What Steel Security checks
Pro deep providers currently include public backup directories under `wp-content`, suspicious PHP-family files in uploads, sensitive file permissions, public identity-style REST routes, and MU-plugin authentication overrides.
What scan history adds
Stored runs with timestamps, mode, finding counts, environment metadata, trend points, and run-to-run diffs.
Recommended action
Use history to understand whether the site is trending safer or accumulating new exposure over time.