoring, and avoidance of overlap is designed to be correct.

How does MySQL get the CPU?

A query without an index, meta search, large report, disk sort, and repeat call can increase the CPU database. Process list is just a momentary state; slow query log and digest abundance give a better picture. Check the query with plan and number of rows and build the index first on clone; the additional index costs write and space.

If there's also a lock or schema error,MySQL and WordPress error guidesSee. Restarting the database doesn't fix the bad query and may delete the hot cache.

How do we isolate the plugin or template?

  1. Record the latest deployment, update and change of settings.
  2. Reproduce the URL/job of the bar producer in the staging.
  3. Find the hook and caller with the profiler or Query Monitor.
  4. Confirm plugins controlled grouping and factoring.
  5. Modify the function setting/code with the compatible rollback version.
  6. Measure the same workload before and after.

Disabling all plugins on production could break the commercial service.Secure log debug.logUse it, not show the visitor the error.

Temporary restraint without concealing the cause.

If the site is on a fixed threshold, targeted rate limit, temporary halt of a given job, decreased concurrency of the operator or the correct activation of cache can take time. Each action should have owner, expiration time, and rollback.

Common Mistakes

  • Reboot before storing process and logs
  • Blocking the whole thing with no exception to payment and webhook.
  • Increasing PHP worker on saturated CPU
  • Deleting cron queue or database without backup
  • Install multiple cache plugins in the middle of the incident
  • Conclusion from a short snapshot

Prevention and monitoring

Monitor CPU, load, PHP queue, latency, error rate, and endpoint traffic. Alert should be activated before saturation is stable and for a reasonable time so as not to alert to unimportant spikes. Timing heavy jobs, updating on test staging, and reviewing capacity with actual traffic.

When is special intervention needed?

If the CPU is still high after the traffic decline, multiple processes are involved or the problem only occurs under concurrency, trial and error is at risk on production.WordPress speed boost serviceIt can define the source of consumption from process and access log to PHP and query.

Common Questions

Is the CPU 100% always bad?

Short spike may be normal; stable saturation with row, latency and error is a sign of capacity or workload problems.

Does the upgrade of the server solve the problem?

Capacity takes more time, but a faulty loop, bot, or query usually reappears as traffic grows.

Why is the CPU up at night?

Compare the backup, scan, cron and sync scheduled to the same timeframe.

Why Is the WordPress Dashboard Slow? Diagnosing wp-admin Performance
Identify the widget of a wp-admin from AJAX, plugins, wp-cron, databases, external API and PHP workers, even when public pages are fast.