Skip to content

Trust

What we do with other people's work, and what we do not claim.

This site lists templates made by other people. That makes copyright the first question, not the last one.

Control boundary Explicit scope
Implemented

8

Sourced practices

Not claimed

5

Named boundaries

Implemented

Every practice below exists in the repository.

Each one names the file that implements it, so a claim on this page can be checked rather than trusted.

We host no template files

Every download and every demo link points at the author. Nothing here is a mirror, and there is nothing to take down except a listing.

Implemented in app/Http/Controllers/Directory/

A screenshot is rendered only for a permissive licence

A screenshot reproduces the author's design. Where no OSI licence is detected we link to the template and render no image, and the listing stays out of the main grid rather than filling it with a placeholder.

Implemented in app/Catalog/Images/ImagePipeline.php

Descriptions are derived, not copied

A README is fetched so a machine can classify the repository. What is stored is that derived summary. GitHub's terms licence a repository's content to others through GitHub, which is not the same as on our site.

Implemented in app/Catalog/Import/

Licence facts are attributed

Stars, forks, dates and the SPDX string are facts and are safe to republish. deps.dev publishes the same fields under CC-BY 4.0 with caching expressly permitted, and is credited in the footer.

Implemented in config/themevault.php

A takedown is honoured within 24 hours, permanently

A removed listing is the one state the importer refuses to update, so the next sweep sees it and leaves it alone. It cannot quietly come back.

Implemented in app/Catalog/Moderation/ListingModerator.php

Every paid placement is labelled

A visible label and rel="sponsored" on the link, neither of which a sponsor can pay to remove. Nothing here is editorial-looking and paid for.

Implemented in resources/views/components/directory/sponsor-slot.blade.php

Outbound fetches cannot be turned against our network

Every URL we fetch came from a stranger. Each one is resolved first and judged on the resolved address, the address is pinned for the request, every redirect is re-checked, and the response is capped — so a hostname that resolves to a private address is refused rather than followed.

Implemented in app/Support/Net/UrlGuard.php

Two-factor authentication on the accounts that can publish

Time-based codes, single-use recovery codes, and password confirmation before a takedown — the one action the importer will never undo.

Implemented in config/fortify.php, routes/web.php

Not claimed

What this page deliberately does not say.

A badge is a claim. These are the claims that would be false.

  • No SOC 2, ISO 27001, HIPAA or PCI DSS certification is held, and no badge suggesting one is displayed.
  • We do not verify that a template is free of malicious code. Read what you clone.
  • A licence shown here is the one the source declared. It is a report, not legal advice, and the author's repository is the authority.
  • No uptime figure is published for the sites we link to. They are not ours.
  • No affiliation with any listed author or sponsor is claimed or implied.

Reporting something

For a security problem, use the contact page and say so in the first line. For a listing that should not be here, the takedown page is faster — it goes to the same people with the right details already asked for.

Questions

Want a listing removed?

The takedown page is the fastest route — it asks for the details needed to act, and a request is honoured within 24 hours.