Accurate guidance for Steel Security Free and Steel Security Pro

Hardening Overview

The Hardening page documents and controls preventive changes using the same logic that feeds related scanner findings.

Hardening Free / Pro Updated August 9, 2026

What this means

Hardening in Steel Security is organized by the same operator-facing sections shown in the plugin: Access & Authentication, Public Exposure, Content & Editing, and Uploads & Execution.

The grouped Hardening page is meant to make preventive changes understandable in context instead of presenting a flat checklist of toggles.

What Steel Security can do

Steel can directly enable selected controls such as disabling XML-RPC, hiding login error detail, restricting REST user endpoints, renaming the default `admin` username, and hiding the default login URL.

Some items remain advisory-only, such as `FORCE_SSL_ADMIN` and `DISALLOW_FILE_MODS`, because Steel does not currently treat them as universally safe to change automatically.

Rollback / Recovery

Where Steel changes runtime options or scoped server configuration, rollback is expected to be available from the same hardening page.

Uploads PHP execution blocking supports managed rollback on Apache/LiteSpeed and IIS. Nginx receives manual guidance instead of a pretend “fix” button.

Continue reading