Sometimes you apply a fix, re-run the scan, and the test still fails or reports that it could not determine the status.
This often happens on:
- Local development sites on your computer
- Sites with a maintenance or “coming soon” plugin
- Password-protected staging sites
Some tests pretend to be a normal browser visitor. If anything blocks or redirects that request, the test cannot see the real public response and may fail.
Local setups also differ from production servers (self-signed SSL certificates, different file permissions, hosts-file URLs). Treat those failures as environment noise unless the same test fails on a publicly reachable production site.
SSL on local development
Self-signed certificates are common locally and are not trusted like a public Certificate Authority certificate. Tests that inspect HTTPS behavior can fail even when your local site “works” in the browser after you accept the warning.
Tests that often fail in those environments
- Check if the
expose_phpPHP directive is turned off - Check if the uploads folder is browsable
- Check if the admin interface is delivered via SSL
- Check if
readme.htmlis accessible - Check if
license.txtis accessible - Check if
install.phpis accessible - Check if
upgrade.phpis accessible
Related: Maintenance and password-protected sites.