1) Static analysis security vulnerability

https://brakemanscanner.org/

2) Coding practises & convention

https://github.com/rubocop/rubocop-rails

3) 3rd party library vulnerability

https://github.com/jeremylong/DependencyCheck

4) Security headers in general

https://securityheaders.com/

5) CSP header

https://csp-evaluator.withgoogle.com/

6) Javascript dependencies vulnerability scan (static)

$ npm audit

7) Javascript dependencies vulnerability scan

https://geekflare.com/tools/js-vulnerability-scanner

8) SSL configuration test

https://www.ssllabs.com/ssltest/