Handing over your main cPanel login gives one person total control of every site, mailbox and database on the account, with no way to tell their actions apart from yours.
BETTER OPTIONS
Create a dedicated FTP account limited to the folder they are working in. cPanel > FTP Accounts, and set the Directory to that site's folder only. Create a separate application user. In WordPress, add them as an Administrator with their own login rather than sharing yours. Create a separate database user if they only need database access. Use a password manager's sharing feature rather than emailing credentials.
DURING THE WORK
Ask them to work on a staging copy rather than the live site where practical. Take a backup before the work begins. Keep a note of what access you granted and when.
WHEN THE WORK FINISHES
Delete the FTP account Delete or demote the application user Change any password you did share Check for new admin users, scheduled tasks or unfamiliar files Review cPanel > Cron Jobs for anything they added
This is not about distrust. Accounts are frequently compromised through a former developer's credentials long after the relationship has ended, often because that developer's own computer was infected.