Directory practices
Every practice below exists in the repository. Each one names the file that implements it.
HTMLPick hosts no template files
Each demo and source link points to the author.
Implementation source
app/Http/Controllers/Directory/
Screenshots need a permissive licence
The image service does not render a screenshot without a detected OSI licence.
Implementation source
app/Catalog/Images/ImagePipeline.php
Summaries are derived
The importer classifies public source data. It does not store copied README descriptions.
Implementation source
app/Catalog/Import/
Licence facts include attribution
The footer credits deps.dev for its CC-BY 4.0 licence data.
Implementation source
config/themevault.php
A takedown stays removed
HTMLPick acts within 24 hours. The importer cannot publish the removed listing again.
Implementation source
app/Catalog/Moderation/ListingModerator.php
Paid positions stay visible
Each paid position has a label and a sponsored link attribute.
Implementation source
resources/views/components/directory/sponsor-slot.blade.php
Outbound requests use URL checks
The URL guard checks resolved addresses, redirects and response limits.
Implementation source
app/Support/Net/UrlGuard.php
Publishing accounts use two-factor authentication
The application supports time-based codes, recovery codes and password confirmation.
Implementation source
config/fortify.php, routes/web.php
Limits
HTMLPick does not make unsupported claims.
These limits are part of the public trust statement.
- HTMLPick does not claim SOC 2, ISO 27001, HIPAA or PCI DSS certification.
- HTMLPick does not verify that a template contains no malicious code.
- The author repository remains the authority for the licence.
- HTMLPick does not publish an uptime figure for external sites.
- A listing does not state an affiliation with its author.
Report a problem
Use the contact page for a security report. Use the takedown page for a listing removal.