What this means
Steel Security does not assume a site is risky just because it has never been scanned. Instead, the current workflow prompts you to run a scan explicitly.
How to run it
Open `Steel Security` in WordPress admin.
Use the `Run Scan` button from the dashboard or scan page.
Wait for the run to complete, then review the grouped results by severity and category.
- Dashboard `Open Scan` action
- Scan page `Run Scan` button
- Recommended Actions if the site has never been scanned
What changes after the first scan
The dashboard begins showing a current risk score, counts by severity, and a last-scan status message.
Recommended Actions switch from first-run guidance to actual site-specific next steps.
If Pro is active, stored runs can feed history, change tracking, and scheduled reporting.
If the scan fails
A failed scan should not destroy previous completed results. The scan state is marked failed, and the UI keeps the failure visible instead of pretending the data is current.
Individual checks are expected to degrade to `Skipped` findings when possible rather than breaking the entire scan.