Title: DiceStack
Author: Dice Codes
Published: <strong>August 7, 2026</strong>
Last modified: August 7, 2026

---

Search plugins

![](https://ps.w.org/dicestack/assets/banner-772x250.png?rev=3637655)

![](https://ps.w.org/dicestack/assets/icon-256x256.png?rev=3637655)

# DiceStack

 By [Dice Codes](https://profiles.wordpress.org/dicecodes/)

[Download](https://downloads.wordpress.org/plugin/dicestack.1.5.16.zip)

 * [Details](https://mfe.wordpress.org/plugins/dicestack/#description)
 * [Reviews](https://mfe.wordpress.org/plugins/dicestack/#reviews)
 *  [Installation](https://mfe.wordpress.org/plugins/dicestack/#installation)
 * [Development](https://mfe.wordpress.org/plugins/dicestack/#developers)

 [Support](https://wordpress.org/support/plugin/dicestack/)

## Description

**DiceStack** replaces a whole stack of separate (and often paywalled) plugins with
one lightweight, modular toolkit. Switch tools on and off from a single dashboard—
when a tool is off, none of its code runs, so your site stays fast.

Every feature is free. There is no locked “Pro” tier.

Built and maintained by **[Dice Codes](https://dicecodes.com)**.

#### Why DiceStack

 * **Modular & light** — disabled modules load zero code, scripts, or extra database
   reads.
 * **See the cost of everything** — each module shows its memory, front-end JavaScript,
   and database-query impact so you decide what to keep.
 * **No paywalls** — 2FA-grade login protection, schema, spam protection, caching,
   backups, and more, all included.
 * **Self-hosted first** — runs on your own server. Modules that contact an external
   service ask for consent and link to where to get any keys.

#### What’s included (170+ modules across 10 categories)

 * **Security** — login protection, login & comment captcha, security hardening,
   security headers, force HTTPS, activity log, 404 monitor, bad-bot blocking, Cloudflare
   control (Under Attack mode, cache purge), and more.
 * **Performance** — **page caching with gzip, mobile cache and preloading**, **
   Redis / Memcached object cache**, minify HTML, defer JavaScript, lazy loading,
   image optimization, database cleanup, hover prefetch, disable bloat, and more.
 * **SEO & AI** — meta tags, schema/JSON-LD, XML-friendly robots, breadcrumbs, FAQ
   schema, site verification, **Analytics (GA4, Tag Manager, Meta Pixel)**, llms.
   txt for AI assistants, and a free SEO/AI visibility checker.
 * **Forms** — contact form, spam shield, SMTP email, newsletter signup, and a universal
   submissions tracker that logs entries from the major third-party form plugins
   in one place.
 * **WooCommerce** — checkout field editor, custom order statuses, wishlist, back-
   in-stock alerts, product badges, catalog mode, quick quantity buttons, and more.
 * **Media** — image optimizer, WebP/AVIF uploads, media folders, broken-image finder.
 * **Content & marketing** — popups, cookie consent, maintenance mode with shareable
   bypass link, table of contents, related posts, reading progress, and more.
 * **Site management** — backup & restore (no upload limit), cloud backup (FTP/WebDAV/
   email/Google Drive), monthly client report, update notifications, search & replace,
   import/export config.
 * **Admin & developer** — admin menu editor, hide notices, white label, master 
   search, last-login column, and more.
 * **Accessibility & legal** — accessibility toolbar, skip links, focus outlines,
   reduced-motion, cookie consent, terms consent.

### External services

DiceStack itself contacts no external services by default. The following modules
connect to a third party **only when you enable and configure them**, and each field
links to where to obtain any required ID/token:

 * **Analytics & tracking** — when you add a GA4, Google Tag Manager, or Meta Pixel
   ID, the corresponding script from Google/Meta is loaded on your front end and
   visitor analytics is sent to that provider. See Google’s privacy policy (https://
   policies.google.com/privacy) and Meta’s (https://www.facebook.com/privacy/policy/).
 * **Cloudflare control** — sends your API token and Zone ID to the Cloudflare API(
   https://api.cloudflare.com) to change settings you request. Cloudflare privacy
   policy: https://www.cloudflare.com/privacypolicy/.
 * **Cloud backup** — uploads your backup archive to the destination you configure(
   your own FTP/WebDAV server, an email address, or Google Drive). Google Drive 
   uses a one-time connect via the Dice Codes connector (https://dicecodes.com/dicestack);
   only an access token is stored.

No data is sent to any of these unless you turn the relevant module on and enter
your details.

## Installation

 1. In wp-admin go to **Plugins  Add New  Upload Plugin** and choose `dicestack.zip`(
    or install from the directory).
 2. Activate **DiceStack**.
 3. Open **DiceStack** in the admin menu and toggle on the modules you want. Each card
    shows its performance cost.

## FAQ

### Does an inactive module slow my site down?

No. When a module is off, its code is never loaded — no hooks, scripts, or database
reads. The only baseline cost is one cached option read.

### Is it really free?

Yes. Every module is free, with no locked features.

### Do I need API keys?

Most modules need nothing. A few optional ones (Analytics, Cloudflare, Google Drive
backup) need an ID or token — each field links to exactly where to get it.

### How do I request a feature?

Use the “Request a feature” link in the DiceStack dashboard, or email Contact@dicecodes.
com.

### Who makes DiceStack?

DiceStack is built and maintained by Dice Codes (https://dicecodes.com).

## Reviews

![](https://secure.gravatar.com/avatar/9bc4677112b3a4fd46611bfa0393a35ed0e64189a01b9ad170c2d91672a8bf49?
s=60&d=retro&r=g)

### 󠀁[How this is free](https://wordpress.org/support/topic/how-this-is-free/)󠁿

 [Prince](https://profiles.wordpress.org/princeramgarhia/) August 7, 2026

the only plugin you need to install in your wordpress site

 [ Read all 1 review ](https://wordpress.org/support/plugin/dicestack/reviews/)

## Contributors & Developers

“DiceStack” is open source software. The following people have contributed to this
plugin.

Contributors

 *   [ Dice Codes ](https://profiles.wordpress.org/dicecodes/)

[Translate “DiceStack” into your language.](https://translate.wordpress.org/projects/wp-plugins/dicestack)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/dicestack/), check 
out the [SVN repository](https://plugins.svn.wordpress.org/dicestack/), or subscribe
to the [development log](https://plugins.trac.wordpress.org/log/dicestack/) by [RSS](https://plugins.trac.wordpress.org/log/dicestack/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.5.16

 * The “Recommended setup” link now hides itself when there is nothing left to recommend.
 * Agency Mode has a distinct look and its buttons are clearly scoped to agency 
   tools only.

#### 1.5.15

 * The “Dashboard” link now sits at the very top of the DiceStack menu, above the
   tool and post-type pages.

#### 1.5.13

 * Every DiceStack settings and tool page now uses a consistent modern design (styled
   headers, cards, buttons and inputs) that matches the main dashboard.

#### 1.5.12

 * The Recommended-setup scan now checks more high-value tools (security headers,
   disable XML-RPC, bad-bot blocking, image optimization, heartbeat control, database
   cleanup).
 * The Diagnostics page now reports more environment details (database version, 
   HTTPS, permalinks, WP_DEBUG, WP-Cron, object cache, active theme, locale, upload
   limits).

#### 1.5.11

 * Fixed a fatal error (“Call to undefined function dicestack_admin_html()”) that
   could break several settings screens (Backups, Cloud backup, Object cache, Image
   optimizer, Admin menu editor, Error monitor, Monthly report, Agency Mode).
 * The admin dashboard now uses a single page scrollbar with a sticky sidebar instead
   of a nested inner scroll area.

#### 1.5.10

 * Fixed a WordPress 6.7 “translation loading was triggered too early” notice: modules
   now load on the init action, so no translated text is requested before init.

#### 1.5.9

 * Shortcode callbacks that embed other shortcodes now escape their returned HTML
   with wp_kses_post (recently-viewed and wishlist product grids).
 * The page-cache and HTML-minify features now serve output through the standard
   output-buffer callback and readfile(), so no page markup is echoed from a variable.
 * The shared inline-CSS/JS helpers now neutralise any style/script block break-
   out at the sink, in addition to callers escaping every dynamic value.
 * No feature changes — output-safety hardening only.

#### 1.5.8

 * Security hardening pass for the WordPress.org directory: every admin-screen value
   is now escaped at the point of output with the appropriate function (esc_html,
   esc_attr, esc_url, wp_kses).
 * All request input ($_POST/$_GET/$_FILES) is unslashed and sanitized before use.
 * Removed the “Hide PHP errors” tool, which changed a server-level setting.
 * No behavioural changes to any feature — output escaping and input sanitizing 
   only.

#### 1.5.7

 * Output buffers used for page caching and HTML minification are now explicitly
   closed.
 * Removed the WP-Cron control tool.
 * All remaining inline styles — including on admin screens — now load via wp_enqueue_style/
   wp_add_inline_style.
 * Shortcode return values are escaped.
 * Documentation corrected to match the shipped feature set.

#### 1.5.6

 * Fixed: login protection now uses the real visitor IP behind a proxy/CDN (opt-
   in toggle), so a shared proxy IP can no longer lock out every visitor.
 * Fixed: database search & replace processes rows in batches to avoid memory exhaustion
   on large sites.

#### 1.5.5

 * Hardened for the WordPress.org directory: removed the file and code-editing tools,
   and every inline style/script now loads through the standard wp_enqueue / wp_add_inline_*
   functions.

#### 1.5.4

 * Improved: clearer messaging when a tool needs another plugin (for example WooCommerce),
   with a one-click install link.
 * Improved: tools that have their own screen now show their settings right there.
 * Housekeeping: leaner, security-focused build; every tool still loads only when
   it is enabled.
 * Tested up to WordPress 7.0.

#### 1.0.0

 * First public release of DiceStack.

## Meta

 *  Version **1.5.16**
 *  Last updated **2 days ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.0 or higher **
 *  Tested up to **7.0.3**
 *  PHP version ** 7.4 or higher **
 *  Language
 * [English (US)](https://wordpress.org/plugins/dicestack/)
 * Tags
 * [optimization](https://mfe.wordpress.org/plugins/tags/optimization/)[performance](https://mfe.wordpress.org/plugins/tags/performance/)
   [security](https://mfe.wordpress.org/plugins/tags/security/)[seo](https://mfe.wordpress.org/plugins/tags/seo/)
   [woocommerce](https://mfe.wordpress.org/plugins/tags/woocommerce/)
 *  [Advanced View](https://mfe.wordpress.org/plugins/dicestack/advanced/)

## Ratings

 5 out of 5 stars.

 *  [  1 5-star review     ](https://wordpress.org/support/plugin/dicestack/reviews/?filter=5)
 *  [  0 4-star reviews     ](https://wordpress.org/support/plugin/dicestack/reviews/?filter=4)
 *  [  0 3-star reviews     ](https://wordpress.org/support/plugin/dicestack/reviews/?filter=3)
 *  [  0 2-star reviews     ](https://wordpress.org/support/plugin/dicestack/reviews/?filter=2)
 *  [  0 1-star reviews     ](https://wordpress.org/support/plugin/dicestack/reviews/?filter=1)

[Your review](https://wordpress.org/support/plugin/dicestack/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/dicestack/reviews/)

## Contributors

 *   [ Dice Codes ](https://profiles.wordpress.org/dicecodes/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/dicestack/)