Skip to main content

How Findings Are Categorized

Why Findings Are Categorized

Steel Security groups findings into categories to make them easier to understand and act on.

Each category represents a different type of security concern.

This structure helps you quickly identify where issues exist within your site.


Main Categories

Findings are organized into the following core categories:


File Exposure

Examples include:

  • configuration files
  • backup files
  • directory listings

Execution Risks

Issues that allow code to run in unintended ways.

Examples include:

  • PHP execution in upload directories
  • direct access to internal scripts

System & Information Exposure

Issues where your site reveals internal details.

Examples include:

  • debug mode enabled
  • version information exposed
  • system metadata leakage

Endpoint & Access Risks

Examples include:

  • XML-RPC enabled
  • unrestricted access to sensitive endpoints

Security Headers

Examples include:

  • missing security headers
  • incomplete header configuration

How to Use Categories

Categories help you:

  • focus on specific types of risk
  • address related issues together
  • understand how findings connect to hardening controls

You may choose to resolve findings category by category, or prioritize based on severity.


How Categories Connect to Hardening

Each category aligns with a set of hardening controls.

For example:

  • file exposure findings → file protection controls
  • execution risks → execution controls
  • headers → security header configuration

This alignment makes it easier to move from detection to resolution.


What to Do Next

  • review findings within each category
  • prioritize based on severity and relevance
  • apply corresponding hardening controls