Use case · AppExchange ISVs
Pass AgentExchange Security Review in fewer rounds.
The review (formerly AppExchange Security Review) takes weeks a round. Vulkro moves it into development: the issues reviewers fail packages for are caught in the editor and the pipeline, so far fewer of them ever reach the review.
Vulkro for Salesforce · VS Code extension · Vulkro Core
01The problem
Each failed review round costs weeks
The scanners the review runs execute inside Salesforce’s pipeline, after you have already submitted. Three facts about that round, from Salesforce where Salesforce publishes them.
About half fail first time
Salesforce publishes no first-pass failure rate. About half is the figure partners cite most often: an industry estimate, not an official one.
A $999 fee per attempt
On a paid solution Salesforce charges $999 for the initial submission and again for every later attempt. Missing CRUD and field-level checks are the most common reason a round fails.
Four to five weeks a round
Salesforce says a solution typically takes four to five weeks to get through review, and every fix and resubmit is another attempt. The way to save that time is to fix it while you develop.
02How Vulkro handles it
What each part of Vulkro does
- CRUD, FLS and sharing in every Apex entry point
- Guest-reachable LWC and Aura methods
- Visualforce output and page parameters
- Secrets and outdated JavaScript in static resources
- A readiness checklist: pass, gap or not evaluated
- The gap underlined on the line that causes it
- How the class runs: system or user mode, with or without sharing
- Explain and fix from the lightbulb
- The external services your package calls, in Node, Python, Go or Java
- Vulnerable dependencies in those services
- An SBOM for the reviewer, if asked
03The workflow
Steps from first scan to fix
- 01VS Code extension
Catch it while you write it
The extension flags missing CRUD, FLS and sharing on the line as you develop, months before the review would.
- 02Vulkro for Salesforce
Scan the package
Run Vulkro for Salesforce over your Salesforce DX project. Nothing is uploaded.
- 03Vulkro for Salesforce
Read the readiness checklist
Every requirement category scored pass, gap or not evaluated. Not evaluated is never counted as a pass.
- 04Vulkro for Salesforce
Gate the build
A presubmit gate fails the pipeline while a gap remains, so nothing goes out half fixed.
- 05Vulkro for Salesforce
Submit with the report
Hand the reviewer the readiness report alongside your submission.
04What you get
What you get
- Before submission
- The same requirement categories the review scores, on your machine.
- Honest gaps
- A category Vulkro could not evaluate says so, with what to check by hand.
- In the editor
- CRUD, FLS and sharing findings on the line, with the fix.
- In CI
- A presubmit gate and SARIF on the pull request.
- Free and Pro
- The readiness checklist is free. The reviewer report and the presubmit gate are Pro.
Questions
Common questions
- Does this replace the Security Review?
- No. Salesforce still runs the review. Vulkro tells you, before you submit, where your package stands against what the review looks for.
- Does my code leave my machine?
- No. Vulkro for Salesforce scans locally, and works offline.
- What about the parts a scanner cannot judge?
- They are marked not evaluated, never passed, so you know what to review by hand.