Assessing Security Risks in Low-Code Development Platforms: A Systematic Literature Review
Hiruni Hathnagoda, Ruwan Wickramarachchi · 2024
Low Code Development Platforms (LCDPs) have transformed software development by enabling rapid application creation with minimal coding, democratizing the process beyond professional developers. This type of democratization comes with considerable security risks. The paper aims to classify security risks associated with seven leading LCDPs: Mendix, OutSystems, Microsoft Power Apps, ServiceNow, Salesforce, Oracle, and Pegasystems. It evaluates respective mitigation strategies to improve security. 27 studies reviewed using the PRISMA methodology showed critical vulnerabilities in application, information, platform specific, and user related risks. The most frequent application-level vulnerabilities are code injection, XSS, and insecure APIs, which amateur developers unaware of secure coding practices further worsen. Common information security risks across various platforms include weak encryption, data breaches, and misconfigurations. User related risks include weak credentials and insider threats that expose applications to breaches in Salesforce and Oracle. With automated patch management and secure coding practices, Mendix and OutSystems have better security postures. In contrast, others like ServiceNow and Pegasystems remain vulnerable because of delayed patching and other manual security processes, which introduces a higher probability of human error. Based on this, the study concluded that an extended multi dimensional security strategy is required, comprising technological solutions such as automation, human centered interventions, training, and user management in managing the risks within LCDPs.