Security posture dashboard
Read the Vulnara dashboard - security score, open findings, trend, scan activity, remediation and finding age - and choose the period deltas are measured over.
The dashboard is the first screen after you sign in. It answers "how are we doing?" for your workspace: your security score, what is open right now, how that moved over the period you pick, and what needs attention first.

What it is for
- A single view of your security posture to check each day or share in a review.
- Spotting what changed: new and resolved findings, score movement and failed scans over the last 7, 30 or 90 days.
- Jumping straight to the findings, repositories or settings that need work. Most figures open the matching list when you select them.
How it works
State and period
The dashboard shows two kinds of number:
- State: what is open right now. Open findings, their severity split, the remediation counts, finding age and scan coverage are always current. The period never filters them.
- Period: what happened in the window you pick. Scan activity and the score trend cover the period, and every change figure ("vs 30 days ago") compares the current state with the state at the start of the period.
So switching from 30 to 7 days does not change how many findings are open. It changes what they are compared against.
What counts as open
Open findings come from the latest scan of each repository by each scanner, with the same finding from several scanners or commits counted once. A finding that has been fixed drops out when the next scan no longer reports it. See One finding, many scanners.
What you can set
- Period: 7 days, 30 days or 90 days. The default is 30, and your choice is remembered for your next visit.
The panels, from top to bottom:
- Health banner: problems that stop Vulnara working well, each with a link to fix it: git tokens rejected by their provider, tokens expiring within 14 days, failed scans in the period, git workspaces not synced in over 30 days, alert email for the cycle used up, and, for Editors and Admins, a workspace with no active alert rule. It is hidden when there is nothing to report.
- Security score: your workspace's headline score out of 100 with its band (Strong, Good, Fair or Needs attention) and its change over the period. See Security score.
- Open findings by severity: the open total split by severity, with how many were new and how many resolved in the period. Next to it, separately:
- Confirmed by 2+ scanners: findings more than one scanner reported, the least likely to be false positives. Open it to list them with severity, repository, file or library and the scanners that agreed, and select one to open it in the explorer.
- Dismissed: findings a decision says are not real or already dealt with. They are out of the count and the score.
- Deferred: findings a decision took out of the working list. They still count against the score.
- Repositories never scanned: how many repositories have no scan yet. They are unknown risk and are left out of the score.
- Security score over time: the score trend for the period. It needs at least two points to draw.
- Scan Activity: succeeded and failed scans per day in the period.
- Needs attention: the repositories with the lowest scores and the most critical or high findings, and git workspaces that have gone stale.
- Remediation: the funnel from open findings to Issues opened, Fix PRs opened and Fix PRs merged, and how many dependency findings have a fixed version available. See Issues and AI fix pull requests.
- How long findings have been open: open findings in the age buckets 0-7, 8-30, 31-90 and 91+ days, with the age of the oldest open finding and the oldest open critical.
- Plan usage this cycle: repositories, scan minutes and alert emails used against your plan. See Plans and billing.
- Stat tiles: totals for git workspaces, repositories, open findings and users. These are not tied to the period.
Do it
- Sign in at vulnara.rso.dev and open Dashboard.
- Pick 7 days, 30 days or 90 days at the top.
- Select a severity, a count or a repository to open the matching list.
- Use Download report for a PDF of the same picture. See PDF reports.
The same data is available through the API:
- GraphQL: dashboardAnalytics with
daysfrom 1 to 365, and statistics for the stat tiles. - MCP (read only): dashboard_analytics and statistics.
query {
dashboardAnalytics(days: 30) {
averageSecurityScore
previousAverageSecurityScore
exposure {
total
previousTotal
newFindings
resolvedFindings
corroboratedFindings
}
}
}Good to know
- A new workspace sees a Get started with Vulnara guide instead of the charts: connect a git workspace, import repositories and run your first scan. The charts appear once you have at least one repository.
- A finding's age is measured from the first time Vulnara saw it in that repository, not from the latest scan. A rescan does not make an old finding new.
- Failed and cancelled scans both count as failed in Scan Activity. They get no score and do not affect the average.
- The confirmed-by-scanners list can be shorter than the count on a large workspace. It then says how many of the total it is showing.
- The last point of the score trend always equals the headline score.
- If the dashboard cannot load, it says so and offers Try again. It does not show an empty dashboard as if everything were clean.