Isn't this what static analysis, penetration testing, and various other automated smoke tests made for? Instead of adding to a checklist these tests are updated to account for new vulnerabilities.
This is not how I would recommend running the average startup, but for mission critical software having someone other than the author review all the code using a checklist is probably the best way to ensure quality. The author of the code would have the same checklist and would be expected to hit all the points before handing the code over to the reviewer.