<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.appian.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>KB-2385 Plugin Review &amp; Security Scanning FAQ</title><link>https://community.appian.com/support/w/kb/3709/kb-2385-plugin-review-security-scanning-faq</link><description /><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>KB-2385 Plugin Review &amp; Security Scanning FAQ</title><link>https://community.appian.com/support/w/kb/3709/kb-2385-plugin-review-security-scanning-faq</link><pubDate>Wed, 27 May 2026 18:11:29 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:b7ea018d-4e92-4d29-9ed5-70cdc006dba9</guid><dc:creator>Ryan Good</dc:creator><comments>https://community.appian.com/support/w/kb/3709/kb-2385-plugin-review-security-scanning-faq#comments</comments><description>Current Revision posted to Appian Knowledge Base by Ryan Good on 5/27/2026 6:11:29 PM&lt;br /&gt;
&lt;p&gt;All plugins submitted to Appian for use on Appian Cloud require review and approval. This article aims to answer common questions about the plugin review process.&lt;/p&gt;
&lt;p&gt;For more information on plugin and AppMarket policies, refer to the &lt;a href="https://docs.appian.com/suite/help/latest/Shared_Components.html"&gt;AppMarket Submission Policies&lt;/a&gt; documentation and the &lt;a href="/p/appmarket-submission-agreement"&gt;AppMarket Submissions Agreement&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Table of Contents:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a title="HowAreReviewsPerformed" href="#HowAreReviewsPerformed"&gt;How are plugin security reviews performed?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a title="WhatTooling" href="#WhatTooling"&gt;What specific tooling is used?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a title="HowOften" href="#HowOften"&gt;How often are reviews performed?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a title="PrivatePlugins" href="#PrivatePlugins"&gt;What happens to plugins that are flagged by security scans?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a title="ProvideScanResults" href="#ProvideScanResults"&gt;Can Appian provide the scan results?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a title="FlaggedPlugins" href="#FlaggedPlugins"&gt;What happens to plugins that are flagged by security scans?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a title="HowLongDoIHave" href="#HowLongDoIHave"&gt;How long do I have to remediate a finding in my plugin?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a title="PreviouslyApproved" href="#PreviouslyApproved"&gt;My plugin submission was previously approved. Why is my latest update not approved?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a title="BypassReview" href="#BypassReview"&gt;I need to use my plugin on Appian Cloud ASAP. Can I bypass security review temporarily?&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="HowAreReviewsPerformed"&gt;&lt;/a&gt;How are plugin security reviews performed?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Security scanning is first performed during all submissions of new and updated plugins to Appian. Subsequent reviews are also performed on a routine basis after initial approval.&lt;br /&gt; Scans such as Static Application Security Testing (SAST), Software composition analysis (SCA), and other security related checks are in place.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="WhatTooling"&gt;&lt;/a&gt;What specific tooling is used?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Appian utilizes custom tooling, open source software, and commercial off the shelf software to perform the automated security scanning.&lt;br /&gt; Appian does not publish the specific software used to review plugins.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="HowOften"&gt;&lt;/a&gt;How often are reviews performed?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Reviews are always performed upon plugin submission. Post-approval, additional security reviews are performed regularly.&lt;br /&gt; Appian reserves the right to perform security reviews at any time.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="PrivatePlugins"&gt;&lt;/a&gt;Do security reviews apply to private plugins?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Yes. As stated in the &lt;a href="https://docs.appian.com/suite/help/latest/Shared_Components.html"&gt;AppMarket Submission Policies&lt;/a&gt;, All plug-ins, whether intended for public use on the AppMarket or private use within an organization, must receive approval before deployment.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="ProvideScanResults"&gt;&lt;/a&gt;Can Appian provide the scan results?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Appian does not publish or share the results of security scans.&lt;br /&gt; Plugin authors are notified directly when one of their submissions is flagged by a security scan.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="FlaggedPlugins"&gt;&lt;/a&gt;What happens to plugins that are flagged by security scans?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Plugin authors are notified directly when one of their submissions is flagged by a security scan.&lt;br /&gt; Plugins which are not updated may be removed from the AppMarket. Appian reserves the right to reject or stop hosting plug-ins at any time.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="HowLongDoIHave"&gt;&lt;/a&gt;How long do I have to remediate a finding in my plugin?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Appian will provide a timeline for remediation when notifying you of a finding.&lt;br /&gt; Appian reserves the right to modify plug-in remediation timelines at any time.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="PreviouslyApproved"&gt;&lt;/a&gt;My plugin submission was previously approved. Why is my latest update not approved?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Every submitted version of a plugin is reviewed in full.&lt;br /&gt; Approval of a plugin does not guarantee approval of subsequent versions.&lt;br /&gt; Appian reserves the right to modify plugin security policies at any time.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="BypassReview"&gt;&lt;/a&gt;I need to use my plugin on Appian Cloud ASAP. Can I bypass security review temporarily?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Plugin submissions cannot bypass security review; only fully approved submissions can be deployed on Appian Cloud.&lt;br /&gt; If a plug-in requires expedited review, please include that context and justification in the submission.&lt;br /&gt; If you subscribe to a Signature Appian Success Plan, let your Lead Engineer know of your urgent request.&lt;/p&gt;
&lt;h2&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to all versions of Appian.&lt;/p&gt;
&lt;p&gt;Last Reviewed: May 2026&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: FAQ, plugins&lt;/div&gt;
</description></item><item><title>[DRAFT SUPP-1654] Plugin Review &amp; Security Scanning FAQ</title><link>https://community.appian.com/support/w/kb/3709/kb-2385-plugin-review-security-scanning-faq/revision/5</link><pubDate>Wed, 27 May 2026 15:36:59 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:b7ea018d-4e92-4d29-9ed5-70cdc006dba9</guid><dc:creator>Ryan Good</dc:creator><comments>https://community.appian.com/support/w/kb/3709/kb-2385-plugin-review-security-scanning-faq#comments</comments><description>Revision 5 posted to Appian Knowledge Base by Ryan Good on 5/27/2026 3:36:59 PM&lt;br /&gt;
&lt;p&gt;All plugins submitted to Appian for use on Appian Cloud require review and approval. This article aims to answer common questions about the plugin review process.&lt;/p&gt;
&lt;p&gt;For more information on plugin and AppMarket policies, refer to the &lt;a href="https://docs.appian.com/suite/help/latest/Shared_Components.html"&gt;AppMarket Submission Policies&lt;/a&gt; documentation and the &lt;a href="/p/appmarket-submission-agreement"&gt;AppMarket Submissions Agreement&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Table of Contents:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a title="HowAreReviewsPerformed" href="#HowAreReviewsPerformed"&gt;How are plugin security reviews performed?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a title="WhatTooling" href="#WhatTooling"&gt;What specific tooling is used?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a title="HowOften" href="#HowOften"&gt;How often are reviews performed?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a title="PrivatePlugins" href="#PrivatePlugins"&gt;What happens to plugins that are flagged by security scans?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a title="ProvideScanResults" href="#ProvideScanResults"&gt;Can Appian provide the scan results?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a title="FlaggedPlugins" href="#FlaggedPlugins"&gt;What happens to plugins that are flagged by security scans?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a title="HowLongDoIHave" href="#HowLongDoIHave"&gt;How long do I have to remediate a finding in my plugin?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a title="PreviouslyApproved" href="#PreviouslyApproved"&gt;My plugin submission was previously approved. Why is my latest update not approved?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a title="BypassReview" href="#BypassReview"&gt;I need to use my plugin on Appian Cloud ASAP. Can I bypass security review temporarily?&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="HowAreReviewsPerformed"&gt;&lt;/a&gt;How are plugin security reviews performed?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Security scanning is first performed during all submissions of new and updated plugins to Appian. Subsequent reviews are also performed on a routine basis after initial approval.&lt;br /&gt; Scans such as Static Application Security Testing (SAST), Software composition analysis (SCA), and other security related checks are in place.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="WhatTooling"&gt;&lt;/a&gt;What specific tooling is used?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Appian utilizes custom tooling, open source software, and commercial off the shelf software to perform the automated security scanning.&lt;br /&gt; Appian does not publish the specific software used to review plugins.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="HowOften"&gt;&lt;/a&gt;How often are reviews performed?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Reviews are always performed upon plugin submission. Post-approval, additional security reviews are performed regularly.&lt;br /&gt; Appian reserves the right to perform security reviews at any time.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="PrivatePlugins"&gt;&lt;/a&gt;Do security reviews apply to private plugins?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Yes. As stated in the &lt;a href="https://docs.appian.com/suite/help/latest/Shared_Components.html"&gt;AppMarket Submission Policies&lt;/a&gt;, All plug-ins, whether intended for public use on the AppMarket or private use within an organization, must receive approval before deployment.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="ProvideScanResults"&gt;&lt;/a&gt;Can Appian provide the scan results?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Appian does not publish or share the results of security scans.&lt;br /&gt; Plugin authors are notified directly when one of their submissions is flagged by a security scan.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="FlaggedPlugins"&gt;&lt;/a&gt;What happens to plugins that are flagged by security scans?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Plugin authors are notified directly when one of their submissions is flagged by a security scan.&lt;br /&gt; Plugins which are not updated may be removed from the AppMarket. Appian reserves the right to reject or stop hosting plug-ins at any time.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="HowLongDoIHave"&gt;&lt;/a&gt;How long do I have to remediate a finding in my plugin?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Appian will provide a timeline for remediation when notifying you of a finding.&lt;br /&gt; Appian reserves the right to modify plug-in remediation timelines at any time.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="PreviouslyApproved"&gt;&lt;/a&gt;My plugin submission was previously approved. Why is my latest update not approved?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Every submitted version of a plugin is reviewed in full.&lt;br /&gt; Approval of a plugin does not guarantee approval of subsequent versions.&lt;br /&gt; Appian reserves the right to modify plugin security policies at any time.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="BypassReview"&gt;&lt;/a&gt;I need to use my plugin on Appian Cloud ASAP. Can I bypass security review temporarily?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Plugin submissions cannot bypass security review; only fully approved submissions can be deployed on Appian Cloud.&lt;br /&gt; If a plug-in requires expedited review, please include that context and justification in the submission.&lt;br /&gt; If you subscribe to a Signature Appian Success Plan, let your Lead Engineer know of your urgent request.&lt;/p&gt;
&lt;h2&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to all versions of Appian.&lt;/p&gt;
&lt;p&gt;Last Reviewed: May 2026&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: FAQ, plugins&lt;/div&gt;
</description></item><item><title>[DRAFT SUPP-1654] Plugin Review &amp; Security Scanning FAQ</title><link>https://community.appian.com/support/w/kb/3709/kb-2385-plugin-review-security-scanning-faq/revision/4</link><pubDate>Wed, 20 May 2026 14:15:38 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:b7ea018d-4e92-4d29-9ed5-70cdc006dba9</guid><dc:creator>Daniel DeVeau</dc:creator><comments>https://community.appian.com/support/w/kb/3709/kb-2385-plugin-review-security-scanning-faq#comments</comments><description>Revision 4 posted to Appian Knowledge Base by Daniel DeVeau on 5/20/2026 2:15:38 PM&lt;br /&gt;
&lt;p&gt;All plugins submitted to Appian for use on Appian Cloud require review and approval. This article aims to answer common questions about the plugin review process.&lt;/p&gt;
&lt;p&gt;For more information on plugin and AppMarket policies, refer to the &lt;a href="https://docs.appian.com/suite/help/latest/Shared_Components.html"&gt;AppMarket Submission Policies&lt;/a&gt; documentation and the &lt;a href="/p/appmarket-submission-agreement"&gt;AppMarket Submissions Agreement&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Table of Contents:&lt;/p&gt;
&lt;p&gt;&lt;a title="HowAreReviewsPerformed" href="#HowAreReviewsPerformed"&gt;How are plugin security reviews performed?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="WhatTooling" href="#WhatTooling"&gt;What specific tooling is used?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="HowOften" href="#HowOften"&gt;How often are reviews performed?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="PrivatePlugins" href="#PrivatePlugins"&gt;What happens to plugins that are flagged by security scans?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="ProvideScanResults" href="#ProvideScanResults"&gt;Can Appian provide the scan results?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="FlaggedPlugins" href="#FlaggedPlugins"&gt;What happens to plugins that are flagged by security scans?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="HowLongDoIHave" href="#HowLongDoIHave"&gt;How long do I have to remediate a finding in my plugin?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="PreviouslyApproved" href="#PreviouslyApproved"&gt;My plugin submission was previously approved. Why is my latest update not approved?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="BypassReview" href="#BypassReview"&gt;I need to use my plugin on Appian Cloud ASAP. Can I bypass security review temporarily?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="HowAreReviewsPerformed"&gt;&lt;/a&gt;How are plugin security reviews performed?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Security scanning is first performed during all submissions of new and updated plugins to Appian. Subsequent reviews are also performed on a routine basis after initial approval.&lt;br /&gt; Scans such as Static Application Security Testing (SAST), Software composition analysis (SCA), and other security related checks are in place.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="WhatTooling"&gt;&lt;/a&gt;What specific tooling is used?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Appian utilizes custom tooling, open source software, and commercial off the shelf software to perform the automated security scanning.&lt;br /&gt; Appian does not publish the specific software used to review plugins.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="HowOften"&gt;&lt;/a&gt;How often are reviews performed?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Reviews are always performed upon plugin submission. Post-approval, additional security reviews are performed regularly.&lt;br /&gt; Appian reserves the right to perform security reviews at any time.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="PrivatePlugins"&gt;&lt;/a&gt;Do security reviews apply to private plugins?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Yes. As stated in the &lt;a href="https://docs.appian.com/suite/help/latest/Shared_Components.html"&gt;AppMarket Submission Policies&lt;/a&gt;, All plug-ins, whether intended for public use on the AppMarket or private use within an organization, must receive approval before deployment.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="ProvideScanResults"&gt;&lt;/a&gt;Can Appian provide the scan results?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Appian does not publish or share the results of security scans.&lt;br /&gt; Plugin authors are notified directly when one of their submissions is flagged by a security scan.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="FlaggedPlugins"&gt;&lt;/a&gt;What happens to plugins that are flagged by security scans?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Plugin authors are notified directly when one of their submissions is flagged by a security scan.&lt;br /&gt; Plugins which are not updated may be removed from the AppMarket. Appian reserves the right to reject or stop hosting plug-ins at any time.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="HowLongDoIHave"&gt;&lt;/a&gt;How long do I have to remediate a finding in my plugin?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Appian will provide a timeline for remediation when notifying you of a finding.&lt;br /&gt; Appian reserves the right to modify plug-in remediation timelines at any time.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="PreviouslyApproved"&gt;&lt;/a&gt;My plugin submission was previously approved. Why is my latest update not approved?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Every submitted version of a plugin is reviewed in full.&lt;br /&gt; Approval of a plugin does not guarantee approval of subsequent versions.&lt;br /&gt; Appian reserves the right to modify plugin security policies at any time.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="BypassReview"&gt;&lt;/a&gt;I need to use my plugin on Appian Cloud ASAP. Can I bypass security review temporarily?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Plugin submissions cannot bypass security review; only fully approved submissions can be deployed on Appian Cloud.&lt;br /&gt; If a plug-in requires expedited review, please include that context and justification in the submission.&lt;br /&gt; If you subscribe to a Signature Appian Success Plan, let your Lead Engineer know of your urgent request.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;h2&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to all versions of Appian.&lt;/p&gt;
&lt;p&gt;Last Reviewed: May 2026&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: FAQ, plugins&lt;/div&gt;
</description></item><item><title>[DRAFT SUPP-1654] Plugin Review &amp; Security Scanning FAQ</title><link>https://community.appian.com/support/w/kb/3709/kb-2385-plugin-review-security-scanning-faq/revision/3</link><pubDate>Wed, 20 May 2026 14:12:16 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:b7ea018d-4e92-4d29-9ed5-70cdc006dba9</guid><dc:creator>Daniel DeVeau</dc:creator><comments>https://community.appian.com/support/w/kb/3709/kb-2385-plugin-review-security-scanning-faq#comments</comments><description>Revision 3 posted to Appian Knowledge Base by Daniel DeVeau on 5/20/2026 2:12:16 PM&lt;br /&gt;
&lt;p&gt;All plugins submitted to Appian for use on Appian Cloud require review and approval. This article aims to answer common questions about the plugin review process.&lt;/p&gt;
&lt;p&gt;For more information on plugin and AppMarket policies, refer to the &lt;a href="https://docs.appian.com/suite/help/latest/Shared_Components.html"&gt;AppMarket Submission Policies&lt;/a&gt; documentation and the &lt;a href="/p/appmarket-submission-agreement"&gt;AppMarket Submissions Agreement&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Table of Contents:&lt;/p&gt;
&lt;p&gt;&lt;a title="HowAreReviewsPerformed" href="#HowAreReviewsPerformed"&gt;How are plugin security reviews performed?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="WhatTooling" href="#WhatTooling"&gt;What specific tooling is used?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="HowOften" href="#HowOften"&gt;How often are reviews performed?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="ProvideScanResults" href="#ProvideScanResults"&gt;Can Appian provide the scan results?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="PrivatePlugins" href="#PrivatePlugins"&gt;What happens to plugins that are flagged by security scans?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="FlaggedPlugins" href="#FlaggedPlugins"&gt;How long do I have to remediate a finding in my plugin?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="HowLongDoIHave" href="#HowLongDoIHave"&gt;My plugin submission was previously approved. Why is my latest update not approved?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="PreviouslyApproved" href="#PreviouslyApproved"&gt;I need to use my plugin on Appian Cloud ASAP. Can I bypass security review temporarily?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="HowAreReviewsPerformed"&gt;&lt;/a&gt;How are plugin security reviews performed?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Security scanning is first performed during all submissions of new and updated plugins to Appian. Subsequent reviews are also performed on a routine basis after initial approval.&lt;br /&gt; Scans such as Static Application Security Testing (SAST), Software composition analysis (SCA), and other security related checks are in place.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="WhatTooling"&gt;&lt;/a&gt;What specific tooling is used?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Appian utilizes custom tooling, open source software, and commercial off the shelf software to perform the automated security scanning.&lt;br /&gt; Appian does not publish the specific software used to review plugins.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="HowOften"&gt;&lt;/a&gt;How often are reviews performed?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Reviews are always performed upon plugin submission. Post-approval, additional security reviews are performed regularly.&lt;br /&gt; Appian reserves the right to perform security reviews at any time.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="PrivatePlugins"&gt;&lt;/a&gt;Do security reviews apply to private plugins?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Yes. As stated in the &lt;a href="https://docs.appian.com/suite/help/latest/Shared_Components.html"&gt;AppMarket Submission Policies&lt;/a&gt;, All plug-ins, whether intended for public use on the AppMarket or private use within an organization, must receive approval before deployment.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="ProvideScanResults"&gt;&lt;/a&gt;Can Appian provide the scan results?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Appian does not publish or share the results of security scans.&lt;br /&gt; Plugin authors are notified directly when one of their submissions is flagged by a security scan.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="FlaggedPlugins"&gt;&lt;/a&gt;What happens to plugins that are flagged by security scans?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Plugin authors are notified directly when one of their submissions is flagged by a security scan.&lt;br /&gt; Plugins which are not updated may be removed from the AppMarket. Appian reserves the right to reject or stop hosting plug-ins at any time.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="HowLongDoIHave"&gt;&lt;/a&gt;How long do I have to remediate a finding in my plugin?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Appian will provide a timeline for remediation when notifying you of a finding.&lt;br /&gt; Appian reserves the right to modify plug-in remediation timelines at any time.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="PreviouslyApproved"&gt;&lt;/a&gt;My plugin submission was previously approved. Why is my latest update not approved?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Every submitted version of a plugin is reviewed in full.&lt;br /&gt; Approval of a plugin does not guarantee approval of subsequent versions.&lt;br /&gt; Appian reserves the right to modify plugin security policies at any time.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="BypassReview"&gt;&lt;/a&gt;I need to use my plugin on Appian Cloud ASAP. Can I bypass security review temporarily?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Plugin submissions cannot bypass security review; only fully approved submissions can be deployed on Appian Cloud.&lt;br /&gt; If a plug-in requires expedited review, please include that context and justification in the submission.&lt;br /&gt; If you subscribe to a Signature Appian Success Plan, let your Lead Engineer know of your urgent request.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;h2&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to all versions of Appian.&lt;/p&gt;
&lt;p&gt;Last Reviewed: May 2026&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: FAQ, plugins&lt;/div&gt;
</description></item><item><title>[DRAFT SUPP-1654] Plugin Review &amp; Security Scanning FAQ</title><link>https://community.appian.com/support/w/kb/3709/kb-2385-plugin-review-security-scanning-faq/revision/2</link><pubDate>Wed, 20 May 2026 14:07:51 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:b7ea018d-4e92-4d29-9ed5-70cdc006dba9</guid><dc:creator>Daniel DeVeau</dc:creator><comments>https://community.appian.com/support/w/kb/3709/kb-2385-plugin-review-security-scanning-faq#comments</comments><description>Revision 2 posted to Appian Knowledge Base by Daniel DeVeau on 5/20/2026 2:07:51 PM&lt;br /&gt;
&lt;p&gt;All plugins submitted to Appian for use on Appian Cloud require review and approval. This article aims to answer common questions about the plugin review process.&lt;/p&gt;
&lt;p&gt;For more information on plugin and AppMarket policies, refer to the &lt;a href="https://docs.appian.com/suite/help/latest/Shared_Components.html"&gt;AppMarket Submission Policies&lt;/a&gt; documentation and the &lt;a href="/p/appmarket-submission-agreement"&gt;AppMarket Submissions Agreement&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Table of Contents:&lt;/p&gt;
&lt;p&gt;&lt;a title="HowAreReviewsPerformed" href="#HowAreReviewsPerformed"&gt;How are plugin security reviews performed?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="WhatTooling" href="#WhatTooling"&gt;What specific tooling is used?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="HowOften" href="#HowOften"&gt;How often are reviews performed?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="ProvideScanResults" href="#ProvideScanResults"&gt;Can Appian provide the scan results?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="PrivatePlugins" href="#PrivatePlugins"&gt;What happens to plugins that are flagged by security scans?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="FlaggedPlugins" href="#FlaggedPlugins"&gt;How long do I have to remediate a finding in my plugin?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="HowLongDoIHave" href="#HowLongDoIHave"&gt;My plugin submission was previously approved. Why is my latest update not approved?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="PreviouslyApproved" href="#PreviouslyApproved"&gt;I need to use my plugin on Appian Cloud ASAP. Can I bypass security review temporarily?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="HowAreReviewsPerformed"&gt;&lt;/a&gt;How are plugin security reviews performed?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Security scanning is first performed during the submission of new and updated plugins to Appian.&lt;/p&gt;
&lt;p&gt;Subsequent reviews are also performed on a routine basis after initial approval.&lt;/p&gt;
&lt;p&gt;Scans such as Static Application Security Testing (SAST), Software composition analysis (SCA), and other security related checks are in place.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="WhatTooling"&gt;&lt;/a&gt;What specific tooling is used?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Appian utilizes custom tooling, open source software, and commercial off the shelf software to perform the automated security scanning.&lt;/p&gt;
&lt;p&gt;Appian does not publish the specific software used to review plugins.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="HowOften"&gt;&lt;/a&gt;How often are reviews performed?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Reviews are always performed upon plugin submission.&amp;nbsp;Post-approval, additional security reviews are performed regularly .&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Appian reserves the right to perform security reviews at any time.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="ProvideScanResults"&gt;&lt;/a&gt;Can Appian provide the scan results?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Appian does not publish or share the results of security scans.&lt;/p&gt;
&lt;p&gt;Plugin authors are notified directly when one of their submissions is flagged by a security scan.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="PrivatePlugins"&gt;&lt;/a&gt;Do security reviews apply to private plugins?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Yes. As stated in the &lt;a href="https://docs.appian.com/suite/help/latest/Shared_Components.html"&gt;AppMarket Submission Policies&lt;/a&gt;, All plug-ins, whether intended for public use on the AppMarket or private use within an organization, must receive approval before deployment.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="FlaggedPlugins"&gt;&lt;/a&gt;What happens to plugins that are flagged by security scans?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Plugin authors are notified directly when one of their submissions is flagged by a security scan.&lt;/p&gt;
&lt;p&gt;Plugins which are not updated may be removed from the AppMarket.&lt;/p&gt;
&lt;p&gt;Appian reserves the right to reject or stop hosting plug-ins at any time.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="HowLongDoIHave"&gt;&lt;/a&gt;How long do I have to remediate a finding in my plugin?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Appian will provide a timeline for remediation when notifying you of a finding.&lt;/p&gt;
&lt;p&gt;Appian reserves the right to modify plug-in remediation timelines at any time.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="PreviouslyApproved"&gt;&lt;/a&gt;My plugin submission was previously approved. Why is my latest update not approved?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Every submitted version of a plugin is reviewed in full.&lt;/p&gt;
&lt;p&gt;Approval of a plugin does not guarantee approval of subsequent versions.&lt;/p&gt;
&lt;p&gt;Appian reserves the right to modify plugin security policies at any time.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="BypassReview"&gt;&lt;/a&gt;I need to use my plugin on Appian Cloud ASAP. Can I bypass security review temporarily?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Plugin submissions cannot bypass security review; only fully approved submissions can be deployed on Appian Cloud.&lt;/p&gt;
&lt;p&gt;If a plug-in requires expedited review, please include that context and justification in the submission.&lt;/p&gt;
&lt;p&gt;If you subscribe to a Signature Appian Success Plan, let your Lead Engineer know of your urgent request.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;h2 id="mcetoc_1jp2rd10e5"&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to all versions of Appian.&lt;/p&gt;
&lt;p&gt;Last Reviewed: May 2026&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: FAQ, plugins&lt;/div&gt;
</description></item><item><title>[DRAFT SUPP-1654] Plugin Review &amp; Security Scanning FAQ</title><link>https://community.appian.com/support/w/kb/3709/kb-2385-plugin-review-security-scanning-faq/revision/1</link><pubDate>Tue, 16 Sep 2025 20:14:38 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:b7ea018d-4e92-4d29-9ed5-70cdc006dba9</guid><dc:creator>Ryan Good</dc:creator><comments>https://community.appian.com/support/w/kb/3709/kb-2385-plugin-review-security-scanning-faq#comments</comments><description>Revision 1 posted to Appian Knowledge Base by Ryan Good on 9/16/2025 8:14:38 PM&lt;br /&gt;
&lt;p&gt;This article serves as a template that you can copy/paste into a new article for use later on.&amp;nbsp;This template should be used to provide extra details about a certain topic. It can either be internal or external.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;The title of the article must be under 256 characters (less depending on the types of characters used in the title as this is a limitation of Telligent). It must be as concise as possible. Those using the Knowledge Base should get a good idea of what the article is about just by reading the title.&lt;/p&gt;
&lt;p&gt;This description is for informational purposes only. Besides a Table of Contents, there should be no text above the&amp;nbsp;Q and A when using this template, unless it is a brief statement about the article purpose. All FAQ articles should begin with a Table of Contents. Detailed instructions on how to create a Table of Contents can be found in&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;a href="/solution-engineering/w/internal-knowledge-base/725/int-0000-how-to-write-kb-articles#Creating%20Anchors%20for%20Lists"&gt;INT-0000&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Table of Contents:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="/solution-engineering/w/internal-knowledge-base/724/int-0003-template-faq#HowToFormat"&gt;How should the Q and A be formatted?&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="HowToFormat"&gt;&lt;/a&gt;How should the Q and A be formatted?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Format&amp;nbsp;each question&amp;nbsp;as shown here. The question should be&amp;nbsp;bold with the corresponding answer below.&lt;/p&gt;
&lt;p&gt;Examples:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="/solution-engineering/w/internal-knowledge-base/675/int-1402-forum-accounts-and-user-management-faq"&gt;INT-1402 Forum Accounts and user management FAQ&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="/support/w/kb/370/kb-1153-saml-authentication-faq"&gt;KB-1153 SAML Authentication FAQ&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="/support/w/kb/1087/kb-1678-engine-checkpoint-faq"&gt;KB-1678 Engine checkpoint FAQ&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This section includes any relevant version information for Appian or other third/party configurations. Some examples of valid affected versions are as follows:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;This article applies to all versions of Appian.&lt;/li&gt;
&lt;li&gt;This article applies to all self-managed versions of Appian.&lt;/li&gt;
&lt;li&gt;This article applies to all versions of Appian Cloud.&lt;/li&gt;
&lt;li&gt;This article applies to Appian 7.11 and later.&lt;/li&gt;
&lt;li&gt;This article applies to Appian 16.2 and earlier.&lt;/li&gt;
&lt;li&gt;This article applies to Appian 7.11 and 16.1.&lt;/li&gt;
&lt;li&gt;This article applies to Appian 16.1, 16.2, and 16.3.&lt;/li&gt;
&lt;li&gt;This article applies to self-managed Appian 19.3 and earlier.&lt;/li&gt;
&lt;li&gt;This article applies to all versions of Appian from Appian 7.10 to Appian 16.2.&lt;/li&gt;
&lt;li&gt;This article applies to all versions of Appian using JBoss EAP 6.4.9 as an application server and Internet Explorer 9 as a web browser.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Last Reviewed: Month YYYY&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;
</description></item></channel></rss>