Accurate guidance for Steel Security Free and Steel Security Pro

Artifact and Backup Discovery

Steel Security looks for publicly reachable files and archives that often exist by accident rather than by design.

Scanning Free Updated August 9, 2026

What this means

Files such as `.env`, `wp-config` backups, `phpinfo` scripts, SQL dumps, and backup archives can reveal credentials, configuration, or full site data to anyone who can request them.

What Steel Security checks

Root-level checks for `.env`, `wp-config.php` backups, `wp-config` backups, `phpinfo` scripts, SQL dumps, and backup archives.

Recursive pattern discovery for SQL dumps and backup archives deeper inside the site tree, with bounded depth and match limits.

Recommended action

If an artifact is still needed, move it out of the public site tree.

If it is no longer needed, quarantine it first so you can review and restore it if required.

What Steel Security can do

For file-based findings, Steel can offer quarantine actions instead of deleting files blindly.

Continue reading