TERM · SECURITY

Website stress test

What is a website stress test?

A website stress test measures how many visitors a site takes at once before it slows down or stops. Artificial traffic is raised in steps while response time, error rate and server load are watched. It belongs before a campaign, before Black Friday or before a television slot, run early enough that there is still time to act on what it shows.

Example

A shop plans a two-day campaign with a €2,000 budget and expects around 20,000 visits, most of them in the twenty minutes after the email goes out. 20,000 visits against €2,000 is €0.10 a visit. Before the launch the site is loaded artificially, in steps:

Requests per secondAverage response timeErrors
50.9 s0%
102.4 s1%
208 s17%

The ceiling is about 12 requests a second; the peak needs at least 15, which is five visits a second opening three pages each. The reason is that every page is rebuilt from the database on each visit. With a cache for anonymous visitors and two slow queries fixed, the site holds 45 a second under one second. Without the test, twenty minutes of downtime at the peak would have cost roughly 6,000 visits, about €600 of the budget.

Why it matters for a business

One visitor measures speed; a hundred at once measure capacity. Those are different numbers and they are fixed by different work. A test turns hosting into a decision with a figure behind it: you know the point where the site gives up, and whether it gives up slowly or with errors. A page that crawls at the peak damages the conversion rate exactly when the traffic is most expensive, which is why the test belongs before the campaign rather than in the explanation afterwards.

What to ask

  • Does the test follow the real customer path (listing, product, basket, payment) or only the home page?
  • Does it run against a copy? If it runs against the live site, has the host been told, or will it read it as an attack and suspend the account?
  • What are the targets: requests per second, response time, acceptable error rate?
  • Is the slowest tenth of requests measured, or only the average?
  • Is there a retest after the fixes, and who runs it?

A stress test and website security testing ask the same question from two sides: what the system does under pressure nobody planned for.

A term you do not recognise? Write to us and we will add it.

The glossary grows with the questions we are asked.