Skip to content
Kanixa Technologies
AppExchange

AppExchange security review: a checklist for passing the first time

What Salesforce's AppExchange security review checks, the issues that fail most submissions, and how to prepare your managed package and documentation.

By Vitap, Founder & Salesforce Architect. Published 22 September 2026. 3 min read.

The short answer

The AppExchange security review checks that your package enforces sharing and field-level security, resists injection and cross-site scripting, stores secrets safely and calls only secure external endpoints. Run Salesforce Code Analyzer, fix or document every finding, scan any external services you call and submit with clear test instructions.

Every app listed on the AppExchange goes through Salesforce's security review before customers can install it. Teams that treat it as a final formality often fail it, and a failed review can delay a launch by weeks.

The good news is that the review is predictable. Reviewers look for the same categories of issues every time. If you build to them from the first sprint, the review becomes a confirmation rather than a surprise.

What the review is checking

At a high level, reviewers want to know that installing your app won't weaken a customer's org. That means your package:

  • Respects the customer's sharing rules and field-level security.
  • Can't be tricked into running unintended queries or scripts.
  • Stores credentials and secrets safely.
  • Talks only to external services that are themselves secure.

The checklist

Data access

  • Use with sharing (or inherited sharing deliberately) on Apex classes that touch user data.
  • Enforce object and field permissions, for example with WITH USER_MODE in SOQL or Security.stripInaccessible.
  • Never let a user see or change data their permissions wouldn't allow in the standard UI.

Injection and scripting

  • Use bind variables in SOQL. If you must build dynamic queries, escape input and validate field names against the schema.
  • Avoid raw HTML rendering in Lightning Web Components and Visualforce. Escape output by default.
  • Don't load JavaScript from external CDNs in components. Use static resources.

Secrets and authentication

  • Store credentials in Named Credentials, protected custom settings or protected custom metadata, not in code or public settings.
  • Use OAuth where the external service supports it.
  • Don't log tokens, passwords or personal data in debug statements.

External endpoints

  • Call only HTTPS endpoints with modern TLS.
  • If your app relies on your own web service, scan it too. Reviewers will look at the service, not just the package.

Documentation

  • Include clear test instructions and credentials for any external system the reviewer needs.
  • Explain every scanner finding you believe is a false positive, with the reason.

Run the scanners before Salesforce does

Run Salesforce Code Analyzer across your package and fix what it finds. Then scan any external web application or API your app depends on. Keep the reports: you'll attach them to the submission, and they show reviewers you've done the work.

Build it in from day one

The cheapest time to pass security review is before you've written the code. Agree on a data-access pattern, a secrets strategy and a logging approach in your first sprint, then enforce them in code review.

If you're planning an app or recovering from a failed review, our AppExchange app development team can help you get listed.

Frequently asked questions

How long does the AppExchange security review take?

Plan for several weeks from submission to result, and longer if the review fails and you need to resubmit. Build that time into your launch plan rather than treating it as a formality.

What are the most common reasons apps fail security review?

Missing CRUD and field-level security checks, SOQL injection from dynamic queries, unescaped output that allows cross-site scripting, secrets stored in plain text and insecure external endpoints are the issues we see most often.

Can you fix an app that already failed security review?

Yes. The review report lists the findings. We fix each issue in code or configuration, rerun the scanners and prepare explanations for any false positives before resubmitting.

Keep reading

Tell us what you're trying to build

A 30-minute call with a Salesforce architect. You'll leave with a clear next step, whether or not we work together.

Book a call WhatsApp