I guess people would pay for a service that could identify 90% of all security issues with an online service by going through source code and available routes. Anything that is available today?
http://pentestlab.wordpress.com/2012/11/27/automated-source-...
https://www.owasp.org/index.php/Static_Code_Analysis
http://code.google.com/p/yara-project/
http://www.lightbluetouchpaper.org/ (the 3rd post
(these aren't the services, these are what you shd read to decide if some service's operatives are appropriately expensive, and up on current research