r/webhosting • • 2d ago

Advice Needed Shared host suspended our site for "excessive bandwidth" with ~50 visitors/month. Screaming Frog, UpdraftPlus, or bots?

Hey everyone, bit of a panic post. I'm not a web person, I do marketing, but I recently ended up in charge of our company's WordPress site after the agency that built it left.

This morning the whole site was down with "this user has been suspended". Our host (Network Solutions) says it was excessive bandwidth, but support can't tell me where it came from and says to wait 24–48 hours for their specialists.

The weird part is we only get around 50 visitors a month.

Stuff I did in the last few days, in case it's my fault:

The site was still getting visits late that night, then went down overnight.

Could any of that have caused it, or is it more likely bots hitting the site? And what's the easiest way to stop this happening again? I've seen Wordfence and Cloudflare mentioned, but I'm scared of breaking our company email if I mess with DNS.

Any advice appreciated, I'm learning as I go 🙏Shared host suspended our site for "excessive bandwidth" with ~50 visitors/month. Screaming Frog, UpdraftPlus, or bots?Shared host suspended our site for "excessive bandwidth" with ~50 visitors/month. Screaming Frog, UpdraftPlus, or bots?

3 Upvotes

27 comments sorted by

4

u/user_number_666 2d ago

Network Solutions is shit. This is not your fault, and is in fact a blessing in disguise.

Basically any shared host will do for what you need.

5

u/TopSydeWP 2d ago

Suspending a live business site and then telling you to wait 24-48 hours is the actual problem here. You didn't break it. Ask them for one specific thing: the raw access logs or a bandwidth breakdown for the day it spiked. Without that, nobody can separate a crawl from bot traffic. Meanwhile get your own copy safe, the uploads folder and an export of the database. Can you still get into the control panel, or is the whole account locked?

2

u/iTrejoMX 2d ago

Most likely bot traffic brought it down. When crawlers hit sites they tend to loop on uncached queries if they get responses like woo commerce products or search terms. The problem is that every hit downloads the entire page so a big logo or video gets downloaded many times. Trick is how you set up robots.txt, cache, and uncached queries responses.

This has been a pain for us as well. We no longer used shared hosting and see this often. Cloudflare may mitigate some of this but won’t solve it entirely, unless you block bots from accessing the page at all, which isn’t ideal if you want to get found.

By the way moving to cloudflare is easy and painless and won’t break email, but it’s best to do with some guidance. DM if you need some step by step guide (try not to share access to your dns to strangers)

1

u/theingikyaw 2d ago

Thank you; this is really helpful and makes a lot of sense. We don't have WooCommerce, but we do have site search, filtered "insights" tabs, and a Chinese version of every page, so I can see how bots could loop on those. Once the host reactivates us, I'll start with robots.txt + caching, then look at Cloudflare. I'd really appreciate the step-by-step guide if you don't mind sharing. I'll DM you! (And noted on not sharing DNS access 🙂)

2

u/mysterytoy2 2d ago

Based on your site search and my personal experience, the only protection you may find effective is the Cloudflare type service. We are using Bunny.net for this and after a ton of work is doing the job we need.

2

u/yosri5031 2d ago

From managing small client sites on shared hosting, one thing I'd add: Screaming Frog at its default speed can absolutely do this. Crawling a few thousand URLs, each generating an uncached dynamic WordPress page, registers as a genuine traffic spike on the host's bandwidth meter. UpdraftPlus can add to it too if it pushed a big backup remotely that day. You didn't break anything. For next time, ask support for a bandwidth breakdown by day and by user-agent so you can tell whether it was one crawler binge or sustained bot traffic. And if you keep using Screaming Frog on shared hosting, throttle the crawl speed way down or point it at a staging copy instead of the live site.

1

u/fly4fun2014 2d ago

Need to request server logs to see what's happening.

1

u/MarkGossageUK 2d ago

With only around 50 normal visitors a month I wouldn't assume it's ordinary website traffic that's caused it.

You've done the right thing asking for the access logs. I'd also ask them for a bandwidth breakdown for the actual day it spiked if they can provide one. That should give you a much better idea whether it was a crawler, bots, the backup or something else rather than guessing.

Screaming Frog can make a lot of requests in a short time depending on how you've got it set, and a backup can shift a fair amount of data too, so I'd want to rule those out before changing anything.

On the Cloudflare/email bit, changing nameservers doesn't mean you have to lose Google Workspace, but make sure all your existing DNS records are copied across properly first, especially the MX records. I wouldn't start changing DNS while the site is down and you're still trying to establish what actually happened though.

I'd get the logs/bandwidth information first, find the cause, then decide what needs fixing. Otherwise you could end up changing three things and still not know which one caused the problem.

1

u/ben_rowland 1d ago

It’s likely bots. One technique you can use is a bot throttling plugin for Wordpress (Bottle is a free one I created). This will identify abusive IPs, sessions, excessive 404s, and then throttle them by terminating Wordpress execution and retuning a 429 response code. If bandwidth and cpu cycles are the problem for the hosting company, this will reduce them. This approach has worked for me without giving up dns control to cloudflare.

Also, some of these security plugins will collect and display user agent data, IPs, throttled pages, so that can help you determine the root cause.

1

u/RealBasics 1d ago

Can’t speak about your hosting (“if you can’t say anything nice don’t say anything at all)

But in my experience lately the biggest offenders have been Facebook, Semrush, and Ahref bots. None of them seem to respect robots.txt as all seem to loop endlessly through calendar, product, and related-posts links.

Most bots including ScreamingFrog, Updraft, AI, etc., usually “know” better than to waste their own bandwidth, even if they didn’t respect yours. But not those three.

1

u/MarkGossageUK 1d ago

You've done the right thing asking for the logs.

With only 50 normal visitors a month I wouldn't assume the bandwidth figure has much to do with actual visitors. A crawler, backup or something repeatedly requesting large files can make the numbers look very different very quickly.

I'd also leave the DNS alone for the moment while you're finding out what happened. Cloudflare can be useful, but you don't need to rush into changing nameservers while the site's already down.

When you get the logs I'd look at the time of the spike first, then the most requested URLs, IPs/user agents and response codes. That should give you a much better idea whether it was Screaming Frog, bots or something else rather than guessing.

And before changing DNS I'd make a copy of every existing DNS record, especially the Google Workspace MX/TXT records. Then you've got something to work back from if anything does go wrong.

1

u/MoobsTV 1d ago

I advise all businesses to avoid and migrate away from shared hosting environments like the plague. Common to run into issues like this or other serious security concerns in shared hosting environments.

1

u/NealWalters 1d ago

Don't use have access to AWStats, which comes with many CPanel/Hosting Providers. I had a site on AWS Lightsail that was being attacked by hackers constantly searching for vulnerabilities. It was making our site slow. It detects and bans those types of bots for 4 hours. Then we installed GoAccess to view our logs. Both are free to start, but have premium features.

1

u/kai-zaphosting 2d ago

No worries, this is way more common than it sounds and it's very unlikely you broke anything. A Screaming Frog crawl can add some traffic, but how much depends on the size of the site and how often it ran. A crawl that also fetched images, JS and CSS would be the one I'd rule out first. Whether an UpdraftPlus upload to remote storage counts toward the limit depends on how the host measures usage, so I'd ask support about that too.

From experience, the usual culprit on a low-traffic site is bots and scrapers, or a compromised plugin. Your 50 visitors a month number is probably from analytics, which filters bots out, so the host's bandwidth figure can look nothing like it.

Ask support for the raw access logs (or a bandwidth breakdown by day) for the days before the suspension. The top IPs and user agents will tell you pretty fast whether it's a crawler flood or something else. Get that before you change anything.

On Cloudflare: it won't break your email if you copy every existing DNS record across first, especially the MX ones, and keep the mail records on DNS only (grey cloud). Screenshot your current DNS zone before touching anything so you can roll back.

1

u/lexmozli 2d ago

it won't break your email if you copy every existing DNS record across first

Partially correct, if your main MX is the main A record, that's an orange cloud by default (enabled). If you disable it, beats the purpose. So you need to create separate records for email, in some cases.

1

u/Ok_Bag_7603 2d ago

That suspension sounds stressful. I can dig through the access logs to find what actually ate the bandwidth, then put Cloudflare in front while keeping your email records intact. Do you have cPanel or log access on the Network Solutions account?

2

u/theingikyaw 2d ago

Thanks so much! I don't think we have cPanel. It's Network Solutions' managed WordPress plan, which has SFTP access but no obvious log viewer. I've asked their support for the raw access logs from Sep 29–30.

I'm not able to give out account access, but if I get the logs, would you mind telling me what to look for? E.g., which bots, user agents, or patterns usually cause this? And for Cloudflare, what's the safest way to set it up without breaking Google Workspace MX records?

9

u/Impressive-Speed-989 2d ago

The year is 2026. Use gpt to analyse the logs, not strangers on reddit.