What this means
Hardening in Steel Security is organized by the same operator-facing sections shown in the plugin: Access & Authentication, Public Exposure, Content & Editing, and Uploads & Execution.
The grouped Hardening page is meant to make preventive changes understandable in context instead of presenting a flat checklist of toggles.
What Steel Security can do
Steel can directly enable selected controls such as disabling XML-RPC, hiding login error detail, restricting REST user endpoints, renaming the default `admin` username, and hiding the default login URL.
Some items remain advisory-only, such as `FORCE_SSL_ADMIN` and `DISALLOW_FILE_MODS`, because Steel does not currently treat them as universally safe to change automatically.
Rollback / Recovery
Where Steel changes runtime options or scoped server configuration, rollback is expected to be available from the same hardening page.
Uploads PHP execution blocking supports managed rollback on Apache/LiteSpeed and IIS. Nginx receives manual guidance instead of a pretend “fix” button.