Most Salesforce orgs are carrying security debt they don't know about. This plugin surfaces it in a single command.
TL;DR: Install @cclabsnz/sf-audit, run sf audit security --target-org <alias>, get an HTML report with a health score, a grade, and a prioritised list of findings.