Playing out the web application infiltration testing as a feature of your Software Development Life Cycle or SDLC interaction would be the awesome most practical technique in warding off web application vulnerabilities.
See All 8 Episodes of "Automate Your Web Application: Penetration Testing"