1) Static analysis security vulnerability
2) Coding practises & convention
https://github.com/rubocop/rubocop-rails
3) 3rd party library vulnerability
https://github.com/jeremylong/DependencyCheck
4) Security headers in general
5) CSP header
https://csp-evaluator.withgoogle.com/
6) Javascript dependencies vulnerability scan (static)
$ npm audit
7) Javascript dependencies vulnerability scan
https://geekflare.com/tools/js-vulnerability-scanner
8) SSL configuration test