Automated Qualys Vulnerability Scorecard
Every Monday, WebRun opens Qualys, reviews the latest vulnerability scan results, logs critical and high severity findings by asset into Google Sheets, and posts a scorecard to Notion showing counts and trend against last week.
How do I track Qualys vulnerability findings week over week without a manual export?
WebRun reviews Qualys vulnerability scan results every Monday, logs critical and high severity findings by asset into Google Sheets, and posts a trending scorecard to Notion comparing this week against last. It never patches or remediates a finding itself, so every fix stays a deliberate step for your engineering team.
- Critical and high findings are tracked by asset every week, not per scan
- Trend against last week is visible at a glance in Notion
- Remediated findings close automatically instead of lingering on the list
Built for vulnerability management teams · security engineers · IT admins · CISOs
What does WebRun do on every run?
The exact actions WebRun takes, in order - in plain language, so you can adjust anything.
-
WebRun signs in and gets to work
Opens
www.qualys.comin a real browser with your saved login - no setup, no API keys. -
1
Qualys - review scan results
WebRun opens Qualys to review scan results. - Open Qualys and review the latest vulnerability scan results
- Filter to critical and high severity findings
- Note the affected asset and days open for each
Done when This week's critical and high findings are listed by asset.
-
2
Google Sheets - log findings by asset
WebRun opens Google Sheets to log findings by asset. - Open the vulnerability tracker in Google Sheets
- Add a row for each new finding with asset, severity, and days open
- Mark previously listed findings as closed once remediated
Done when The Google Sheets tracker matches this week's findings.
-
3
Notion - post the scorecard
WebRun opens Notion to post the scorecard. - Open the security page in Notion
- Post a scorecard showing counts of critical and high findings, and the trend versus last week
- Link to the Google Sheets tracker for full detail
Done when The Notion page shows this week's vulnerability scorecard.
How is each run configured?
Secure by default
Connect once, stays signed in
WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.
Every action is checked against this policy before it runs.
Questions, answered
Does WebRun patch or remediate anything itself?
No. WebRun only reads scan results and reports them. Patching or remediating a vulnerability is a manual step your engineering or IT team takes.
Does it scan anything new itself?
No. It only reads results from scans Qualys already ran. Kicking off a new scan stays a manual action in Qualys.
What happens to a finding once it's fixed?
It reads the live status each Monday, so anything remediated is marked closed in the Google Sheets tracker automatically.
Put this on autopilot.
Turn it on in minutes - or have our team set it up for you.