A vulnerability finding is not a work order
A security report that says "12 issues" has told you almost nothing. Twelve of what? Confirmed against the versions you actually run, or twelve advisories that merely mention a plugin you have installed?
Three states, deliberately kept apart
- Confirmed — the advisory applies to the component and version actually installed. This is real work.
- Needs review — applicability could not be established. It is not a severity; it is an open question.
- Not applicable — the component is not present, or the affected condition does not exist on this site.
Merging these produces a number that looks urgent and cannot be acted on. Worse, it teaches operators that the number is unreliable — and once that happens, the genuinely confirmed item is lost inside it.
Never recommend an update that does not exist
Some advisories have no corrected release. The honest response is to say so: the issue is real, no fix has been published, and the decision is whether to accept the risk, replace the component, or mitigate around it. Offering an "Update" button that leads nowhere is worse than offering nothing.
Recording a decision is not the same as fixing
Accepting a risk is a legitimate professional decision, and it should be recorded as one. But recording it does not close the technical finding — the condition still exists, monitoring continues, and if a corrected release appears later the decision can be revisited. Keeping those two facts separate is what makes the record trustworthy months afterwards.
Run this on a site you manage
Public evidence only, no account required — and the result names exactly which facts it established.