Updating Failed: The Response Is Not a Valid JSON Response
You click Update or Publish in WordPress and get "Updating failed. The response is not a valid JSON response." Your content is usually fine — the editor asked your site to save it and got back something other than the answer it expected.
Common signs of this issue
- A red bar in the WordPress editor says "Updating failed. The response is not a valid JSON response." or "Publishing failed. The response is not a valid JSON response."
- It happens when you click Update, Publish, Save draft, or when you drag an image into a post.
- Some posts save fine while one particular post fails every time, or the error started on every post at once.
- Tools, then Site Health, shows "The REST API encountered an error" or "The REST API encountered an unexpected result".
- It began after installing or updating a security plugin, turning on Cloudflare or a firewall, switching to https, or moving the site.
- Other admin screens work normally — you can log in, see your posts, and change settings.
Safe checks you can do yourself
None of these require sharing passwords with anyone.
- Copy your text somewhere safe first. Select everything in the editor and paste it into a plain document. The error usually means the save did not go through, so do not close the tab until you have a copy.
- Go to Settings, then Permalinks and click Save Changes without changing anything. This rewrites WordPress's address rules and is the single most common fix, especially after a move or a server change.
- Go to Settings, then General and compare WordPress Address (URL) and Site Address (URL). Both should start with the same thing — usually
https://— and match the address in your browser bar, including www or no www. A mismatch here is a classic cause. If the fields are greyed out, they are set in a config file, so note what they say and leave them. - Open yourdomain.com/wp-json/ in a new tab. A healthy site shows a wall of code-like text starting with a curly bracket. If you get a 404 page, a login box, a "403 Forbidden" or "Access denied" message, or a security block page, the editor's saving channel is being blocked, and that page tells you by whom.
- Open Tools, then Site Health and look for a REST API item. Expand it — the details often include a status code such as 401, 403, or 404 and sometimes the name of what blocked the request.
- Try a test: create a new draft with one plain sentence and save it. If that saves but your real post does not, something in the content itself (often pasted code, a script snippet, or text that looks like a database command) is tripping a firewall on the server.
- If you use a security plugin (Wordfence, Solid Security, All In One WP Security, and similar), check its firewall or blocked-requests log for entries at the moment you clicked Update. Many can whitelist the action in one click once you find it.
- If you use Cloudflare, check Security, then Events for blocked requests to paths containing
/wp-json/. Bot-fighting and strict firewall rules can block the editor as if it were an attacker. - Ask your host (or check your browser's developer tools, Network tab, for the red failed request) whether a server firewall like ModSecurity blocked the save. Hosts can see this in their logs in seconds and can usually whitelist the rule for your site.
What this usually means
The WordPress block editor does not save your post the old-fashioned way. It sends your content in the background to your site's REST API (the addresses under /wp-json/) and expects a small, tidy data reply in a format called JSON. When anything else comes back — an HTML error page, a firewall block page, a redirect, a login prompt, or a PHP warning printed before the real reply — the editor cannot read it and shows this message. So the error is a symptom: the real question is what came back instead.
In practice the causes cluster into a few groups. Address problems: broken permalink rules, or the site address set to http while you browse on https, so the request gets redirected. Blocking: a security plugin, a host firewall, or Cloudflare deciding the save looks suspicious — very common when a post contains code snippets or words that resemble a database query, which is why one post can fail while others save. Noise: a plugin or theme printing warnings or notices into the response, which often happens with debug display switched on or right after a PHP upgrade. And occasionally the server itself returns a 500 error because a plugin crashed mid-save.
The good news is that this is rarely data loss and rarely a hack. Your existing posts are untouched; only the latest save failed. Installing the Classic Editor plugin will often make the error disappear, but that is a workaround, not a fix — it bypasses the REST API rather than repairing it, and other things that rely on the REST API (some forms, page builders, WooCommerce admin screens, mobile apps) will stay broken. It is worth finding the actual blocker.
What not to do
- Don't close the editor tab or reload before copying your unsaved text somewhere safe.
- Don't switch off your security plugin or firewall entirely and leave it off. Find the specific rule that blocked the save and whitelist that, or ask your host to.
- Don't edit the WordPress Address or Site Address fields to guess at a fix. A wrong value there can lock you out of the admin completely.
- Don't treat the Classic Editor plugin as the permanent solution. It hides the problem while other features that use the REST API stay broken.
- Don't disable the REST API with a plugin or snippet because an article said it improves security. That is often the exact cause of this error.
- Don't delete and recreate the post that fails. If content is triggering a firewall, the new copy will fail the same way.
When to get help
If re-saving permalinks and checking your site addresses did not help, and /wp-json/ shows a block page, a 500 error, or a redirect loop, the fix is usually in server logs, firewall rules, or configuration files rather than in the dashboard. That is also true when the error only appeared after a move to https or to a new host, because leftover redirects and hard-coded addresses in wp-config.php or .htaccess are easy to make worse by trial and error. Someone who can read the failed request and the server's response will usually identify the blocker in minutes, then whitelist the one rule that needs it instead of weakening the site's security to get the editor working. Related problems are worth a look while you are there: see 401 Unauthorized errors, mixed content warnings, and a plugin update that broke the site.
Glenn, who runs WebsiteSelfHelp, tracks down "not a valid JSON response" errors for small business WordPress sites — permalink rules, security plugin blocks, Cloudflare and host firewalls, and mixed http/https settings. Tell him what you are seeing and when it started, and you will get a clear answer on what it will take to get the editor saving again. No passwords are needed to start the conversation.
Not sure what to do next?
Answer a few short questions and we'll point you to the safest next step — DIY, a freelancer, or a direct review. No passwords required.
Is this a business website? If this issue may be costing you leads, sales, or trust, you may want a direct review instead of trial and error.
Frequently asked questions
What does "The response is not a valid JSON response" mean in WordPress?
The editor tried to save your post through your site's REST API and got back something it could not read — usually an error page, a firewall block page, a redirect, or a PHP warning — instead of the small data reply it expected. The save did not go through.
Did I lose my post?
Usually not. Earlier saved versions are still there, and the text you just typed is still in the open editor. Copy it somewhere safe before reloading. WordPress also keeps a local backup in your browser and may offer to restore it when you reopen the post.
Why does only one post give the updating failed error?
That points strongly at a server or plugin firewall reacting to something in that post, such as pasted code, an embed snippet, or text that looks like a database command. Test by saving a copy with that section removed; if it saves, ask your host or security plugin to whitelist the rule it tripped.
Will installing the Classic Editor plugin fix it?
It often makes the message go away because the classic editor saves differently. But the REST API is still broken underneath, and other features that depend on it will keep failing. Use it as a stopgap while you find the real cause.
Can Cloudflare cause the not a valid JSON response error?
Yes. Firewall rules, bot protection, and some security settings can block or challenge the editor's background requests to wp-json. Check Cloudflare's security events for blocked requests at the time you clicked Update and add an exception for your admin traffic.
Is this error a sign my site was hacked?
Rarely. It is almost always a configuration, firewall, or plugin issue. If you also see unknown admin users, strange redirects, or files you did not add, treat that as a separate warning sign and look into it.
Can I fix it myself?
Often, yes. Re-saving permalinks and correcting a mismatched http/https site address fix a large share of cases. If those do not work and wp-json shows a block page or a server error, the fix usually needs access to logs or firewall settings.