What are the key AppExchange security review considerations for an ISV?
Suggested answer
Salesforce conducts a Security Review for all AppExchange listings. Key areas:
Apex security: All SOQL must be secure against SOQL injection (use bind variables, not string concatenation). FLS enforcement — check field visibility before reading/writing. Use WITH SECURITY_ENFORCED or Security.stripInaccessible(). Use with sharing by default.
XSS prevention: Visualforce pages must use {!HTMLENCODE()} for user-controlled data. LWC templates auto-escape but lwc:dom="manual" bypasses this — audit carefully.
CSRF protection: Visualforce pages include CSRF tokens automatically. Custom REST APIs must validate session tokens.
Remote Site Settings / Named Credentials: All external callouts must be documented. Hardcoded credentials are an automatic failure.
Permission sets vs profiles: Package should install with minimal permissions; provide Permission Sets for least-privilege access.
Open redirect vulnerabilities: Do not redirect to user-supplied URLs without validation.
Tools: Salesforce Code Analyzer (PMD rules for Apex security), Checkmarx for SAST scanning. Perform security review early — not at the end of development.
Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.
Community comments (0)
No comments yet.
Sign in or create a free account to add a comment. Comments are moderated before they appear.