all tools

[ assessment - 8 min ]

AppExchange Security Review Checklist

Score your managed package against the security posture reviewers actually probe before you submit.

01 CRUD and FLS enforcement

Apex reads and writes enforce user permissions through USER_MODE, stripInaccessible, or equivalent patterns.

02 Sharing model

Every data-touching class declares sharing deliberately and least-privilege paths are tested.

03 Injection and unsafe input

Dynamic SOQL, REST inputs, URL parameters, and UI output are validated, bound, and escaped.

04 Secrets and endpoints

Credentials, endpoints, and external calls are handled through protected metadata or named credentials.

05 Static scans

Code Analyzer, PMD, ESLint, or partner scans run before submission and known findings are resolved.

06 Review evidence

Architecture notes, data-flow explanations, permissions, and test evidence are ready for the questionnaire.

[ want a second opinion ]

Want us to interpret this with your real org?

Book a working session and we will turn the score into a concrete Salesforce and Agentforce next step.

30-min working session · delivery team · usually replies within 1 business day