BlogSecurity

WordPress Site Down? Find the Cause Before Disabling Plugins

Akshat ChoudharyAkshat ChoudharyUpdated October 8, 2026 · 7 min read

feature image

It’s Monday morning, a campaign email goes out at noon, and your homepage greets you with an error instead of your site, which is exactly when people start disabling plugins at random and make things worse.

If your WordPress site is down, the error on your screen already hints at which layer to check, and most outages turn out smaller than they feel.

This guide walks through the checks in the order that narrows the cause fastest, so you know each step is safe before you take it.

TL;DR: Confirm the outage from a second network, record the exact error, and check your domain, SSL, and hosting before touching WordPress. Create a complete WordPress backup first, then isolate plugins through reversible steps, and let your security plugin scan the files if you suspect an attack.

Is your WordPress site really down?

Check from a second network before you change anything, because a local problem looks identical to a real outage.

Website uptime checker showing whether a site is currently down
  • Open a private window, then try your phone on mobile data
  • Use an external status checker to see whether other visitors get the same failure
  • Check your host’s status page for incidents or maintenance
  • Record the time, URL, exact error, and which pages fail (homepage, a post, wp-admin, wp-login.php)

If it loads on your phone, the cause is probably local DNS, cache, a VPN, or a firewall, so leave WordPress alone.

📝 Note: A second-device check separates a local failure from a wider outage but doesn’t identify the cause, so keep your evidence before changing settings.

What is the error telling you?

Once the outage is confirmed, the WordPress error is your map, not permission to change several things at once.

  • DNS_PROBE_FINISHED_NXDOMAIN or a certificate warning: the domain isn’t resolving, or the certificate is expired or mismatched
  • ERR_TOO_MANY_REDIRECTS: two layers are bouncing the request back and forth
  • 404 or 403: a missing rewrite rule, or a permission or security rule blocking the request
  • 429: rate limiting by the server or a security layer
  • 500, 502, 503, 504: PHP, memory, .htaccess, custom code, resource limits, or an update in progress

📝 Note: Meanings vary by host, so I treat a status code as a boundary marker that narrows the search, not a diagnosis.

Could it be your domain, DNS, or SSL?

If the browser can’t find your site, WordPress never gets a chance to run, so check the domain layer first.

  • Look for an expired domain or a billing suspension
  • Check whether nameservers changed during a recent migration
  • Compare your A and CNAME records with the values your host supplied
  • Confirm the certificate’s expiry and covered hostnames, including www

Redirect loops usually mean a proxy and WordPress disagree about HTTP versus HTTPS, so fix one layer at a time, then clear caches.

📝 Note: DNS changes are slow to reverse, so ask your registrar or host before editing records you’re unsure about.

Is your host the problem?

If the domain checks out, open your hosting panel even though the public site won’t load, because the account itself may be the cause. Look for:

Hosting panel option for modifying a hosting plan
  • A suspension or unpaid invoice
  • Scheduled maintenance
  • An exhausted disk or exceeded bandwidth
  • A reached PHP worker or CPU limit

For a 502, 504, or stubborn 5xx, contact the host with the timestamp, affected URLs, response code, and what changed beforehand. This is where people usually trip up: they raise memory limits or switch PHP versions at random, which can add a second problem on top of the first.

📝 Note: Resource limits are provider-specific, so record the current value before changing anything.

How do you fix a WordPress critical error?

When the request reaches WordPress, “There has been a critical error on this website” usually means PHP stopped while loading a plugin, theme, or custom code. Check the administrator’s recovery email first, since it may name the culprit and offer a Recovery Mode link. Before editing files, make sure your backup plugin or host has saved a current copy.

WordPress plugin management screen
If you can reach SFTP or the file manager but not wp-admin, [isolate a possible plugin conflict](https://blogvault.net/plugin-conflict-wordpress/) without deleting anything.
  • Rename the plugins folder in wp-content to plugins.hold
  • Reload the site to confirm a plugin is involved
  • Restore the name and reactivate plugins one by one until the failure returns

A theme can be tested the same way, but only if another compatible theme is installed to fall back on.

If nothing recovers, stop changing things and read the WordPress error logs instead of guessing. Turn on private WordPress debugging by setting WP_DEBUG and WP_DEBUG_LOG to true and WP_DEBUG_DISPLAY to false in wp-config.php, then remove those settings once you understand the cause.

📝 Note: Never display errors publicly, because a public error page can expose file paths and database details.

What if an update caused it?

A failed update can leave a .maintenance file in your site root, which keeps the site stuck on a maintenance message. Only delete it after confirming no update is still running, since removing it mid-update can leave WordPress half installed.

If the outage started immediately after a plugin update, follow the checks for a WordPress site down after a plugin update before retrying the update.

WordPress staging environment in BlogVault

A 404 on posts but not the homepage is usually a permalink issue, not an outage, so save the Permalinks settings without changing anything. Remember that .htaccess applies to Apache only, so confirm your web server before editing it.

What about your config, database, or core files?

Back up before editing wp-config.php, the database, or core files. For a database connection error, verify the name, username, password, and host against your hosting panel, since the database server may also be down.

Don’t delete wp-content or reinstall WordPress as a first move, because that can wipe uploads and the evidence of what failed.

📝 Note: Treat database credentials as secrets and share only the error text when asking for help.

Could it be a security problem?

MalCare security email with two-factor authentication
Unfamiliar files, changed admin accounts, repeated login attempts, or odd traffic are reasons to [check whether your WordPress site has been hacked](https://blogvault.net/ways-to-know-if-your-wordpress-site-has-been-hacked/). Ask your host for access logs and resource graphs, then run a scan with your security plugin. If you suspect malware, contain the site and keep a clean backup before deleting anything, because a rushed cleanup can destroy evidence.
MalCare WordPress security summary

When should you restore a backup?

If noon is close and the cause is still unclear, restoring a known-good backup is a legitimate call, especially after a failed update you can’t safely reverse.

BlogVault backup details and restore information
  • Verify the restore point was made before the problem began
  • Accept the loss of orders, comments, or content created since
  • Afterward, change admin and database passwords and scan the restored files

📝 Note: A backup made after the problem began can restore the same bug or compromise, so check its date first.

When should you hand it off?

If no reversible step works, contact the host for DNS, SSL, account, server, or resource problems, and a WordPress professional for suspected malware, custom code, or no verified backup. Give them the exact error, timestamps with time zone, affected URLs, recent changes, and the steps you’ve tried.

FAQs

What should I check first when my WordPress site is down?

Confirm it from another network, record the exact error, then check your domain, DNS, certificate, and host status before touching any plugin.

What does a WordPress critical error mean?

A PHP fatal error from a plugin, theme, or custom code. Check the recovery email and error logs, then isolate the component.

How do I disable plugins without wp-admin?

Rename the plugins folder in wp-content through SFTP or your file manager, or use WP-CLI. Restore the name afterward and reactivate plugins one at a time.

What does ERR_TOO_MANY_REDIRECTS mean?

Two layers are redirecting the request back and forth, often a proxy and WordPress disagreeing on HTTP versus HTTPS. Check SSL mode and your siteurl and home values.

When should I restore a backup or contact the host?

Restore when a verified backup is safer than continued edits. Contact the host for DNS, SSL, account, server, or resource problems.

Conclusion

A down site is only a symptom, so confirm the scope, read the error, and find the failing layer before making broad changes. That order keeps a DNS problem from becoming a WordPress problem and a plugin test from hiding a host outage.

Start by recording the exact message and time, then check your domain and host from another network before opening a single WordPress file. If the request reaches WordPress, follow the matching step with a fresh backup in hand, and call your host once the evidence points outside your site.

Written by
Akshat Choudhary
Akshat Choudhary

Akshat is the founder and CEO of BlogVault, MalCare, and WP Remote.

Backups built for scale. Restores for the bad day.

No credit card · 14-day money-back guarantee

© 2026 BlogVaultWhatever breaks, you'll get it all back.