We have developed one custom Salesforce app and before we submit for Salesforce security review, it would be good to have your feedback on below question.
As part of this app, we are fetching data using API from 3rd party website and storing some information on custom object in Salesforce and displaying information real time based on user selecting on Salesforce.
We have already scanned Salesforce app using Checkmarx: https://security.secure.force.com/security/tools/forcecom/scanner and worked on points, as identified and suggested by scanner.
Do we need to scan, 3rd party website using Chimera Scanner as per this page https://security.secure.force.com/sourcescanner/ ? As I mentioned above, we use this website for API calls and fetching data to be displayed on Salesforce app.
Looking forward to your feedback!
Thank you,
Brijesh