Skip to main content

Understanding Scan Findings

What Scan Findings Are

Scan findings are the results generated when Steel Security analyzes your WordPress site.

Each finding highlights a potential risk, exposure, or configuration issue that may affect your site's security.


Why Findings Matter

Findings help you understand where your site may be vulnerable.

They are designed to:

  • identify potential security risks
  • highlight areas of unnecessary exposure
  • guide you toward practical improvements

Not all findings indicate an immediate threat, but each represents an opportunity to strengthen your site.


How Findings Are Organized

Steel Security groups findings into logical categories to make them easier to understand and act on.

These categories may include:

  • file exposure
  • execution risks
  • system and information exposure
  • endpoint and access risks
  • security headers

Grouping findings helps you focus on specific areas of your site.


Understanding Severity

Each finding is assigned a severity level to help prioritize action.

Severity reflects the potential impact and likelihood of exploitation.

Typical severity levels include:

  • High — significant risk, should be addressed promptly
  • Medium — moderate risk, should be reviewed and resolved
  • Low — lower risk, but still worth addressing

Severity helps guide your response, but should not be the only factor in decision-making.


How to Approach Findings

When reviewing findings:

  1. start with higher severity items
  2. review the context of each finding
  3. determine whether the issue applies to your site
  4. apply fixes where appropriate
  5. test your site after making changes

Avoid applying changes blindly — understanding the impact is important.


Not All Findings Require Action

Some findings may:

  • reflect intentional configuration choices
  • be acceptable based on your use case
  • require a balanced decision between security and functionality

Steel Security provides guidance, but final decisions depend on your environment.


How Findings Connect to Hardening

Each finding typically corresponds to a hardening control.

For example:

  • exposed files → file protection controls
  • execution risks → execution restrictions
  • missing headers → security header controls

This relationship helps you move from detection to resolution.


What to Do Next

After reviewing your findings:

  • prioritize based on severity and relevance
  • apply appropriate hardening controls
  • verify changes after implementation
  • continue monitoring over time

Key Principle

Findings are not just warnings.

They are actionable insights that help you improve your site's security posture over time.