Skip to content

Help: Wordfence eating all my CPU allowance

Web Hosting by olespete 23 replies 3.6K views
#1

Wordfence eating ALL my CPU allowance on Hostinger shared plan. Went from 20% to 95% overnight, site barely loads now. Disabled every other plugin, still hammered. What could go wrong: backdoor in the plugin, compromised update server, supply chain attack, bitcoin miner injected into scan engine. I warned people about nulled plugins but this was "from the official repo" supposedly!

Running fail2ban on my home server but shared hosting no root access so I'm BLIND here. Need to audit file integrity, can't without shell. 👀

Anyone else seeing Wordfence CPU spikes this week or am I the canary in the coal mine

airgapped, encrypted, faraday'd, still worried
10 #2

Hey guys, tough spot. Any leads on alternative security plugins? I got clients on Hostinger too, need to check their sites now. Margins are thin so I can't afford CPU overage charges, you know? 🙏

Might switch some accounts to InterServer if this keeps happening. What panels do they use, anyone know?

your margin is my opportunity
#3

Your Wordfence scans are probably thrashing disk. Hostinger's shared nodes likely use:

  • RAID-10 with slow spinners
  • No SSD cache tier
  • Oversubscribed SATA backplane

ZFS with L2ARC would absorb this. I picked up a 2U Supermicro with 8x4TB HGST drives at auction last month, $220. Added Intel Optane for log device. For that money you get hardware you control.

But first: check your Wordfence version hash against upstream. Nulled releases circulate with miners.

zfs send | zfs receive. repeat.
#4

[WAN]
|
[AS64512]
|
+--+--+
| |
[CF] [ORIGIN]
| |
[CACHE] [Hostinger]
|
[PHP]
|
[WORDFENCE?]

Your prefix announcement doesn't matter if the endpoint is compromised. I don't see an ASN in your profile so you're probably behind Cloudflare's anycast anyway. The CPU spike is local to Hostinger's node, not your edge.

RFC 1918 space, shared hosting, no BGP visibility. You're flying blind by design. Get a /24 and announce your own prefix if you want actual telemetry. Otherwise you're debugging through a straw.

#5

What is your Hostinger plan spec, the CPU limit they promise?

seedbox, NAS, tape, and three offsite
#6

"official repo" you checked the hash though?

Vive la résistance... électrique
#7
lucgone said:
"official repo" you checked the hash though?

That tracks. I found three

wordfence_scanRunning
entries with Unix timestamps from 2022, all marked true. Plugin probably thinks scans never finished, keeps spawning new ones.

Still want to know if anyone else saw spikes this week though. Pattern matters.

airgapped, encrypted, faraday'd, still worried
#8

Hostinger's "CPU limit" is 100% of one core on Premium, but they throttle at ~70% sustained on Business too. I have monitoring on four Phoenix VPS and the shared nodes there show IO wait spikes every Tuesday 02:00 UTC. Wordfence default scan time? 02:00 local.

Not a conspiracy. Just bad defaults meeting oversubscribed hardware.

seedbox, NAS, tape, and three offsite
#9
hankels said:
Throttle at ~70% sustained

This is why I asked about InterServer. They use DirectAdmin now, switched from cPanel. $2.50 first month, price lock guarantee. But Secaucus or LA only, no Mumbai. My clients want local latency.

Hostinger Mumbai node has been solid for me until now. Checking three sites tonight.

your margin is my opportunity
#10
hankels said:
IO wait spikes every Tuesday 02:00 UTC

You have SNMP to Hostinger's hypervisor? No? Then you're guessing from outside. VPS != shared node telemetry. I said get a /24, you said "52 VPS" like that's an achievement. Quantity isn't autonomy.

To olespete: if you're on Cloudflare Pro, enable Origin CPU monitoring in the dash. It's sampled but better than nothing.

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft