AppSecNews
SAST Open source Established

PMD

by PMD open source project

Extensible source code analyzer that applies rule sets to the syntax tree of several languages, bundled with a cross language copy and paste detector.

Visit pmd.github.io (leaves AppSecNews, opens in a new tab) Leaves AppSecNews for the vendor's own site.

No endorsements yet

Run PMD in production? A named recommendation helps the next team shortlisting it.

Recommend this tool

Endorsers verify their identity through LinkedIn. Titles and companies are self declared, shown as they were when each person signed, and reviewed by an editor before anything is published. Endorsements are never paid for.

What we still need to verify : 1 point in this profile is not yet confirmed against vendor documentation.
  • Language list changes between releases as modules are added and retired, confirm the current set

Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.

What it does

PMD parses source into an abstract syntax tree and evaluates rules against it. Rules are written either as XPath expressions over the tree or as Java classes implementing a visitor, which means adding a project specific rule is a matter of describing the shape you want to forbid rather than writing a parser. The bundled rule sets are organized into categories: best practices, code style, design, error prone constructs, performance, multithreading and security. Most are quality rules, but the error prone and security categories overlap with real vulnerability classes, and the Apex rule set in particular carries genuine security checks for Salesforce code including sharing violations, SOQL injection and insufficient access control.

The second component is CPD, the copy paste detector. It tokenizes source and finds duplicated token sequences across files and across languages. That is a maintainability signal most of the time, but it is also how you find a patched vulnerability that was copied into three other files and only fixed in one.

Where it fits

PMD runs as a build plugin under Maven or Gradle, as a standalone command line scan, or inside an IDE. The usual placement is a build step that fails on new violations, with an agreed rule set checked into the repository so the same rules apply locally and in continuous integration. It needs only source, no compiled artifacts and no running application. Developers own it. In many organizations it is consumed indirectly, as one of the analyzers a code quality platform runs on your behalf.

Strengths

  • Rule authoring through XPath over the syntax tree is accessible enough that teams actually write their own rules, which is where most of the value is.
  • Apex support is unusually good, and for Salesforce development PMD is a primary security analysis option rather than a supplementary one.
  • CPD gives duplicate detection across languages from the same install.

Limitations

  • Primarily a code quality tool. The security rule coverage outside Apex is thin compared with scanners designed for vulnerability detection.
  • Analysis is largely local to a method or a file. There is no substantial interprocedural taint tracking, so injection classes that cross function boundaries are out of reach.
  • Default rule sets are noisy if enabled wholesale, and a team that does not curate them tends to disable the whole tool instead.

Who it suits

A sensible baseline for Java and Apex teams who want enforceable coding rules in the build, and the obvious first choice for Salesforce security review. Not a replacement for a security scanner on a general purpose web application: use it for hygiene and custom rule enforcement, and put dataflow analysis somewhere else in the pipeline.

Used PMD? Recommend it under your own name and title.

Recommend this tool