Suggested answer

Salesforce conducts a Security Review for all AppExchange listings. Key areas:

Apex security: All SOQL must be secure against SOQL injection (use bind variables, not string concatenation). FLS enforcement — check field visibility before reading/writing. Use WITH SECURITY_ENFORCED or Security.stripInaccessible(). Use with sharing by default.

XSS prevention: Visualforce pages must use {!HTMLENCODE()} for user-controlled data. LWC templates auto-escape but lwc:dom="manual" bypasses this — audit carefully.

CSRF protection: Visualforce pages include CSRF tokens automatically. Custom REST APIs must validate session tokens.

Remote Site Settings / Named Credentials: All external callouts must be documented. Hardcoded credentials are an automatic failure.

Permission sets vs profiles: Package should install with minimal permissions; provide Permission Sets for least-privilege access.

Open redirect vulnerabilities: Do not redirect to user-supplied URLs without validation.

Tools: Salesforce Code Analyzer (PMD rules for Apex security), Checkmarx for SAST scanning. Perform security review early — not at the end of development.

Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.

Community comments (0)

No comments yet.

Sign in or create a free account to add a comment. Comments are moderated before they appear.

Plain text only, 3–2000 characters. A moderator reviews every comment before it is published.