Website not loading? Check if it’s down for everyone
First, find out who can’t see the site. Turn off Wi-Fi on your phone and open the site over mobile data. Try a private window on your computer, and ask someone in another town to try too. If it loads for them, the problem is probably your office internet, your browser, or a security plugin that blocked your office after too many wrong passwords. If it fails for them too, check your host’s status page or account dashboard for an outage notice.
If nobody can load it, write down what you see before you change anything. Take a screenshot of the message, note the time, and try a few pages, not only the homepage. Then try your login page, usually your web address followed by /wp-admin. Whether the admin side still opens is a big clue for whoever fixes it.
Check one more thing: does your business email still work? If email bounces too, suspect the domain, or the hosting if your email runs on the same account. If email works and only the website fails, the problem is more likely the hosting or WordPress itself.
What each error message usually means
The message on the screen is your best clue. Here is what the common ones usually mean and who can fix each. Treat it as a starting point, not a diagnosis.
- “This site can’t be reached” with “server IP address could not be found” underneath. Often the domain: it expired, or its settings point to the wrong place. Check your domain registrar first. If it says “took too long to respond” or “refused to connect” instead, start with your host.
- A page saying the domain has expired, or a parking page full of ads. The domain lapsed. Renew it at the registrar as soon as you can.
- “Account suspended” from your hosting company. Usually an unpaid bill or an expired card. Hosts also switch sites off for overuse or malware. Call the host.
- “Your connection is not private.” Often the security certificate behind the padlock in the address bar expired, didn’t renew or doesn’t match your address. If other sites show it too, check the computer’s date and time. Your host can usually reissue the certificate.
- “There has been a critical error on this website.” Something stopped WordPress from running. Common causes include a plugin, the theme, the PHP version and the memory limit. Look for WordPress’s recovery email, covered below. Some sites show “The site is experiencing technical difficulties” instead.
- A blank white page. WordPress’s own guide says PHP or database errors can cause it, and lists a clashing plugin or theme among the usual reasons.
- “Error establishing a database connection.” WordPress can’t reach the database where your pages live. The cause is often wrong login details for it or a problem at the host, and sometimes a hack. Start with the host.
- “500 Internal Server Error.” WordPress’s guide names a damaged .htaccess file, a server settings file on many hosts, as the most likely cause. A plugin or theme can cause it too. This needs someone with hosting access.
- “502 Bad Gateway,” “503 Service Unavailable” or “504 Gateway Timeout.” The server behind your site is overloaded, under maintenance or not answering properly. Check your host’s status page and wait a few minutes; if it stays, call the host.
- “Briefly unavailable for scheduled maintenance” that won’t go away. WordPress adds a small file while it updates, and it wasn’t removed properly. Give it a few minutes; if it stays, someone with file access deletes the file named .maintenance.
- “Connection timed out,” or pages that crawl. Often the server running short of resources, from a heavy plugin or a hosting plan that’s too small.
- A red warning from Google, pages you never wrote, or visitors sent to other sites. These are signs of a hack. Skip to the hacked section below.
References: WordPress Developer Resources: Common WordPress errors (opens in a new tab) · Make WordPress Core: Fatal error recovery mode in 5.2 (opens in a new tab) · IETF RFC 9110: HTTP Semantics, server error status codes (opens in a new tab) · Google Search Console Help: Security issues report (opens in a new tab)
Check the three renewals that can switch a site off
Some outages have nothing to do with WordPress. The site is fine, but a renewal lapsed. Check the domain, the hosting and the security certificate before anyone opens the code.
While you’re there, look at where the reminder emails go. If they go to a past web designer or an inbox nobody reads, change the contact email to one you check and switch on auto-renew. Our guide to who owns your software, your data and your domain covers which accounts should be in your name.
- The domain. Log in where you registered it and check the expiry date. For .com and other generic endings, ICANN rules make registrars send at least two reminders, about a month and a week before it expires. Once it lapses, the registrar must cut off the website and email the domain points to before deleting it. Some registrars delete within days; others keep it renewable for weeks. After deletion, most generic endings give you 30 days to restore it, and the registrar may charge a fee. Country endings like .us aren’t covered by these rules, so ask your registrar.
- The hosting. Check the billing page and the card on file. An expired card can take a site down while the warning emails sit unread.
- The security certificate. Many hosts renew it for you. When we checked in October 2026, Let’s Encrypt, a common free provider, issued certificates that last 90 days by default. So renewal has to keep working in the background. If it fails, visitors see a warning instead of your site.
References: ICANN: Expired Registration Recovery Policy (opens in a new tab) · ICANN: 5 things every domain name registrant should know about the Expired Registration Recovery Policy (opens in a new tab) · ICANN: FAQs for registrants: domain name renewals and expiration (opens in a new tab) · Let’s Encrypt: FAQ (opens in a new tab)
Ask what changed in the last few days
Something usually changed, even if nobody meant it to. On most sites, WordPress installs minor and security updates in the background by itself, and plugins and themes can be set to update on their own too. So “we didn’t touch anything” can be true and still not the whole story.
Write a short timeline. WordPress’s guide for hacked sites gives advice that fits any outage: note what you see, when you noticed it, and what was done recently. That page of notes saves time, and time is what a repair costs.
Go through this list and write down anything that fits:
- An update to WordPress, a plugin or the theme, by a person or automatic.
- A new plugin, or a changed setting in one, such as a form, booking or security plugin.
- An edit to the theme, or a code snippet someone pasted in.
- A change at the host, like a move to a new server or to a newer version of PHP, the language WordPress runs on.
- A new person with a login: staff, a marketer or a past developer.
- A card that expired, or a renewal email nobody acted on.
References: WordPress.org Documentation: Updating WordPress (opens in a new tab) · WordPress.org Documentation: Site Health screen (opens in a new tab) · WordPress.org Documentation: FAQ My site was hacked (opens in a new tab)
Safe WordPress repair steps you can take yourself
If WordPress shows “There has been a critical error on this website,” check the inbox of the site’s admin email address, spam folder included. Since version 5.2, WordPress emails that address a secret link to recovery mode. Recovery mode pauses the plugin or theme causing the error, but only for you. Visitors still see the error until it’s fixed.
Once you’re in, WordPress tells you which plugin or theme failed. If it’s something minor you recognize, like a photo slider or a social feed, deactivating it is a step you can undo. If it runs your quote form, booking, shop or payments, call for help first. Switching it off can stop requests or orders without any warning.
Then open Tools, then Site Health. The Status tab lists critical issues, like plugins waiting for updates. The Info tab has a button that copies your whole setup, from versions to plugins and server details. Paste it into a message to your helper.
Some fixes do more damage than the problem. Leave these alone unless you know exactly what they do:
- Deleting plugins. Deleting runs a plugin’s clean-up, which can wipe its settings and saved data; deactivating it is designed not to.
- Restoring an old backup. It can overwrite every order, request and post since that day.
- Installing a “fix” plugin, or pasting code from a forum or a video.
- Editing theme or plugin files from inside WordPress. One typo can lock you out of the admin side too.
- Changing the WordPress address or site address under Settings, General. A wrong value can make the whole site unreachable.
References: Make WordPress Core: Fatal error recovery mode in 5.2 (opens in a new tab) · WordPress Developer Resources: Common WordPress errors (opens in a new tab) · WordPress.org Documentation: Site Health screen (opens in a new tab) · WordPress Plugin Handbook: Uninstall methods (opens in a new tab) · WordPress Developer Resources: Migrating WordPress (Changing the site URL) (opens in a new tab)
Signs your site was hacked, and the first steps
WordPress’s guide for hacked sites lists clear signs. Google or Bing flags the site, your host disables it, it’s reported for spreading malware, or visitors’ antivirus software warns them off. Others are new user accounts you didn’t create, or a defaced page you can see in the browser. Strange pages under your name in Google count too: Google calls content placed on your site without permission “hacked content.”
If you see any of these, stop the do-it-yourself fixes. The guide calls finding and removing the hack the most daunting part. Hacks often add new files, and WordPress’s built-in reinstall often overwrites only the files already there. One missed file can let the attacker back in. That’s a job for your host’s security team or a developer.
While you line that up, these first steps from the guide are ones any owner can take:
- Write down what you see and when, plus anything that changed recently.
- Ask your host. On shared hosting, a hack can reach more than your site, and the host may be able to tell a real hack from an outage.
- Run a full virus scan on the computers you use to log in. Some attacks start there, by stealing passwords.
- Change the passwords for WordPress, the hosting control panel and FTP (the login for moving files onto the server). Leave the database password to your host or developer: it has to be changed in a settings file too, or the site goes down. Change them all again once the site is clean.
- Take a copy of the site as it is, even infected, before the cleanup starts.
- If Google flagged the site, check the Security Issues report in Google Search Console. After the cleanup, request a review there; Google says a review can take from a few days to a few weeks.
References: WordPress.org Documentation: FAQ My site was hacked (opens in a new tab) · Google Search Console Help: Security issues report (opens in a new tab)
When to call for help, and what to ask first
The checks above are safe for anyone; past them, guesswork tends to make things worse. Stop and call if you see any sign of a hack. The same goes if the broken part takes money or requests, like a shop, a booking calendar or a quote form. Stop, too, if the fix means editing files like wp-config.php or .htaccess, or using FTP, and you haven’t done it before.
Other signs it’s time: you can’t log in, the “Lost your password?” link on the login page didn’t help, and no recovery email came. Or you have no backup from the last week, you don’t know who holds the hosting login, or it’s the second or third time this has happened.
Call your host first about a certificate warning, a suspended account, a database error, or a site that’s slow or timing out. Hosts can see the server’s error logs, which often name the cause. Ask what their support covers before you pay anyone else. A lapsed domain goes to your registrar, if that’s a different company.
Call a developer for plugin and theme errors, anything that means editing files, a hack, or a problem that keeps coming back. Breakage that returns usually means the cause was patched, not found.
Whoever you call, send your notes: the screenshot, the time, what changed and the Site Health info. Share logins through a password manager rather than email. Flat-fee fixes and repair services are easy to find, and how the work is done matters more than the headline price. Before you hand over access, ask these questions and get the answers in writing:
- Will you take a full backup, files and database, before you change anything?
- What do you think the cause is, and how will you confirm it?
- Is the price fixed, and what happens if the problem turns out to be bigger?
- Will you test the forms, bookings and checkout after the fix?
- Will you write down what you changed, so the next person knows?
- Will you use your own login, and remove it when you’re done?
Keep the next breakage small
Most of the pain of a broken site comes from what wasn’t ready: no recent backup, no login, no idea what changed. WordPress’s backup guide says a full backup has two parts, the files and the database, and you need both to restore a site. It suggests weekly backups for smaller sites and daily ones for busy sites, with several recent copies kept in different places.
Most hosts back up the whole server too, the guide notes, but restoring from those copies takes time. So keep your own, and take a fresh backup before any update, as WordPress suggests.
Then protect the records the site collects. The costly breakages are quiet: the site looks fine, but a form or booking plugin stopped working after an update. For example, a 6-truck plumbing company with its quote form in a plugin could lose a week of requests before anyone notices. So could a café taking catering orders through a shop plugin, or a property manager whose tenants report repairs on a web form.
So test your forms after every update, as our guide to a website form that stopped sending explains. And send every request somewhere besides the website: an email copy at least, or better, the list or system your team already works from. Then a broken site costs you some visitors, not the requests already in hand. What website maintenance includes covers the full routine; these basics come first:
- Updates on a set day each month, with a backup first and a test request through your forms after.
- A short plugin list. In calm times, remove plugins you don’t use.
- Renewal emails for the domain, hosting and certificate going to an inbox you read, with auto-renew on.
- A free uptime monitor that emails you when the site goes down, so you hear before customers do.
- Owner logins for the domain and WordPress in your business’s name, and a written note of whose account holds the hosting and how to move it.
References: WordPress Developer Resources: WordPress backups (opens in a new tab) · WordPress.org Documentation: Updating WordPress (opens in a new tab)
How we help when your website breaks
If your site is down right now, start with the checks above: renew a lapsed domain at your registrar, and call your host about certificates and server faults. Our team handles the repair behind it and the care after. We look after websites and software, including sites we didn’t build. We review it first: how it’s built, who has access and what shape it’s in. Then we tell you what we can look after, and whether a repair or a new site makes more sense.
A one-off fix on a site we don’t look after yet is typically $750–$3,000 and takes 1–2 weeks. A monthly plan for updates, fixes and small changes is priced in your quote, and every project we launch includes 30 days of fixes. We don’t promise 24/7 support: calls run Monday to Friday, 7 am to noon Pacific, and reply times are written into your plan.
If an old site keeps breaking, a new one can be the better spend; a new website with us is $2,500–$6,000 over 3–6 weeks. These are our prices as of October 4, 2026. The first call is free, and you get a fixed price in writing within 48 hours of it. See how our website and software support works.
Want someone to look after it for you?
See management & support