WP Manifestindependent plugin directory
manifest / utilities / dicestack-all-in-one-wordpress-toolkit

DiceStack (Full Edition) WP Registry grade B-. Medium-severity findings · 4 findingsWP RegistryMedium-severity findings · 4 findingsOpen the reportB- releases

DiceStack - All-in-One WordPress Toolkit Plugin. 200+ modular tools for security, performance, SEO, WooCommerce, caching, backups & more. Enable only what you need; disabled tools load zero code. By Dice Codes.

by Dice Codes · github.com/iamramgarhia/dicestack-all-in-one-wordpress-toolkit · website

8stars
15release downloads
1forks

Install

The author publishes release zips, so WP-CLI can install straight from GitHub:

wp plugin install https://github.com/iamramgarhia/dicestack-all-in-one-wordpress-toolkit/releases/download/v1.6.5/dicestack.zip

DiceStack (Full Edition) — Free All-in-One WordPress Plugin (200+ Tools)

One plugin. Every tool. Always free. DiceStack bundles 200+ modular tools for security, performance, SEO, WooCommerce, caching, backups, forms, and site management into a single lightweight dashboard — and you turn on only what you need. Disabled tools load zero code, so your site stays fast.

Built by Dice Codes — your digital dream team.

🔗 Download on WordPress.org  •  🌐 Plugin Home  •  📖 Documentation

DiceStack — the free all-in-one WordPress plugin with 200+ modular tools for security, performance, SEO, WooCommerce, caching and backups


Two editions

DiceStack comes in two builds. This repository is the Full Edition.

Full Edition (this repo) WordPress.org Edition
Where GitHub Releases wordpress.org/plugins/dicestack
Tools 200+ ~170
Includes power tools ✅ File manager, code snippets, database tools, wp-config editor, .htaccess editor, header/footer code, custom CSS ❌ (not allowed on the .org directory)
Updates One-click from GitHub (built-in updater) WordPress.org auto-updates
Best for Developers & agencies who want everything Most sites — lean and directory-vetted

Both are 100% free. The two never clash: the Full Edition carries an Update URI header, so WordPress will never cross-update one into the other.


Why DiceStack?

Most WordPress sites run a dozen plugins — one for caching, one for security, one for SEO, another for backups — each adding weight, cost, and conflicts. DiceStack replaces that whole stack with one free, modular toolkit:

  • 🧩 200+ tools, one install — security, performance, SEO, WooCommerce, media, marketing, admin, accessibility and more.
  • ⚡ Zero bloat by design — every tool is off until you enable it, and disabled tools load no PHP, JS, or CSS. The dashboard shows the exact RAM / JS / DB cost of each tool before you turn it on.
  • 💯 100% free, forever — no "Pro" upsell, no locked features, no nag screens.
  • 🛡️ Safe Mode & isolation — a failing tool auto-disables itself instead of taking down your site.
  • 🤝 Conflict-aware — DiceStack detects plugins you already run (e.g. an SEO or caching plugin) and warns you before enabling an overlapping tool.
  • 🏢 Agency Mode — a distinct client toolkit, plus a 1-click "Recommended setup" that scans your site and enables the right essentials.

Features — 200+ tools across 10 categories

Category Tools Examples
🛡️ Security 29 Login protection, two-factor auth (2FA), malware File Scanner, core file integrity check, Under Attack mode, Login IP allowlist, vulnerability scanner, security headers, Cloudflare control
Performance 27 Page cache, object cache (Redis/Memcached), CDN URL rewrite, cache warmup, critical CSS, minify, lazy-load, heartbeat control
🔍 SEO 21 Meta titles & descriptions, schema markup, breadcrumbs, redirects, robots.txt, Open Graph, broken-link checker
📝 Forms 8 Contact forms, spam protection, SMTP, submission logging
🛒 WooCommerce 25 Direct checkout, abandoned cart recovery, PDF invoices, catalog mode, custom order statuses, checkout field editor
🖼️ Media 11 Image optimization, WebP/AVIF, media folders, lightbox, AI alt-text
📣 Content & Marketing 32 AI content assistant, announcement bar, cookie consent, GA4/Pixel, related posts, table of contents
🧰 Admin & Developer 35 Code Snippets, Database tools, wp-config editor, Cron manager, file manager, .htaccess editor, admin menu editor, WP-CLI
🗄️ Site Management 14 Backups & restore, cloud backup, email log, monthly reports, error monitor, activity log, diagnostics
Accessibility & Legal 7 Cookie consent, accessibility toolbar, skip links, terms consent

👉 Full tool-by-tool guides: dicecodes.com/dicestack/docs

🔐 Malware & hardening suite

DiceStack ships a real security sweep, not just checkboxes:

  • File Scanner — scans wp-content for malware-shaped code (obfuscated/encoded payloads, dangerous functions fed request input, web-shell markers, PHP hidden inside fake image uploads). Precision-tuned to avoid flagging legitimate framework/vendor code.
  • Core file integrity — verifies wp-admin/wp-includes/root against the official WordPress.org checksums and flags modified, missing, or injected core files.
  • Under Attack mode — emergency lockdown: block XML-RPC, block the REST API for logged-out visitors, disable registration, and per-IP rate limiting. Logged-in users are never affected.
  • Login IP allowlist, login protection, security headers, bad-bot blocking, two-factor auth, and vulnerability scanner.

🧑‍💻 Developer power tools (Full Edition only)

Gated behind admin capabilities, with clear warnings and safe defaults:

  • Code Snippets — run PHP snippets; each is wrapped in try/catch and auto-disables if it errors.
  • Database Tools — browse/optimize tables and run SQL (read-only by default).
  • wp-config editor — toggle common constants safely; backs up the file first.
  • Plus file manager, .htaccess editor, header/footer code, custom CSS, and cron manager.

Installation

Full Edition (this repo — 200+ tools)

  1. Download the latest dicestack.zip from the Releases page (use the attached dicestack.zip, not the auto-generated "Source code").
  2. In wp-admin go to Plugins → Add New → Upload Plugin and choose the zip.
  3. Activate, then open the DiceStack dashboard.
  4. Future updates appear as a normal one-click update in wp-admin (checked from GitHub Releases).

WordPress.org Edition (lean — ~170 tools)

  1. In wp-admin go to Plugins → Add New, search for DiceStack, click Install Now → Activate. Updates come through WordPress.org.

How it works

DiceStack uses a modular architecture: each tool is a self-contained module that is only loaded when you enable it.

  • Disabled module → 0 KB PHP/JS/CSS, 0 extra DB queries.
  • Each card in the dashboard shows the tool's footprint (e.g. "If on: +12 KB") so you make informed choices.
  • Your enabled/disabled choices persist across updates — updating the plugin never re-enables tools or loses settings.

A free alternative to premium WordPress plugins

Looking for a free alternative to… Use DiceStack's built-in tools
WP Rocket / W3 Total Cache (caching) Page Cache, Object Cache (Redis/Memcached), Minify, Lazy Load, Defer JS, CDN rewrite, Cache Warmup
Wordfence / Sucuri (security) Login Protection, Two-Factor Auth, File Scanner (malware), Core Integrity, Under Attack mode, Vulnerability Scanner, Security Headers, Login IP allowlist
Really Simple SSL (HTTPS) Force HTTPS, Mixed Content Fixer, HSTS & Security Headers, SSL certificate monitor
Yoast SEO Premium / All in One SEO (SEO) Meta Tags, Schema / JSON-LD, Breadcrumbs, Redirect Manager, robots.txt, Analytics (GA4), Broken-link checker
UpdraftPlus / BlogVault (backups) Backup & Restore, Cloud Backup (FTP / WebDAV / Email / Google Drive)
Imagify / ShortPixel / Smush (images) Image Optimizer, WebP / AVIF, bulk compression, AI alt-text
WPForms / Gravity Forms (forms) Contact Form, Spam Shield, SMTP, universal Submissions Tracker
Code Snippets / WP Data Access (developer) Code Snippets, Database Tools, wp-config editor, Cron manager

Every one of these is 100% free in DiceStack — no premium tier, no upsell.


Requirements

  • WordPress 6.0 or higher
  • PHP 7.4 or higher
  • Some tools need server capabilities (Redis/Memcached for object cache, Imagick for image optimization, ZipArchive for backups) — DiceStack detects these and clearly marks any tool your server can't run.

FAQ

Is there a free all-in-one WordPress plugin? Yes — DiceStack is a completely free all-in-one WordPress plugin. One install gives you 200+ modular tools for security, performance, SEO, WooCommerce, caching, backups and more, with no premium tier and no upsell.

What's the difference between the Full Edition and the WordPress.org version? The Full Edition (here on GitHub) includes ~200+ tools, including developer power tools (code snippets, database tools, file manager, wp-config editor) that the WordPress.org directory doesn't allow. The WordPress.org version is a leaner, directory-vetted ~170-tool build. Both are free; pick whichever fits.

How does the Full Edition update? It has a built-in updater that checks this repo's GitHub Releases and offers a normal one-click update inside wp-admin. It will never be overwritten by the WordPress.org version (it carries an Update URI header).

Are the power tools safe? They run admin-authored code, so they're gated behind the highest capabilities (manage_options, and unfiltered_html for snippets), protected by nonces, default to safe modes (e.g. the SQL runner is read-only unless you opt in), and show clear warnings. Use them on a site you control, and keep backups.

Will it slow my site down? No. Tools you don't enable load nothing at all. Enabling the caching and optimization tools typically makes sites faster.

Will it conflict with my existing SEO / caching / security plugin? DiceStack detects common plugins and warns you before you enable a tool that overlaps.

What happens to my settings when I update? Nothing changes — enabled tools stay enabled, disabled stay disabled, and all settings are preserved.


Contributing

Issues and pull requests are welcome. Please open an issue for bugs or feature requests.

License

DiceStack is free software, released under the GNU General Public License v2.0 or later — the same license as WordPress itself.

Credits

Designed and built by Dice Codes. 📧 Contact@dicecodes.com

Releases

9 releases. Each count is every asset in that release; expand a row for the breakdown.

Tag
Published
Assets
Downloads
v1.6.5 latest
Aug 7, 2026 1mo ago
dicestack.zip
7
Aug 7, 2026 1mo ago
dicestack.zip
2
Aug 7, 2026 1mo ago
dicestack.zip
1
Aug 7, 2026 1mo ago
dicestack.zip
0
Aug 7, 2026 1mo ago
tag only
Aug 7, 2026 1mo ago
tag only
Aug 7, 2026 1mo ago
tag only
Jul 27, 2026 1mo ago
tag only
Jun 26, 2026 2mo ago
dicestack.zip
5
B- grade

Security

DiceStack (Full Edition) 1.6.5 · audited by WP Registry

Medium-severity findings.

4 medium
Audited release
1.6.5
Findings
4
Worst severity
medium
Content hash
55802c9f9e1b5b8337f1651b…

Findings

  • medium Contact, newsletter, and form-log CPTs use post capabilities so Editors can read visitor PII

    missing_capability

    Contact_Form, Newsletter_Signup, and Submissions_Tracker register private CPTs (dicestack_entry, dicestack_subscriber, dicestack_form_log) with show_ui true, capability_type post, and map_meta_cap true. Guest submissions are wp_insert_post'd as publish with PII in the title (subscriber email) or post meta (_dicestack_name/_dicestack_email/_dicestack_message/_dicestack_ip, or _dicestack_fields from CF7/WPForms/Gravity/Forminator/Elementor). WordPress therefore maps list/edit to edit_posts/edit_others_posts, not manage_options. An Editor (or any role with edit_others_posts) can open /wp-admin/edit.php?post_type=dicestack_entry (and the sibling types) even if they cannot see the parent DiceStack menu, and read every visitor's email, message, and IP. Authors are author-scoped so they do not see post_author=0 guest rows; Subscribers cannot access edit.php. This is not public REST (show_in_rest unset).

    modules/Forms/Contact_Form.php:126-144

    Recommendation

    Give all three CPTs custom capabilities mapped to manage_options (or a dedicated cap granted only to administrators), e.g. 'capability_type' => 'dicestack_entry', 'capabilities' => array('edit_posts' => 'manage_options', 'edit_others_posts' => 'manage_options', ...). Keep show_in_rest false. Repeat for dicestack_subscriber and dicestack_form_log.

  • medium AI content assistant AJAX allows any edit_posts user to send any post's content to the site API key

    missing_capability

    wp_ajax_dicestack_ai_generate is registered when the AI Content Assistant module is active. generate() requires a nonce and current_user_can('edit_posts') only — it never calls current_user_can('edit_post', $post_id) or checks post status/type. It then get_post($post_id), takes the first 4000 characters of post_content, and sends them to OpenAI or Gemini using the administrator-configured API key. An Author or Contributor who can open post.php (where the nonce is localized) can POST another author's draft/private page ID and receive an AI excerpt, meta description, or title list derived from that content, and can burn the site's paid API quota. Subscribers lack edit_posts and cannot obtain the nonce from the editor.

    modules/Content/AI_Content_Assistant.php:174-206

    Recommendation

    Require current_user_can('edit_post', $post_id) after resolving the post. Reject posts the user cannot read. Rate-limit per user and do not expose raw provider error messages that might include key hints.

  • medium Spam Shield and login/comment math captchas fail open when protection fields are omitted

    insecure_config

    Spam Shield (enabled in Core::recommended_defaults on fresh install) treats a missing timestamp as success: passes() only enforces the min-seconds trap when $ts > 0, and an empty/absent honeypot is allowed. A bot POSTing only core wp-comments-post.php / register fields therefore bypasses the module entirely. Login_Captcha::verify returns the already-authenticated WP_User when dicestack_login_math_h is empty (documented fail-open for custom login forms), so a password-guessing client that omits the captcha fields never answers the math question. Math_Captcha::verify similarly returns $commentdata when dicestack_math_h is empty. These are not RCE; they make the advertised anti-abuse controls ineffective against any client that does not scrape the form HTML.

    modules/Forms/Spam_Shield.php:148-164

    Recommendation

    Fail closed when the module is enabled and its fields are missing on the standard comment, registration, or wp-login POST (require both honeypot presence and a valid timestamp/hash). Keep a narrow allow-list for known alternate forms if needed. For login captcha, reject authenticate when log is present but dicestack_login_math_h is not.

  • medium Maintenance mode is skipped for every logged-in user, not just administrators

    missing_capability

    Maintenance_Mode::maybe_show() is documented as showing a coming-soon page to visitors while admins still browse, but the gate is current_user_can('manage_options') || is_user_logged_in(). The manage_options test is therefore dead: any authenticated Subscriber, Customer, Author, or Editor bypasses the 503/coming-soon screen and sees the live site (including unpublished product/content the operator intended to hide). Unauthenticated visitors are still blocked. Preview-key cookie bypass is separate and admin-configured.

    modules/Content/Maintenance_Mode.php:125-133

    Recommendation

    Allow only current_user_can('manage_options') (and optionally a dedicated capability or the existing bypass_key cookie). Remove the is_user_logged_in() short-circuit.

WP Registry hashes the installable build and reports on that exact bytes-for-bytes copy. Embargoed findings are withheld until they are disclosed, so a clean verdict means nothing public is outstanding. WP Manifest does not audit code itself.