How Findings Are Categorized

Why Findings Are Categorized

Steel Security groups findings into categories to make them easier to understand and act on.

Each category represents a different type of security concern.

This structure helps you quickly identify where issues exist within your site.


Main Categories

Findings are organized into the following core categories:


File Exposure

Examples include:


Execution Risks

Issues that allow code to run in unintended ways.

Examples include:


System & Information Exposure

Issues where your site reveals internal details.

Examples include:


Endpoint & Access Risks

Examples include:


Security Headers

Examples include:


How to Use Categories

Categories help you:

You may choose to resolve findings category by category, or prioritize based on severity.


How Categories Connect to Hardening

Each category aligns with a set of hardening controls.

For example:

This alignment makes it easier to move from detection to resolution.


What to Do Next



Revision #1
Created 2026-04-04 18:46:57 UTC by Jason Wassing
Updated 2026-04-04 18:46:58 UTC by Jason Wassing