One possible big disadvantage for a site owner in letting people pay with money instead of data is dealing with taxes.
I'm not actually sure how most jurisdictions tend to classify it when someone comes to your site and you charge them to access your content. My guess would be it would be taxed the same way they tax digital goods such as downloadable software that does not include any physical components.
For such goods most jurisdictions that tax them seem to base the tax on the buyer's location rather than the seller's location, so the seller has to deal with charging the appropriate tax and filing returns for potentially a large number of jurisdictions.
If the seller is providing the content for "free" and making their money selling visitor data to advertisers then their income will probably only be subject to taxation in their own jurisdiction. It will simply be ordinary business income.
It would be a net benefit for everyone, including the US, if it's broken taxation system becomes a national emergency and finally gets fixed.
It is less necessary, but can be useful, to prevent repeated login attempts (rate limiting works there).
For accessing a website it's completely inexcusable.
I can keep you out of your account indefinitely with a curl loop and a rotation of proxies?
Rate limiting is completely ineffective in preventing credential stuffing attacks from determined adversaries. The challenge is not brute-forcing, but credential leaks and password reuse. Attackers have access to vast seas of IP addresses and in my past life doing the defending, we would see an IP address involved in automation twice, and then it would go away forever.
Only if there isn't some shared knowledge between the website and prospect.
For example some niche websites that I use have locally-based challenges such as 'how many engines can be fitted to a Boeing 747-400'* or a short mathematical algebra to solve.
Both approaches work without Javascript and without external support, just with a two-column table and a trusted group of challenge-creators.
* it's more than four
Because the reason why https://en.wikipedia.org/wiki/Hashcash wasn't useful for anti-spam after all is because attackers have access to the cheapest compute in the world: botnets and devices that aren't their own.