Repository navigation
Releases: IamRamgarhia/All-In-One-Free-SEO-Tool
Release list
v0.6.0 — the numbers were sometimes wrong, and the agent now fixes 4x more
Two things to act on: update the WordPress plugin (0.4.0 → 0.6.1), and
if your rank history has flat "not ranking" stretches, they may not have been
real.
Most of this release fixes places where the tool gave you a confident answer
that was wrong. Nothing crashed and nothing was logged, and the number looked
exactly like a real one — which is why several of these survived for months.
A blocked search was being recorded as "not ranking"
DuckDuckGo answers suspected bots with a puzzle page over HTTP 202. The code
treated 202 as success and parsed the puzzle as zero results.
So a check that never ran was written into your rank history as a real
position. Competitor discovery found nobody. Directory checks said "not
listed."
Search pages are now classified — blocked, genuinely empty, or unreadable —
against real captured pages, and a failed check is no longer stored as a
position at all.
Others in the same shape: the algorithm-update list contained a core update
that never happened and nothing from 2026 (it now comes from Google's Search
Status Dashboard, refreshed daily); WordPress sites with clean URLs were told
at high severity to fix their permalinks, because the check matched the
?p=123 shortlink in every page's head; the malware scanner called a stock
WordPress file a critical breach; the page monitor ignored a page going 404;
and the dashboard called an AI model on every single page load, which cost
money if you pay per token.
The agent fixes 29 of 72 finding types, up from 7
New: canonical tags, robots directives, Open Graph and Twitter tags, alt text,
redirects, internal links, schema, site hardening, and the first site-wide
fix — your robots.txt AI crawler policy. It works on any site behind
Cloudflare now, not only WordPress, and you can approve a whole class of
change at once.
Your autonomy setting still decides everything. The default is still
suggest — nothing reaches a live site until you say so.
Three plugin bugs were writing changes that never appeared on your site:
alt text saved to the database and never rendered, the meta description and
canonical never printed, Open Graph written but never taken back. An old
plugin will keep silently dropping those edits, so please update it.
Your task list now looks at your site before making work
New clients used to get a fixed checklist per platform and niche, written
without reading the site. On a real install, 8 of 13 open tasks were advice
about work finished years ago — add canonical tags (every page had them),
generate a sitemap (already in robots.txt), enable HTTP/2 (already on).
The tool now reads the site first and skips what you have already done,
writing the evidence to your activity log so you can check it. If it cannot
tell, it keeps the task.
Related: a task you marked "skipped" was still being shown to your client as a
recommendation, in the portal and in the PDF report. It isn't any more.
Connect a chat app to your own SEO data
22 tools over MCP, and a new remote HTTP endpoint so connectors can attach —
off until you generate a token in Settings → AI connection. There are two
tokens now: a read-only one that reaches 15 tools and cannot run the agent
or edit your site (this is the one to paste into a chat app), and full access.
Both are capped at 120 requests a minute. Claude Desktop on Windows works now;
npx in the config never did.
Download
all-in-one-free-seo-tool-v0.6.0.zip (4.9 MB) — the whole project, pinned to this version. No Git needed.
Unzip it, then pick one:
# Docker — builds and runs everything
docker compose up -d
# or Node 20+ — migrations run automatically before the build
npm install && npm run build && npm startThen open http://localhost:3000.
Verify the download if you like: sha256sum should give
49148ca61f72a56ffce8d5d2f287fed11ceb4587fae40dd5325a08dd7e173a35
(also attached as a .sha256 file).
Prefer one command and always-latest? The installer in the README still works
and is the easier path for most people — this zip is for pinning to a known
version, installing without Git, or keeping an offline copy.
Upgrading
- WordPress plugin 0.4.0 → 0.6.1 — needed for the three fixes above
- Nine migrations apply automatically on next start. No downtime.
- No config changes, no new keys. The tool still works with no API keys at all.
Full release notes: docs/releases/v0.6.0.md
Still honest about limits: backlink data is thin without a paid index, a rank
check from one machine is one sample from one location, and AI features need
either a local model or your own key.
v0.5.1 — the WordPress plugin actually works on PHP 8
If you use the WordPress plugin, this is the one you need. v0.5.0 shipped
a plugin that returns a 500 on almost everything. Not a corner case — eight of
its eleven endpoints, on any modern PHP.
The WordPress plugin was broken on PHP 8
We ran the plugin inside a real WordPress for the first time — not a stand-in,
an actual install. It took about two minutes to find this:
Uncaught ArgumentCountError: is_numeric() expects exactly 1 argument, 3 given
Our routes told WordPress to validate ids with is_numeric. WordPress calls
that with three arguments, and PHP 8 throws when a built-in gets more than it
takes. PHP 7 let it slide. The plugin's own requirements say PHP 8.
So every endpoint with an id in its URL was dead: titles, meta descriptions,
alt text, schema, images, internal links, undo. The three that worked — ping,
the post list, revisions — happen not to take an id.
Fixed. And verified against real WordPress 7.0.4 on PHP 8.5, end to end:
write a title, read it back, list images, write schema, insert an internal
link, confirm it renders on the published page, undo it, confirm the article
is back exactly as it was.
Why 57 passing tests missed it: they call the plugin's functions directly,
so they never go through WordPress's REST router — and that router is where
the broken validation runs. The tests were exercising the half of the system
that worked. There's now a check that reads the registered routes and fails
the build if any of them hands a PHP built-in to WordPress.
The agent now works without an API key
If you connect Claude Code, Claude Desktop or Cursor to this tool, the agent
can do its job using your subscription instead of an API key.
Previously it couldn't. With no key of its own it planned all the work and
then quietly dropped it — no record, nothing to act on. You'd have seen an
agent that appeared to do nothing.
Now it still decides what to change and why — that comes from the audit,
not from a model's opinion — and your assistant writes the actual words:
list_proposed_fixestells you what needs changing, why, what's there now,
and the rules the new text has to meetapply_fixtakes your wording, checks it against those same rules, writes
it, reads the page back to confirm, and records an undo
The checks stay on our side. A 95-character title gets refused whoever wrote
it — including your assistant, which will happily suggest one, because a model
asked for a shorter title returns a plausible answer every time.
Worth being clear about the limit: this works with desktop clients that run
the tool locally. claude.ai in a browser and ChatGPT's connectors need a
different kind of connection that isn't built yet.
Upgrading
Press Update to latest in the control panel, or git pull and rebuild.
WordPress users: update the plugin as well. The copy on your site is the
one with the broken endpoints, and updating this tool doesn't touch it.
Still unproven
No MCP client has been pointed at this yet — it's been driven by a test that
speaks the same protocol, which is not the same thing. Search Console, Bing
and live AI providers are still covered by fixtures rather than real calls.
v0.5.0 — the first audit no longer stops dead, and one file to click
Update to v0.5.1. The WordPress plugin in this release returns a 500 on eight of its eleven endpoints on PHP 8 — which the plugin itself requires. It was found by running the plugin inside a real WordPress for the first time, after this release went out. Everything else here still stands.
If you're already running this, update. The very first thing a new user does —
add a site, hit "Run audit" — could get stuck with no error and no way out. And
the agent, which is supposed to fix things for you, could only actually do three
of the seven jobs it claims.
Both fixed here, along with a much simpler way to start the whole thing.
The audit that went nowhere
Someone reported it like this: "it says crawling the site and running 30+ checks
and it just stops in this place and doesn't go anywhere."
They were right, and it turned out to be four separate problems piled on top of
each other.
If an audit ever got interrupted — you closed the tab, restarted your computer,
the site was slow — it stayed marked as "running" in the database. After that,
every time you pressed "Run audit", nothing happened. No error, no message, not
even a log line. Just the same page again. For a full hour.
Meanwhile the audit page itself had no idea what to show for an audit that was
still running, so it drew an empty screen. That's the blank page people were
staring at.
And on a fresh install where the browser engine hadn't downloaded yet, one failed
attempt got remembered forever, so rank checking and screenshots stayed broken
until you restarted the app — all while showing an error that didn't mention the
actual fix.
Now: if an audit really is running, pressing the button takes you to it. If it's
been stuck more than ten minutes, a new one just takes over. The page tells you
what's happening and refreshes itself. And if the browser engine is missing, it
says so and tells you the one command that fixes it.
The agent couldn't do most of its job
This one's embarrassing. The crawler labels its findings one way — long_title,
missing_image_alt — and the agent was looking for completely different names,
title_too_long, missing_alt_text. They never matched.
So the agent could only ever fix the three "missing something" findings. Long
titles, long descriptions and alt text were untouchable, no matter how many times
you ran it.
Worth saying plainly: the v0.4.0 notes said alt-text writing worked. It didn't.
The code for it was all correct — writing, checking, undo, the lot — but the part
that decides what to work on could never hand it anything to do.
Three other parts of the app had drifted the same way: quick wins, the fix
guidance, and proposals. Nothing ever errored. Every list looked perfectly
sensible on its own. The only symptom was work quietly not happening, which is
why it survived this long.
There's now one list of finding names that everything else reads from, and the
build fails if anything drifts away from it again.
Every problem now tells you how to fix it
34 of the 52 checks used to show you a problem and then just... stop. No
explanation, no steps, nothing. The bit that displays guidance quietly returned
nothing when it didn't recognise a check.
All 52 now explain what the problem is, why it matters, and what to actually do
about it, with links to Google's own docs where they exist. If one ever goes
missing again the card says so instead of going blank.
Two bits of bad advice got deleted rather than kept: telling you to cut a page
down to a single H1 (multiple H1s are fine, Google has said so), and suggesting
your H1 should differ from your title "by 10-20 characters for variety", which is
a number someone made up.
One file to click
The folder used to have seven different things you might click to start this,
plus a launcher folder with four more, plus another six tucked away. Seventeen
ways to start one program.
Now there's one. SEO Tool.cmd on Windows, SEO Tool.command on Mac and Linux.
Double-click it and a control panel opens in your browser with buttons for
everything — install, start, stop, update, back up. You only see the buttons that
make sense right now, so there's no guessing.
Installing also puts an icon on your Desktop, so after the first time you
never need to open the folder again. That used to happen only if you'd used the
one-line installer, so anyone who downloaded the zip got nothing. The Windows
Start Menu shortcut was also pointing at a folder that no longer existed.
One thing worth explaining, since it was specifically asked for: this can't be a
plain .html file. When you double-click an HTML file it opens in a locked-down
sandbox that isn't allowed to start programs or touch your files. The buttons
would look real and do absolutely nothing. So there's a tiny launcher file whose
only job is to open the page that can do the work. You still click one thing.
A few smaller things
Backups no longer risk being committed to git — they're copies of your database,
API keys and all.
The README is now honest that Vercel with Supabase or Neon won't run this.
It's the obvious thing to try and it would waste your afternoon: the database is
a file on disk, rank checking drives a real browser, and the scheduler needs
something that stays running. If you want it hosted for free, Oracle Cloud's free
tier actually fits. Fly.io doesn't have one any more.
We'd also claimed that switching to PostgreSQL was "about a day of work". It
isn't — 72 tables and most of the migrations are SQLite-specific.
How to update
Easiest: open the control panel and press Update to latest.
Or from a terminal:
git pull && docker compose up -d --buildYour data isn't touched — migrations run on their own.
The old launcher files get cleaned up automatically. If you had a Desktop or
Start Menu shortcut pointing at the old launcher folder it won't work any more;
run the installer once, or press Add to Desktop in the panel, and you'll get
a fresh one.
What we still can't promise
The WordPress plugin has never actually run inside a real WordPress install. Its
code is tested against a stand-in, which is our best understanding of WordPress
rather than the real thing. Nobody has pointed a real MCP client at the MCP
server yet either. And Search Console, Bing and the AI providers are all covered
by test fixtures rather than live calls.
Also, the install folder will always have package.json, a lockfile and a few
config files in it. Those can't move without breaking the tools that read them.
The difference now is that you don't need to look in there.
v0.4.0 — the WordPress integration works now, and the agent stopped lying about what it fixed
If you self-host this, upgrade. Several headline features did not work
in 0.3.0 — not "worked badly", did not work at all — and you would have had
no way to tell, because none of them threw an error.
Read this first if you use the WordPress plugin
It had never worked. Not once, in any version.
The plugin authenticated on Authorization: Bearer. The tool has only ever
sent X-STB-Key. Every request, every endpoint, since the plugin's first
release, returned 401.
Nothing about the failure said "wrong header" — a 401 reads as a bad key, so
anyone debugging it would have re-copied the key, which was never the problem.
Update the plugin to 0.4.0. Both headers are accepted now, and the tool
explains a 401 instead of passing it through.
Also fixed in the plugin, all found the first time its PHP was ever executed:
- Undo restored the wrong value on any site past 500 logged changes.
Revision ids came fromcount($revisions) + 1and the log caps at 500, so
every revision after that was id 501 and undo found the oldest one — putting
back a value from hundreds of edits ago, and reporting success. - Internal linking refused work it could do, and gave a false reason. Any
phrase whose whole text sat inside a tag —<li>pricing</li>,<code>,
a table cell — was reported "already linked" when nothing was linked. - The literal JSON
nullwas accepted as schema and printed
<script type="application/ld+json">null</script>into the page. - Schema could be added and never removed, so the agent could put
structured data on a page with no way to take it off. - Licence corrected to MIT. It said PolyForm Noncommercial, which is not
GPL-compatible — meaning the plugin could never have been submitted to the
WordPress.org directory it was written for.
The agent was reporting fixes it wasn't making
run.ts decided what needed drafting from an inline list of two kinds. Four
kinds are executable. Alt text and schema weren't on the list, so they went to
the executor with an empty string, wrote it, read the field back to verify
— and it matched, because nothing had changed — and recorded themselves as
verified.
Every image the agent "fixed" still had no alt text. The finding was closed and
the run log said it was done.
Two fixes: drafting is now derived from the drafting paths that exist rather
than restated, and the executor refuses an empty value outright — a guard that
doesn't depend on any list being correct.
Orphan detection never found an orphan
orphans was pages.filter(p => p.inbound === 0), but the crawl only
discovers pages by following links — so a page with no inbound links is never
fetched and can never be reported. Measured on a four-page fixture with a real
orphan: 3 pages crawled, zero orphans found.
Both the internal-linking tool and the site audit now seed their crawl from
your sitemap. Same fixture: 4 pages, orphan found.
New in this release
The agent links orphan pages. It finds pages nothing links to, picks the
most relevant existing page, and links it using a phrase already in that
article — no model invents anchor text, so it can't write words you didn't.
Body edits stay behind review unless you raise autonomy deliberately. That's
the agent's fifth capability, alongside titles, meta descriptions, alt text and
schema.
MCP server — point Claude Code, Claude Desktop or Cursor at your install
and work against your own data in plain English. Ten tools over the joined
history: crawl findings, rank movements, AI citations, and every change the
agent made. Most SEO MCP servers wrap one API; "why did this page drop last
month" needs all of it. It can act, and undo. Setup: docs/mcp-server.md.
Citation landscape — which domains get cited for your topics, ranked, with
your own share. The question the paid GEO tools sell on. It counts only
answers where the model actually searched the web; answers from training memory
are excluded, because they describe what a model absorbed months ago rather
than what AI search cites today. A ranking built from three answers is labelled
too small to call, not presented as a share of voice.
Keyword density is no longer scored. The content grader used the right
method all along — top-10 SERP, TF-IDF corpus, shared headings — but 20 of its
100 points went to hitting a density band, which this project's own principles
name as folklore. Worse, it pushed writers to repeat an exact-match phrase in
prose that didn't need it. Those points moved to term coverage; density now only
warns when a page is genuinely stuffed.
Also in this release
- Team accounts with per-client access
- Rankings from Search Console instead of scraping, labelled with their source
- Bulk report generation with a review step before anything goes out
- Proposals built from real audit findings
- Embeddable audit widget for lead generation
- Real search volume and backlinks from Bing Webmaster Tools
- One
/connectpage for every integration - Provenance on every number shown
Upgrading
git pull && docker compose up -d --buildMigrations run automatically on boot. WordPress users: update the plugin to
0.4.0 too — the tool cannot talk to older versions.
Nothing here changes your data. The content score will move for pages that were
scoring on density; that is the fix working.
Honest limits
Two things in this release have been exercised against faithful stand-ins but
not the real thing: the WordPress plugin has never run inside an actual
WordPress install (its PHP is now tested against stubbed WP functions, which is
new, but stubs are a reading of WordPress rather than WordPress), and no MCP
client has yet rendered the server. Search Console, Bing and live AI providers
remain verified by fixture rather than by a live call.
If you hit something, please open an issue — that is the fastest way these get
found.
v0.3.0 — GEO release: cover every AI-search surface a client can appear in
v0.3.0 — GEO release: cover every AI-search surface
✨ New tools
/tools/ai-robots— Audits your robots.txt for AI-crawler coverage across 15 bots (GPTBot, OAI-SearchBot, ChatGPT-User, ClaudeBot, claude-web, Google-Extended, PerplexityBot, Bytespider, CCBot, Applebot-Extended, Amazonbot, Meta-ExternalAgent, FacebookBot, cohere-ai, Diffbot). Per-bot status + copy-paste patch block./tools/freshness— Harvests every freshness signal AI-search systems parse (HTTPLast-Modified, meta tags, JSON-LDdateModified/datePublishedthrough nested@graphnodes,<time datetime>, visible "Last updated" text, sitemap<lastmod>). Scores 0–100, flags signal disagreements >90 days apart, generates a ready-to-paste JSON-LD + meta patch./tools/geo-swot— Per-client Strengths / Weaknesses / Opportunities / Threats report for AI-search visibility. Deterministic cite-or-bust evidence footer (no hallucinated data points). Template fallback when no AI provider is configured.
✨ New AI-visibility providers (browser-mode, no API key)
- Google AI Mode — Drives Google's
?udm=50AI Mode surface via the browser pool and extracts the generative response + inline citations. - Microsoft Copilot — Drives
copilot.microsoft.com/?q=and extracts the assistant turn + numbered citations. - Both wired into
checkOneProvider()as first-class providers. - New inline "Also scan Google AI Mode + Copilot" pill toggle on every per-client AI-visibility page. Off by default (~15–20s/keyword).
🚀 Existing tools upgraded
/tools/aio-passage— Now supports live URL analysis in addition to paste mode. Fetches the page, strips chrome, and scores every passage. New "Rewrite all low-scoring passages" button batch-rewrites everything below the 70 threshold in parallel (8 concurrent)./ai-visibilityper-client page — New sentiment column with tone-coded pill (positive / neutral / negative) + hover tooltip showing raw score. "Generate GEO SWOT" quick-link appears once ≥3 checks exist.
🐛 Bug fixes
- Google OAuth Error 400
invalid_request— The three places that built theredirect_uri(settings page, auth start, callback) diverged under load balancers. Fixed with a sharedresolveRedirectUri()helper. Same commit fixed per-client Google refresh ignoring env-var credentials and OllamanullURL being silently swallowed inai-call.ts. - Windows launcher first-run failures — 10+ bugs across the one-click launcher path:
- Fresh ZIP had no
node_modules→START.cmdnow self-bootstraps (pnpm install→build→playwright install chromium) with live progress written to.install-progress. - HTA crashed reading empty error log (
fso.OpenTextFile+ReadAllthrows on 0-byte files) — fixed with size check. - HTA's
cmd /c "" "path"form silently returned rc=1 without executing — corrected tocmd /c "path". STOP.cmdparse error (label inside parenthesized IF block) — replaced with sentinel variable.SEO Tool.htmlcouldn't detect a running server (CORS:file://can't hitlocalhost) — HTA is now the single entry.- HTA now shows real-time first-run progress ("Step 2 of 3: Building production bundle…") instead of a 5–8 minute mystery.
- Stale
.nextbuild crashed server after reinstall (invalidbetter-sqlite3-<hash>externals) —START.cmdauto-detects + auto-rebuilds.
- Fresh ZIP had no
- Stray files — Removed
hard),3000),dev,productionfiles created by shell heredoc parsing during previous commits; added to.gitignoreso they can't come back.
🔧 Internal / DX
- Provider dispatch registry (
src/lib/provider-dispatch.ts) — All 12 AI providers (gemini, groq, anthropic, openai, openrouter, perplexity, ollama, mistral, deepseek, cerebras, together, github) unified behind a single registry +dispatchProviderCall().callAI's ~150-line if/else chain collapsed to a single call. Adding a new provider is now one registry entry, not three separate touchpoints. - Dev-mode migration watcher (
scripts/migrate-watch.cjs) — New opt-inpnpm run dev:watchspawnsnext dev, watchessrc/db/migrations/*.sqlfor adds/changes, re-runs migrations with a 500ms debounce, and touchesschema.tsto trigger Next hot-reload. Zero new dependencies. Cross-platform (Windows / macOS / Linux). - New shared libs:
src/lib/main-content-extractor.ts— dependency-free HTML → paragraph-list extractor (used by URL-mode passage rewriter, reusable anywhere readable content is needed).src/lib/freshness-check.ts— comprehensive freshness signal harvester with recursive JSON-LD traversal.src/lib/ai-search-scrapers.ts— browser-mode scrapers for AI Mode + Copilot with defensive multi-selector extraction.
🧭 Upgrade notes
- Fresh installs: click
Start SEO Tool (Windows).hta— it self-bootstraps deps, build, and the Playwright browser. First run takes 5–8 minutes; HTA shows live step-by-step progress. - Existing installs: pull, then
pnpm run dev(orpnpm run dev:watchif iterating on schema).predevruns migrations automatically. No manual migration step needed — theaiVisibilityChecks.providerenum extension is type-side only. - Enable AI Mode + Copilot tracking: flip the new pill toggle on any per-client AI-visibility page.
- No new API keys required — everything in this release runs on the existing free-first stack.
📊 By the numbers
- 3 new tools · 2 new AI-visibility providers · 1 tool upgraded
- 12 AI providers unified behind a single dispatch registry
- 15 AI crawlers audited in robots.txt
- 6 freshness signal sources harvested per URL
- 10+ Windows launcher bugs fixed
- 52 files changed · +4,229 / −2,229 lines · 19 commits
- 0 new paid API keys required
Full commit log: git log v0.2.0..v0.3.0 --oneline
v0.2.0 — All-In-One Free SEO Tool
v0.2.0 — All-In-One Free SEO Tool
Release date: 2026-06-19
Diff: v0.1.1 → v0.2.0
Commits: 22 since v0.1.1
This is the largest release since v0.1.0 — license change, project rename, four shipped Moves from the 90-day plan, 12+ shipped fixes from three separate code audits, and a brand-new desktop launcher. Free-tier path is now verified clean across every tool — no paid third-party APIs are required anywhere.
🔓 License changed: PolyForm Noncommercial → MIT
The tool was previously source-available under PolyForm Noncommercial. It is now MIT-licensed. You can:
- Self-host for personal SEO, freelance, or agency work
- Modify and fork
- Sell the software or a modified version
- Run it as a paid hosted SaaS
- Bundle it into a commercial product
The only requirement is keeping the MIT copyright + permission notice in copies. The maintainer credit + tip prompt remain in the app but are not license requirements — strippable in forks. Asking nicely: leaving the credit in place helps other SEOs find the project.
Why the change: discoverability + adoption matter more than restricting commercial reuse.
🏷️ Project renamed: SEO Tool → All-In-One Free SEO Tool
package.json name: seo → all-in-one-free-seo-tool
README headline: "All-In-One Free SEO Tool — Open-Source Alternative to Ahrefs, Semrush, Moz & SE Ranking"
60+ SEO keywords added to package.json for npm + GitHub discoverability.
The GitHub repo URL stays IamRamgarhia/SEO-Tool — renaming would break every existing clone, star, and Google ranking we've built.
✨ Major features shipped this release
Onboarding + UX foundations (90-day plan Moves #1–#4)
- First-run wizard gate (a481b766): fresh users with zero clients now redirect to
/welcomeuntil they engage or explicitly dismiss - Guided / Pro sidebar modes (fe28bed2): ~15 essential items in Guided vs all 80+ in Pro, toggle in sidebar footer
- Four shared UI primitives (0be9aaa5):
EmptyState,FreshnessBadge,JargonTerm(25+ glossary terms),ConfidenceBadge— migration guide at docs/UI-PRIMITIVES.md - Cite-or-bust on AI exec summary (fd4932ec): every generated executive summary now ships with a deterministic "Data behind this summary" footer mapping prose claims to underlying numbers
- Cite-or-bust on AI site audit (b8cd768e): same pattern applied to single-page AI audits
Trust + data quality
- Audit confidence labels (a4ae5b61): every audit issue now ships with a three-tier confidence —
definitely / probably / test— matching CLAUDE.md spec. Classifier insrc/lib/audit-confidence.tsmaps all ~40 known check types. - Backlinks honesty banner + Ahrefs WMT import (a4ae5b61, b8cd768e): explicit "honest about what this shows" callout + free CSV bulk import from Ahrefs Webmaster Tools (closes the free-tier backlink coverage gap)
- Rank-tracker noise warning (b8cd768e): info tooltip on Position column header explaining the ±1-2 browser-mode noise
- Settings sub-grouping (b8cd768e): TOC regrouped into Setup / Brand / Power / Advanced / About
Install + run experience
- Desktop HTML launcher (a77e17d7): smart
SEO Tool.htmldropped on desktop — polls health, shows "Open" when running, "Start" link when stopped, auto-redirects on first successful probe. Personalised with port + paths at install time. - Seven install/run quick wins (d0f52c1e):
--app=URLbrowser mode (free PWA feel), Start Menu shortcut, opt-in Defender exclusion, graceful SIGTERM shutdown (TERM → wait 5s → KILL), Windows STOP terminal cleanup, Linux--systemservice flag,seo doctordiagnostic CLI bin/seo updateCLI (8fb1cd35): non-UI update path for when the server can't start (broken migration, missing dep)- Stable ephemeral-range ports (fcb82e93): fresh installs derive a stable port in IANA's 49152-65535 range from sha256(install path) — never collides with Next 3000, Vite 5173, Django 8000, etc.
- Audit-index freshness label (8fb1cd35): client cards now show "today" / "5d ago" / "2w ago — refresh" / "stale — refresh"
Background reliability
- Automated daily backups (c0e1c0a5): SQLite
VACUUM INTOsnapshot every 24h, configurable retention (default 7), status + controls on/settings/backup - Cross-install port collision detection (c0e1c0a5): launchers compare the running server's
installRootto their cwd — mismatch → pick a fresh port - Cost-per-client AI tracking (23e6004d):
/settings/ai-usageadds "Cost by client" section (full SQL aggregation, not truncated) - Data retention / cleanup (23e6004d): tick runner ages out screenshots (90d), ai_calls (180d), activity_log (180d), system_errors (30d)
- Daily-agent fault isolation (23e6004d): 5-min hard timeout per step; failures now also write to system_errors
Free-tier verification
- No paid API ever required (f8634bda): every tool verified to work via browser-mode OR free AI key. Image generation now defaults to free Pollinations.ai (was OpenAI-only). Policy doc at docs/NO-PAID-API-POLICY.md with a grep command for catching future regressions.
Tech stack hygiene
- Tremor → Recharts swap (eb824eb0): removed
@tremor/react(now in maintenance mode), migrated 2 chart files. −1 dep, −31 transitive packages. - xlsx CVE safety doc (eb824eb0): header comment in
src/db/import-xlsx.tsdocumenting why the SheetJS CVE doesn't apply.
🐛 Bug fixes
From this session's code review (a77e17d7)
| Severity | What |
|---|---|
| Critical | ai-call.ts spread ...opts instead of ...packed for 9 of 12 provider branches. Effect: credit-saver mode + every user-trained style rule were silently dropped for OpenAI, Groq, OpenRouter, Perplexity, Mistral, DeepSeek, Cerebras, Together, GitHub Models. Only Gemini / Anthropic / Ollama were unaffected. |
| High | runAllAiChecks fired one runAiCheck per keyword across the ENTIRE workspace with no scope, no cap, no throttle — up to 750 AI calls per button click. Now: scoped, capped at 100, throttled. |
| Medium | ai_sentiment + geo_swot were missing from VALID_FEATURES in ai-learn.ts — feedback was miscategorised as "general". |
| Medium | /api/backup streamed the live data.db file without a WAL checkpoint. Now uses VACUUM INTO like tickAutoBackup. |
From earlier audits in this release window
- 12 fixes from the user-journey audit (4aaf2707) — 3 Critical (WP plugin XSS, AI log secret-leak, wp-bridge SSRF), 5 High (invoice auth, crypto-decrypt null, weekly digest race, weekly digest N+1, OG image timeout), 4 Medium (browser-pool TOCTOU, migrate.cjs failure handling, checkProxyHealth semaphore, etc.)
- 10 fixes from earlier user-journey audit (3af1e429)
📚 New docs
docs/COMPETITIVE-AUDIT.md— full market benchmark vs Ahrefs / Semrush / Otterly / Quattr / MarketMusedocs/TECH-STACK-AUDIT.md— per-dep verdict (Keep / Swap / Add) with reasoningdocs/TOOL-RATINGS.md— usability + output-quality rating per tool with rubricdocs/UI-PRIMITIVES.md— migration cheat sheet for the four shared componentsdocs/NO-PAID-API-POLICY.md— free-tier guarantee + contributor enforcement rulesdocs/INSTALL-AND-RUN-IMPROVEMENTS.md— 20-item backlogdocs/NEXT-UX-IMPROVEMENTS.md— 15 chat-doable UX wins for follow-on sessionsdocs/GITHUB-PAGE-EDITS.md— what to change on the GitHub page UI (description, topics, social preview)docs/audits/code-audit-prompt.md— self-contained audit prompt for any AI reviewer
⚠️ Upgrade notes
Database migrations
Two new migrations apply automatically on next start:
0050_audit_issue_confidence.sql— addsconfidencecolumn toaudit_issues0051_ai_visibility_sentiment.sql— adds sentiment columns toai_visibility_checks
Both are pure ALTER TABLE ADD COLUMN — no data is touched and no downtime.
License cha...
Launch-ready release
First public release of the SEO Tool by DiceCodes.
✨ Highlights
- 150+ SEO tools in one self-hosted app
- Audits, rank tracking, keyword research, AI content, backlinks, local SEO, AI-search visibility, paid-ads funnels
- White-label PDF reports with AI executive summary
- Daily AI agent runs ~17 automated jobs per client per day
- One-command install on Windows / macOS / Linux / Docker
- Free Google APIs (GSC, GA4, PSI) + headless-browser fallbacks — no paid SERP API required
- BYO key for AI (Ollama / Gemini / Groq / OpenRouter free tiers)
💰 What it replaces
Solo freelancer stack: ₹3.35 lakh/year (Semrush + Surfer + BrightLocal + Frase + ChatGPT Plus)
Agency stack: ₹7.6 lakh/year (Ahrefs + Semrush + Surfer + BrightLocal + Frase + AgencyAnalytics)
📜 License
PolyForm Noncommercial 1.0.0 — free for self-hosting + freelance/agency client work. Commercial resale / paid SaaS hosting requires a license from Contact@dicecodes.com.