BLASTA

WordPress load testing template

Core front end, REST API, search and wp-admin.

Category CMSStack PHP + MySQL/MariaDB + nginx/ApacheJobs 24

About this WordPress load test

Load tests WordPress: the front page, a single post bypassing the page cache, REST API posts, search, the RSS feed and the wp-admin dashboard, plus a capacity ramp and a ten-minute soak. It shows what your page cache saves and how much PHP and MySQL can take on their own.

It holds 24 ready-made jobs: 9 single scenarios and an enterprise test plan of 15 stages to run in order, 13 of them with pass/fail targets (SLOs). Each job is a plain request pattern you can change before running.

Scenarios include wordpress front page, wordpress single post (uncached), wordpress REST API posts, wordpress REST API single post and wordpress search.

How to load test WordPress

  1. Open the template in BLASTA.
  2. Set url and post to point at your own WordPress system, ideally a staging copy.
  3. Pick a job and choose the rate and duration.
  4. Start the run and watch requests per second, latency percentiles and errors live; the result is saved to your history.

What you set before running

url
Site base URL, no trailing slash
post
Slug of an existing post, from its permalink
adminCookie
A credential, supplied as an environment variable and never typed into the form. Cookie from a logged-in browser. Read from the WP_ADMIN_COOKIE env var; export it before running.

Test scenarios (9)

wordpress front page

Read-only

Cheapest request on the site. If this is fast but 'single post' is slow, a page cache is serving the front end and WordPress itself is untested.

wordpress REST API posts

Read-only

Serialises many posts through PHP, so it is markedly heavier than the front page. Good proxy for headless or API-driven use.

wordpress RSS feed

Read-only

Cheap and cacheable, but it exercises the same template engine as the front page.

wordpress wp-admin dashboard

Changes state: use a staging system

Admin screens run far more PHP per request and each one opens a database connection. Needs {{adminCookie}}. Still writes (transients, session meta), so staging only.

wordpress capacity ramp

Read-only

Linear ramp to 200 rps over two minutes, then holds. Watch p99, not the average: that is where the knee is. Raise 200 to your expected peak.

wordpress 10 minute soak

Read-only

Steady load long enough to surface PHP-FPM pool exhaustion, MySQL connection leaks and cache decay that a short run never reaches.

Enterprise test plan (15)

Run in order: smoke, baseline, load, stress, spike, soak, breakpoint and failover window, each with pass/fail targets.

WordPress: 01 smoke

Read-only

Enterprise plan, step 1 of 10. One request a second for 30 seconds. Run this first, every time: it proves the address, credentials and headers are right and that the environment is up before any real load is applied. Gate: zero errors. Reference request: wordpress single post (uncached).

WordPress: 02 baseline (20% load)

Read-only

Step 2 of 10. About a fifth of normal traffic for 5 minutes: the uncontended latency of this request. Every later result is judged against it, so record p50 and p95. Gate: at most 0.5% errors and the default latency targets. Reference request: wordpress single post (uncached).

WordPress: 03 average load (SLO check)

Read-only

Step 3 of 10. Normal busy-hour traffic for 10 minutes. The rate is the reference job's rate: raise it to your measured production peak-hour rate. This is the run that proves (or breaks) your SLO. Gate: at most 1% errors, p95 and p99 inside the targets. Reference request: wordpress single post (uncached).

WordPress: 04 peak load (2x average)

Read-only

Step 4 of 10. Twice the average for 10 minutes: the busiest hour of the year plus headroom. Latency may rise, but must stay in SLO; if it does not, you have no headroom. Gate: at most 2% errors, latency targets doubled. Reference request: wordpress single post (uncached).

WordPress: 05 stress (ramp to 4x)

Read-only

Step 5 of 10. Ramps to four times average over 10 minutes, then holds for 2. Finds where it degrades and HOW: gracefully (latency rises, errors stay low) or badly (errors, timeouts, crashes, restarts). Observation only, no gate. Reference request: wordpress single post (uncached).

WordPress: 06 spike (10x in 10 s)

Read-only

Step 6 of 10. Reaches ten times average within 10 seconds and holds for 2 minutes: a campaign email, a news link, a failover. Checks autoscaling, queue limits and load shedding. Gate: at most 5% errors, because shedding load is acceptable and crashing is not. Reference request: wordpress single post (uncached).

WordPress: 07 recovery after the spike

Read-only

Step 7 of 10. Run IMMEDIATELY after the spike, at average load for 5 minutes. Latency and errors must return to the baseline from step 2. If they do not, something is stuck: queues, connection pools, GC, an autoscaler cool-down. Gate: same as average load. Reference request: wordpress single post (uncached).

WordPress: 08 soak (1 hour at 60%)

Read-only

Step 8 of 10. One hour of steady load. Finds leaks and slow decay in memory, connections, file descriptors, disk, log volume and cache churn. Watch the resource graphs: any line that climbs and never flattens is a finding. Gate: at most 0.5% errors. Reference request: wordpress single post (uncached).

WordPress: 09 breakpoint (find the ceiling)

Read-only

Step 9 of 10. Ramps to twenty times average over 20 minutes. Stop it when errors pass about 5%: the rate at that moment is your ceiling, and ceiling divided by peak is your capacity margin. Use a production-like environment, never production. Reference request: wordpress single post (uncached).

WordPress: 10 resilience window (failover / deploy)

Read-only

Step 10 of 10. Average load for 15 minutes. About 5 minutes in, cause the event you are testing: kill a pod or node, fail over the database, roll out a new version, drain a zone. Errors in the window are your real availability loss. Gate: at most 1% errors overall; read the time series for how long the dip lasted. Reference request: wordpress single post (uncached).

WordPress: no keep-alive (new connection per request)

Read-only

Sends Connection: close, so every request pays for a new TCP and TLS handshake: the cost for clients that do not reuse connections (scripts, some mobile SDKs, health checkers). Shows load balancer and TLS termination limits. Reference request: wordpress single post (uncached).

WordPress: crawler traffic (Googlebot user agent)

Read-only

Same request identified as a search crawler. Tests WAF and bot-management rules and whether crawlers get cached or origin responses. Crawlers can easily be a third of all traffic. Reference request: wordpress single post (uncached).

WordPress: large cookies (~4 KB header)

Read-only

Adds a 4 KB Cookie header, like a logged-in user with many tracking cookies. Proxies and servers reject headers around 8 KB, so this shows how close you are to that limit. Reference request: wordpress single post (uncached).

WordPress: uptime monitors (HEAD from many locations)

Read-only

A fleet of synthetic monitors checking the URL with HEAD requests every 30 seconds from 20 locations, plus load balancer probes. Cheap each, constant in total. Reference request: wordpress single post (uncached).

WordPress: viral post (10x in 10 s)

Read-only

A post is shared widely and traffic arrives within seconds. Uncached, so PHP and the database take the full hit. Ramps to ten times normal. Reference request: wordpress single post (uncached).

Frequently asked questions

What does the WordPress load test cover?

The WordPress template has 24 jobs: 9 single scenarios and an enterprise test plan of 15 stages (smoke, baseline, load, stress, spike, soak, breakpoint and failover window). Scenarios include wordpress front page, wordpress single post (uncached), wordpress REST API posts and wordpress REST API single post. 13 of them have pass/fail targets (SLOs), so a run can be judged against limits you set.

How do I load test WordPress with BLASTA?

Open the template in BLASTA and set url and post, then pick a job and start it. Results stream live: requests per second, latency percentiles and errors, and the run is kept in your history. To run from the command line, use blasta preset new wordpress with your address.

Is it safe to run the WordPress load test against production?

Of the 24 jobs, 23 are read-only, 0 write data and 1 change state. Run the writing and state-changing jobs against a staging system, never against production data. Only test systems you own or have permission to test.

Related templates

Run a load test

Point BLASTA at something you own, choose how hard to hit it, and press Start test. Results stream in live.

1 What do you want to test? Use a template

Request headers

2 How hard should it hit?

Advanced limits
Pass / fail targets (SLO) optional
The result is marked SLO met or SLO missed. The same targets live in a job file, where blasta run exits 2 on a miss so CI or Kubernetes can gate a release.

Set up this job

Quick check

Please confirm you are not a robot to start your free test.

Clear history

Delete every finished test in your history. Tests still running are kept. This cannot be undone.

Add identity provider

Add user

The account is active at once. Share the password with them securely; they can change it from their menu.

Sign in to use templates

Templates and test history are part of the full app. Sign in, or create a free account, to use them.

Sign inCreate account

Change password