How Findings Are Categorized
Why Findings Are Categorized
Steel Security groups findings into categories to make them easier to understand and act on.
Each category represents a different type of security concern.
This structure helps you quickly identify where issues exist within your site.
Main Categories
Findings are organized into the following core categories:
File Exposure
Examples include:
- configuration files
- backup files
- directory listings
Execution Risks
Issues that allow code to run in unintended ways.
Examples include:
- PHP execution in upload directories
- direct access to internal scripts
System & Information Exposure
Issues where your site reveals internal details.
Examples include:
- debug mode enabled
- version information exposed
- system metadata leakage
Endpoint & Access Risks
Examples include:
- XML-RPC enabled
- unrestricted access to sensitive endpoints
Security Headers
Examples include:
- missing security headers
- incomplete header configuration
How to Use Categories
Categories help you:
- focus on specific types of risk
- address related issues together
- understand how findings connect to hardening controls
You may choose to resolve findings category by category, or prioritize based on severity.
How Categories Connect to Hardening
Each category aligns with a set of hardening controls.
For example:
- file exposure findings → file protection controls
- execution risks → execution controls
- headers → security header configuration
This alignment makes it easier to move from detection to resolution.
What to Do Next
- review findings within each category
- prioritize based on severity and relevance
- apply corresponding hardening controls