CleanTalk Surface.php timeouts causing customer-facing HTTP 500 errors
-
Hello CleanTalk Support,
we have identified a serious issue with Security by CleanTalk 2.186 on our production WooCommerce store.
Since August 31, 2026, our WooCommerce fatal error logs contain thousands of recurring identical errors:
Maximum execution time of 120 seconds exceededFile:
wp-content/plugins/security-malware-firewall/lib/CleantalkSP/SpbctWP/Scanner/Surface.phpLine:
463The errors have continued continuously since August 31, usually around 1,500 times per day.
We initially thought these might only be internal scanner/background errors. However, we have now correlated the CleanTalk fatal-error log with our Apache access log for September 7.
On September 7:
- 1,365 HTTP requests returned status 500
- 1,326 of those HTTP 500 requests ran for approximately 122–129 seconds before failing
- 1,234 of these long-running HTTP 500 requests terminate at the same second, or within ±1 second, as one of the recurring CleanTalk
Surface.php:463timeout fatals
These are not limited to background/scanner endpoints. The affected requests include normal public WooCommerce/frontend traffic such as:
- product pages
- cart
- checkout
- order-received / order-pay
- My Account
- WordPress REST requests
- admin-ajax requests
- normal landing pages
We therefore have strong evidence that the CleanTalk issue is currently causing real customer-facing HTTP 500 responses, not merely filling the error log.
This morning, September 8, a customer also reported receiving WordPress’ generic “There has been a critical error on this website” message immediately after successfully paying via Amazon Pay at approximately 06:29 local time. The payment itself was completed successfully. Multiple identical CleanTalk
Surface.phptimeout fatals occurred around that time as well.We cannot yet correlate that particular request with today’s Apache access log because our hosting provider only makes the daily access log available after the day has ended. Therefore we are not claiming yet that CleanTalk caused this specific Amazon Pay incident, but it is consistent with the customer-facing HTTP 500 pattern we have already confirmed for September 7.
The plugin currently shows the last completed malware scan as August 30, although these
Surface.phperrors started on August 31 and have continued around the clock since then.We can see that Security by CleanTalk 2.187 is available. However, this is a high-traffic production WooCommerce store, and we do not want to perform an unverified security-plugin update or disable the firewall without knowing that it addresses the actual problem.
Could you please urgently confirm:
- Is this exact
Scanner/Surface.php:463 – Maximum execution time of 120 seconds exceededissue known in version 2.186? - Does version 2.187 specifically fix this exact issue?
- If yes, which fix/change in 2.187 addresses it?
- Why is
Scanner/Surface.phpapparently being invoked continuously even though the last malware scan shown in the plugin completed on August 30? - Is there a safe temporary way to stop only the affected Scanner/Surface process while keeping Security Firewall and WAF fully active?
- Is it safe to leave the current situation running, considering that we have confirmed customer-facing requests ending in HTTP 500 after approximately 120 seconds?
We can provide the WooCommerce fatal-error logs and the Apache access log privately if you need them for investigation.
Because this is now demonstrably affecting production HTTP requests, we would appreciate an urgent technical response rather than a general recommendation to update to the latest version.
Thank you.
Best regards
Monika
The page I need help with: [log in to see the link]
You must be logged in to reply to this topic.