What this means
Scheduled reporting does not run a fresh scan by itself. It emails a report built from the selected stored scan run mode.
What Steel Security checks
A valid active license.
Scheduled report emails enabled in settings.
At least one stored scan run available.
At least one valid recipient address, or a valid WordPress admin email fallback.
Recommended action
Confirm that Pro is active on the target site, the license is active, scheduling is enabled, and scan history exists before troubleshooting mail delivery.
Important implementation note
The current Pro code now preserves due report-email cron events on normal page loads instead of clearing and recreating them on every `init`. This prevents due email jobs from being pushed into the future before WordPress cron can execute them.
Server or hosting considerations
If WordPress reports that the scheduled email was sent but it never arrives, the next place to inspect is SMTP or host mail delivery, not Steel Security’s reporting renderer.