Share a Scorecard Instead of a Screenshot: Public Vergate Links
For the longest time, sharing your Vergate results meant a screenshot. "Here's my health score" — a PNG that goes stale the moment anyone fixes anything, and blurry enough that nobody can read the numbers anyway.
That changes now. Every project can generate share links — public URLs that render a clean scorecard anyone can open without a Vergate account.
#What the scorecard shows
- A big health ring (
excellent/good/fair/poor) - Module scores: security, performance, SEO, AEO, accessibility
- A severity summary — counts only: critical / high / medium / low / info
- The technology stack detected on the site
#What it deliberately hides
This was the design constraint, and we were strict about it: no vulnerability details. No finding titles, no endpoints, no evidence, no remediation, no stack-traces, no configuration snippets.
The public payload is safe analytics only — the same discipline our badge verification endpoint uses. A scorecard link can be forwarded anywhere without turning into a vulnerability disclosure.
#The lifecycle
- Create — from the project page, generate a token with an optional label ("Q3 client review") and an expiry (default 90 days, or never).
- Share — paste the link in Slack, an issue comment, a proposal, or your site's footer.
- Revoke — the moment it's no longer wanted, revoke it; the link returns 404 instantly. The doc also logs when a link is last viewed.
#Why share a scorecard at all?
Three reasons we hear from customers:
- Client reports. Instead of pasting a 40-page PDF into an email chain, send one link. It's always current.
- Internal reviews. A team lead can check a project's health without a Vergate account or a permalink into the dashboard.
- Proof of work. The scorecard is an honest, dated snapshot of where the site stands — the same trust mechanic as a badge, but revocable and live.
#Try it
Run a scan on any project, then hit the share button. Copy the link, open it in a private window — that's exactly what your client sees.
Frequently asked questions
What exactly is shared?
The scorecard shows the health grade, module scores (security, performance, SEO/AEO, accessibility), a severity summary (counts only), and the technology stack. It intentionally does NOT include finding titles, endpoints, evidence, or remediation — that stays behind your login.
Who can see the link once it's shared?
Anyone with the link. That's the point: it's for people who should see your health score without creating an account. Revoke it at any time from the project page and the link immediately returns 404.
Does a share link ever leak vulnerability details?
No, by design. The public payload is safe analytics only — the same discipline as our badge verify endpoint. We deliberately never expose finding content on a link that can be forwarded.
How is this different from a badge?
A badge is a forever embed for a verified site. A scorecard link is a living snapshot you can revoke — it reflects the latest scan while the token is active, which makes it useful for client reports and internal reviews.