You don't really need vlans, just separate lans. :)
You already have 5 lan interfaces, and since one should be dedicated to the wan, you can have up to 4 segmented lans to play with, without any vlans.
If you need more that that, then the dlink switch in 802.1p mode can provide even more segmented lans.
But I think 4 is enough.
Lets say 4 zones, business, leisure, guest/wifi/printers/phones, and??
Of course things get complicated if for example you want wifi access to he business segment from wifi for some devices, but not for guests, or we don't want the missus to have fb access (god save us).
You should strive to have devices having common internet requirements on the same lan, so you can leverage pfblockerng et al better.