Leech Protection works with password-restricted directories to detect unusually frequent logins to the same protected account.
You configure the maximum number of logins allowed for a user within a two-hour period. cPanel can redirect users who exceed the limit, send an alert, and optionally disable the compromised directory user.
This feature is aimed at shared or leaked directory credentials; it is not general website-login rate limiting for applications such as WordPress.