What we still need to verify : 1 point in this profile is not yet confirmed against vendor documentation.
- Language list changes between releases as modules are added and retired, confirm the current set
Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.
What it does
PMD parses source into an abstract syntax tree and evaluates rules against it. Rules are written either as XPath expressions over the tree or as Java classes implementing a visitor, which means adding a project specific rule is a matter of describing the shape you want to forbid rather than writing a parser. The bundled rule sets are organized into categories: best practices, code style, design, error prone constructs, performance, multithreading and security. Most are quality rules, but the error prone and security categories overlap with real vulnerability classes, and the Apex rule set in particular carries genuine security checks for Salesforce code including sharing violations, SOQL injection and insufficient access control.
The second component is CPD, the copy paste detector. It tokenizes source and finds duplicated token sequences across files and across languages. That is a maintainability signal most of the time, but it is also how you find a patched vulnerability that was copied into three other files and only fixed in one.
Where it fits
PMD runs as a build plugin under Maven or Gradle, as a standalone command line scan, or inside an IDE. The usual placement is a build step that fails on new violations, with an agreed rule set checked into the repository so the same rules apply locally and in continuous integration. It needs only source, no compiled artifacts and no running application. Developers own it. In many organizations it is consumed indirectly, as one of the analyzers a code quality platform runs on your behalf.
Strengths
- Rule authoring through XPath over the syntax tree is accessible enough that teams actually write their own rules, which is where most of the value is.
- Apex support is unusually good, and for Salesforce development PMD is a primary security analysis option rather than a supplementary one.
- CPD gives duplicate detection across languages from the same install.
Limitations
- Primarily a code quality tool. The security rule coverage outside Apex is thin compared with scanners designed for vulnerability detection.
- Analysis is largely local to a method or a file. There is no substantial interprocedural taint tracking, so injection classes that cross function boundaries are out of reach.
- Default rule sets are noisy if enabled wholesale, and a team that does not curate them tends to disable the whole tool instead.
Who it suits
A sensible baseline for Java and Apex teams who want enforceable coding rules in the build, and the obvious first choice for Salesforce security review. Not a replacement for a security scanner on a general purpose web application: use it for hygiene and custom rule enforcement, and put dataflow analysis somewhere else in the pipeline.
Used PMD? Recommend it under your own name and title.
Recommend this tool