Understanding Scan Findings
What Scan Findings Are
Scan findings are the results generated when Steel Security analyzes your WordPress site.
Each finding highlights a potential risk, exposure, or configuration issue that may affect your site's security.
Why Findings Matter
Findings help you understand where your site may be vulnerable.
They are designed to:
- identify potential security risks
- highlight areas of unnecessary exposure
- guide you toward practical improvements
Not all findings indicate an immediate threat, but each represents an opportunity to strengthen your site.
How Findings Are Organized
Steel Security groups findings into logical categories to make them easier to understand and act on.
These categories may include:
- file exposure
- execution risks
- system and information exposure
- endpoint and access risks
- security headers
Grouping findings helps you focus on specific areas of your site.
Understanding Severity
Each finding is assigned a severity level to help prioritize action.
Severity reflects the potential impact and likelihood of exploitation.
Typical severity levels include:
- High — significant risk, should be addressed promptly
- Medium — moderate risk, should be reviewed and resolved
- Low — lower risk, but still worth addressing
Severity helps guide your response, but should not be the only factor in decision-making.
How to Approach Findings
When reviewing findings:
- start with higher severity items
- review the context of each finding
- determine whether the issue applies to your site
- apply fixes where appropriate
- test your site after making changes
Avoid applying changes blindly — understanding the impact is important.
Not All Findings Require Action
Some findings may:
- reflect intentional configuration choices
- be acceptable based on your use case
- require a balanced decision between security and functionality
Steel Security provides guidance, but final decisions depend on your environment.
How Findings Connect to Hardening
Each finding typically corresponds to a hardening control.
For example:
- exposed files → file protection controls
- execution risks → execution restrictions
- missing headers → security header controls
This relationship helps you move from detection to resolution.
What to Do Next
After reviewing your findings:
- prioritize based on severity and relevance
- apply appropriate hardening controls
- verify changes after implementation
- continue monitoring over time
Key Principle
Findings are not just warnings.
They are actionable insights that help you improve your site's security posture over time.
Related
- Reviewing Findings
- Hardening Reference
- [Defense in Depth with Steel Security](https://docs.steelsecurity.com/books/hardening-reference/page/defense-in-depth-with-Steel Security)