Cron Job (specifically WP-Cron in WordPress) is one of those hidden features most site owners rarely think about until their scheduled tasks start failing or running late. In this article, I’ll explain why relying on WP-Cron can be problematic and why replacing it with a proper system-level cron job is a smarter choice for security and reliability.
What is WP-Cron
In WordPress, WP-Cron (wp-cron.php) is a built-in feature that handles scheduled tasks, like scheduling posts or running auto-backup. Typical tasks handled by WP-Cron:
- Checking for updates (plugins, themes, and core).
- Publishing scheduled posts at the right time.
- Sending scheduled emails (like newsletters or notifications).
- Running auto-backup (from plugins).
- Cleaning up temporary or expired data (like transients or trash).
Ironically, WP-Cron only runs when there is someone visits your site. Each time a page loads, WordPress checks whether there are any due tasks and, if so, executes them. Therefore, if your site has only a few visitors or doesn’t get frequent viewers, your scheduled tasks may not running as expected.
The Downsides of WP-Cron
While WP-Cron is convenient (because it is… default?), it comes with a few serious limitations:
- Inconsistent execution: Since WP-Cron depends on user visits, tasks might not run exactly on schedule. If your site has low traffic, scheduled posts or emails may be delayed.
- Overhead on every request: On busy sites, WP-Cron is triggered more often, which can create unnecessary server load. Multiple concurrent visitors may even cause overlapping cron executions.
- Unreliable on Caching/Headless setups: If your site uses aggressive caching or serves content statically (e.g., via a CDN),
wp-cron.phpmay not trigger reliably. - Can be exploited: Since
wp-cron.phpis publicly accessible, it can be targeted in DDoS attacks where bots repeatedly call it, putting strain on your server.
Replacing WP-Cron
A system-level cron job (the kind provided by Linux/Unix servers) is far more reliable than WP-Cron. Benefits of using a real cron job:
- Precise timing: Tasks run exactly as scheduled, not just when someone visits.
- Better performance: Reduces overhead on every page request.
- More reliable: Works regardless of traffic volume or caching setup.
- More secure: Limits public exposure of
wp-cron.php.
How to Disable WP-Cron and Use a System Cron Job
Disable WP-Cron
Add this line to your wp-config.php file:
define('DISABLE_WP_CRON', true);Code language: JavaScript (javascript)
It prevents WordPress from auto-loading cron jobs on every page request.
Set up a System Cron Job
SSH to your server and install WP-CLI. Then, in your Ubuntu terminal, use this command to edit the cron table:
crontab -e
Add this line to the cron table:
*/5 * * * * sudo -u www-data wp cron event run --path=/var/www/public/wordpress --due-now > /dev/nullCode language: Shell Session (shell)
- Replace
/var/www/public/wordpresswith your current path. - Press Ctrl + X, then press Y to Close & Save the cron table.
What it means: This cron job runs every 5 minutes. It executes as the www-data user, uses WP-CLI to process all WordPress cron tasks that are currently due within the installation at /var/www/public/wordpress, and discards normal output to keep server logs clean.