EmDash Billing Warning: How a DDoS Attack Could Cost You $13,000

Cloudflare's EmDash CMS has no spending cap, making a DDoS attack potentially cost thousands in overage fees.

By Central
A single DDoS attack on EmDash can generate 26 billion requests, leading to $13,000 in unexpected charges.
Highlights
  • A botnet with 10,000 devices hitting a site once per second generates 864,000 requests per day.
  • EmDash bills per request and per CPU millisecond across Workers, D1, R2, and KV simultaneously.
  • There is no spending cap or kill switch, so your card keeps getting charged during an attack.

Serverless billing sounds great until your credit card maxes out. Cloudflare’s new EmDash CMS runs on Workers, D1, R2, and KV — each with its own meter. Combine them under a distributed denial-of-service attack, and the math gets terrifying fast.

A single post on the Cloudflare forum laid it bare: 10,000 unique IPs, each making one request per second, can generate 26 billion billable requests in a month. On the paid plan ($5/month for 10 million requests), you’d pay $0.30 per additional million. That works out to roughly $7,800 in overage — before CPU time, database reads, and storage operations. Add those, and $13,000 is a conservative estimate.

A single DDoS on EmDash can bankrupt your business.

There is no spending cap. No kill switch. Your site keeps serving requests, and your card keeps getting charged.

The Billing Model That Scales With Attacks

WordPress hosting is flat-rate. $20 a month, $50 a month — traffic spikes might crash your server, but your bill stays the same. EmDash flips that model entirely. Every page view, admin click, API call, and plugin hook invocation is a Worker invocation. Workers bill per request and per CPU millisecond.

Here’s the breakdown for a typical EmDash site on Cloudflare’s paid plan:

  • Workers: 10 million requests included. After that, $0.30 per million.
  • D1 database: reads and writes billed per row. Each page load can trigger multiple queries.
  • R2 storage: billed per operation (GET, PUT, DELETE). Zero egress, but operations add up.
  • KV: billed per read/write for session state and plugin data.

A single page view can hit four or five billing meters simultaneously. Predicting monthly costs as a small business owner? Impossible.

The attack scenario isn’t theoretical. A botnet with 10,000 compromised devices — common in even modest DDoS attacks — each hitting your site once per second, generates 864,000 requests per day. Over 30 days, that’s 25.9 million requests. But that’s just the Worker count. Each request also triggers D1 lookups (your content), R2 reads (media files), and KV checks (authentication tokens). The real bill multiplies.

Why Rate Limiting Won’t Save You

Cloudflare does offer mitigations. You can set CPU time limits per request. You can configure WAF rate limiting rules. But these tools have hard limits.

Rate limiting is per-IP, not global. A distributed attack from thousands of different IPs — each sending one request per second — bypasses per-IP rate limits entirely. Each IP looks like a normal visitor. The WAF sees 10,000 unique “users” and lets them through.

CPU time limits control duration, not count. A limit of 30 seconds per Worker invocation doesn’t reduce the number of invocations. It just means each request finishes faster — but you’re still billed for every single one.

Cloudflare does offer an “Advanced Rate Limiting” feature that can aggregate across IPs, but it’s an additional paid product (starting at $5/month) and requires manual configuration. Most small publishers don’t know it exists, let alone how to set it up for DDoS protection.

The fundamental issue: EmDash’s billing is designed for normal traffic patterns. An attack is not a normal pattern, and the platform provides no automatic circuit breaker.

The Counterargument — and Why It Falls Apart

Defenders of EmDash point out that Cloudflare’s network itself is built to absorb DDoS attacks. Their edge network can filter malicious traffic before it reaches your Workers. They offer Bot Management and Advanced DDoS protection as add-ons.

This is true. Cloudflare’s infrastructure is world-class. Their free tier already blocks many common attacks.

But here’s the catch: those protections apply to network-layer attacks (L3/L4) and some application-layer attacks (L7) — but they don’t perfectly filter every malicious HTTP request that looks like a legitimate page load. A botnet that sends real-looking GET requests for your home page will bypass most WAF rules because the requests are technically valid. Cloudflare cannot distinguish between a human clicking “refresh” and a script doing the same thing at 1 request per second.

The $5/month paid plan does include basic DDoS protection, but it’s not designed to prevent billing spikes. Cloudflare’s own documentation warns that “Workers usage-based billing” can scale unexpectedly under high traffic. The company’s recommendation? Set up budget alerts and monitor dashboards. That’s not a solution — that’s a notification after the damage is done.

The Second-Order Effect Most Coverage Misses

Beyond the immediate financial risk, the lack of a spending cap creates a chilling effect on EmDash adoption for risk-averse businesses. Freelancers, agencies, and small publishers — the exact audience EmDash targets as a WordPress alternative — cannot afford a $13,000 surprise. They need predictable costs.

This uncertainty will push many potential users toward managed WordPress hosting, where $20/month buys a fixed bill regardless of traffic. Even if EmDash’s architecture is objectively superior, the billing model introduces a risk that most small businesses cannot accept.

The irony: EmDash’s selling point is solving WordPress’s plugin security problem. But it introduces a new, equally dangerous risk — financial insecurity. A single bad plugin in WordPress can compromise your data. A single DDoS on EmDash can bankrupt your business. Both are unacceptable for production sites.

Who Should Worry Most

  • Bloggers and small publishers: You don’t have a dedicated security team to configure WAF rules and monitor dashboards. You publish content and hope for the best. EmDash’s billing model punishes that trust.
  • Agencies building client sites: You’re liable for cost overruns. A client’s site gets attacked, you get the bill. No spending cap means no ceiling on your liability.
  • Developers experimenting: A personal project with low traffic is safe. But as soon as you promote it, the risk grows.

The Real Fix That Doesn’t Exist Yet

Cloudflare could solve this by introducing a hard spending cap — a “stop billing me after $X” switch. They haven’t. The reason is architectural: Workers and D1 are designed for elastic scaling. A hard cap would break that promise.

But for a CMS targeting WordPress refugees, a predictable billing model isn’t optional. It’s table stakes.

Until Cloudflare adds a kill switch, EmDash remains a developer toy — not a production platform for anyone who values their credit card.

Questions answered
  • How much can a DDoS attack on EmDash cost?A DDoS attack can generate 26 billion requests, resulting in over $13,000 in overage fees on the paid plan.
  • Why doesn't rate limiting prevent the billing risk?Rate limiting is per-IP, so a distributed attack from thousands of unique IPs bypasses it, and CPU time limits don't reduce invocation count.
Share This Article