Why do you asume that even a teenager who's learnt something about vulnerabilities of web apps, will only try to find a bug typical for i.e. Rails?
It's more likely your app will become a target when it's popular among users.
It's more likely your app will become a target when it's popular among users.
This is possible because it can be computer-automated.
If you're in a situation where a teenager has to get bored and specifically tinker with your niche software then you may already be a large step ahead.
I mean, right? If we take it as true (as many are claiming here) that all web frameworks have security vulnerabilities and Rails is just being picked on because of its popularity, then you essentially need to make the decision between having 24/7 ability to quickly upgrade all of your running Rails installations, or using something not as popular.