This is a really useful service for what we call "version tracking," and it looks like it's running Brakeman for you too. With that said, it won't find vulnerabilities you code in yourself - only publicly released vulns that Ruby, etc. have issued patches for. A tool like https://www.tinfoilsecurity.com can help you find more vulnerabilities that either a) haven't been found yet publicly or b) you've written in yourself. (Disclosure: I'm the cofounder)