How to Enable Leech Protection in cPanel
Leech Protection is a handy cPanel security feature that watches password-protected areas of your site and takes action if a single login is suddenly used by many people at once — a classic sign that the password has been leaked or shared publicly. It is especially useful for members-only areas.
What Leech Protection does
You set a maximum number of logins allowed within a two-hour window for a protected directory. If an account exceeds it — suggesting the password is being passed around — cPanel can suspend the account, redirect the culprit, and alert you.
Enable Leech Protection in cPanel
- Log in to cPanel and open Security → Leech Protection.
- Select the directory you want to protect (usually one you have password-protected).
- Set the number of logins allowed per two hours.
- Optionally add a redirect URL for offenders and enable email alerts.
- Tick Disable Compromised Accounts for the strongest response, then Enable.
Use it alongside directory protection
Leech Protection works on directories you have secured with a password. If you have not set that up yet, protecting a folder first gives Leech Protection something to guard. Pair it with strong passwords and, where possible, two-factor authentication.
Frequently asked questions
Who is Leech Protection for?
It is ideal for membership sites, paid content areas, or any protected directory where a shared password could let in people who should not have access.
What counts as a “leeched” login?
An unusually high number of logins to one account in a short time, which suggests the credentials have been shared or stolen.
Will it lock out legitimate users?
Set the limit sensibly for your real usage. If genuine users share a login (which is best avoided), give each their own account instead.
Was this article helpful?