You make me sit there and wait for the results of a scan of a website and then don't show me it? You then ask me to create an account to view my 2 "borderline-unsecure" vulnerabilities? Ok, account created with dummy email. Oh whats this? I still can't view the results? I have to upload shit to my production site in order to just view the results? Did you even actually find anything wrong?
I understand the security implications of having someone verify they do indeed own the site scanned...but this bait and switch crap is infuriating. If you are going to go down that route, at least message it somewhere...clearly.