Disclaimer: I work for CodeRabbit.
I'm afraid that some issues could arise at runtime, such as CORS problems, which even an experienced developer might overlook.
I don't believe this is simply a list of static analysis issues that SonarQube can identify. One of the advantages of using AI (despite its tendency to hallucinate and be overly picky about minor details) is its ability to generate a fix or several variations of fixes that we can test.
P.S. This gave me a good idea to check if I can run the community edition for testing purposes.