What Steel Security checks
Whether the expected JSON reporter exists, is readable, contains valid JSON, includes a recognizable timestamp, and appears current enough to trust.
Whether the reporter indicates that Fail2Ban is active, stopped, partial, or unsupported for this Steel build.
Per-jail telemetry such as current bans, total bans, current failures, and total failures when the reporter exports those metrics.
Reporter states
Steel distinguishes between missing, restricted, inaccessible, empty, malformed, missing-timestamp, stale, unsupported-schema, and current reporter states.
- Current: reporter returned valid, current telemetry
- Partial telemetry: the reporter is current, but one or more jail records are incomplete
- Stopped: telemetry is current, but the Fail2Ban daemon is not actively running
- Stale: reporter exists but freshness is too old to trust as current visibility
- Malformed: JSON could not be interpreted safely
- Unsupported schema: the reporter is newer than the current Steel parser understands
- Inaccessible or restricted: WordPress cannot read the reporter from this environment
What you can see when telemetry is healthy
Service state and reporter health.
Active jail count and jail names.
Current total banned count and total ban count.
Per-jail current bans, total bans, current failures, and total failures.
- Expected reporter path: `/var/lib/fail2ban-json-reporter/status.json`
Recommended action
If the reporter is stale, malformed, unsupported, or stopped, confirm Fail2Ban directly with the host or server administrator and repair the reporter before treating the signal as trustworthy.
If no reporter is connected, ask the server administrator to install the Fail2Ban JSON reporter instead of trying to give WordPress direct `fail2ban-client` access.