Website Security & SSL

How to Enable Leech Protection in cPanel

Leech Protection is a handy cPanel security feature that watches password-protected areas of your site and takes action if a single login is suddenly used by many people at once — a classic sign that the password has been leaked or shared publicly. It is especially useful for members-only areas.

What Leech Protection does

You set a maximum number of logins allowed within a two-hour window for a protected directory. If an account exceeds it — suggesting the password is being passed around — cPanel can suspend the account, redirect the culprit, and alert you.

Enable Leech Protection in cPanel

  1. Log in to cPanel and open Security → Leech Protection.
  2. Select the directory you want to protect (usually one you have password-protected).
  3. Set the number of logins allowed per two hours.
  4. Optionally add a redirect URL for offenders and enable email alerts.
  5. Tick Disable Compromised Accounts for the strongest response, then Enable.

Use it alongside directory protection

Leech Protection works on directories you have secured with a password. If you have not set that up yet, protecting a folder first gives Leech Protection something to guard. Pair it with strong passwords and, where possible, two-factor authentication.

Frequently asked questions

Who is Leech Protection for?

It is ideal for membership sites, paid content areas, or any protected directory where a shared password could let in people who should not have access.

What counts as a “leeched” login?

An unusually high number of logins to one account in a short time, which suggests the credentials have been shared or stolen.

Will it lock out legitimate users?

Set the limit sensibly for your real usage. If genuine users share a login (which is best avoided), give each their own account instead.

Was this article helpful?