SAP provides a program to check RFC’s for weak settings: RSRFCCHK.
If you start the program select all the destinations and optionally the connection test to see if the connections work at all. The result will give you a list of potentially dangerous RFC connections and the user ID’s used. This you can use as a worklist for checking.