Although the safe scans are supposed to be "safe" there are some plugins that can cause undesired results. A good example is when you scan a network with all plugins enabled and you hit a bunch of network printers. The scan requests caused them to print reams of garbage. Not that I ever did that. But I heard about it from a friend

Now Nessus has a checkbox in the policy to skip "sensitive" devices.
To find the web app vulns you may want to utilize something like Nikto or Burp suite.