Our 2024 State of Salesforce Development analyzed data from 1,400+ Salesforce orgs unaware of code analysis best practices and the right tools for secure coding.
There is a vast disconnect between Salesforce’s guidance and real-world applications.
76% of Salesforce orgs still have critical OWASP Top 10 security vulnerabilities in production, a security risk exposure that is not acceptable to most security teams.
Apex can circumvent an organization’s permission, and corporate data can be exposed through vulnerable code. Remediating an Apex vulnerability takes 20 months.
A key selling point for Salesforce is its ability to accelerate your organization's time to market. Our data indicates that most applications contain anti-patterns that impede this advantage, causing companies to be slower in responding to market changes. Additionally, 83% of organizations face challenges in maintaining their implementations due to inadequate documentation, high code complexity, and technical debt.
Traditional code scanners don't consider your Org’s context (i.e. your data objects, the classes you define, inheritance, etc). They cannot understand crucial runtime behaviour, such as function calls, inheritance, input propagation, etc. This leads to high rates of errors (false positives) and omissions (false negatives) in the scanners' reports.
Our 2024 State of Salesforce Development analyzed data from 1400+ Salesforce Orgs unaware of code analysis best practices and the right tools for secure coding.