Don't hand a developer your portal login. Change the hosting account password (sometimes called the cPanel password) to a new value, give the developer that plus your domain and FTP/SSH host details, and rotate it again when the work is done. That keeps your portal identity, billing, and account settings untouched while giving them exactly the access they need to do the job.
The portal login controls billing, domain settings, and account-level changes. The hosting account password controls FTP, SFTP, SSH, and some legacy tools. A developer almost never needs the first one.
Set up scoped access
Go to Services, click your hosting service, and use Change password to set a new hosting account password. Share that password plus the connection details (your domain, and sftp://yourdomain.com or SSH host if they need shell access) through a secure channel, not plain email. See Changing your hosting account password for what this password does and doesn't touch, and what breaks when you rotate it.
If the developer only needs to upload files, an FTP account is tighter than handing out the main hosting password. Log in to cPanel from the service page (One-Click Login) and create one under FTP Accounts. If you're running multiple sites on one account, see Addon domains, aliases, and subdomains for how those folders are laid out.
Working in WordPress
In WordPress itself, create the developer their own administrator account instead of sharing yours, and remove it when they're done. This also sidesteps file-level access entirely for theme and plugin work.
What not to share
- Your portal password. It reaches billing, domain transfer controls, and every service on the account, not just the one site the developer is working on.
- Your Support PIN. That's for verifying your identity on sensitive account changes over a ticket or chat, not for day-to-day work.
- Email account passwords, unless the job specifically requires managing mail. Each mailbox has its own password for a reason.
Revoke access when the work is done
Rotate the hosting account password again once the project wraps, delete any FTP accounts you created specifically for the developer, and remove their WordPress user if you added one. If you suspect a password was shared more broadly than intended, or a former developer still has access somewhere you can't account for, treat it the same as any suspected compromise: rotate the password immediately and check for changes you didn't make.
When to contact support
If a developer set up something you can't find (a cron job, a database user, an SSH key you don't recognize) and you're not sure it's safe to remove, open a ticket from the portal's Support section rather than guessing. A real person can walk through what's on the account with you before anything gets deleted.