EmDash Has No Spending Cap – Here’s How to Protect Your Wallet

Cloudflare's new CMS EmDash has no spending cap, risking massive bills from bot attacks. Here's how to stay safe.

By Central
EmDash's serverless billing model lacks a global spending cap, exposing users to potential financial risk.
Highlights
  • EmDash has no global spending cap, meaning a DDoS attack could generate 26 billion billable requests in a month.
  • The paid plan includes 10 million requests, with overage costs of $0.30 per million, plus CPU and database fees.
  • Cloudflare's WAF rate limiting can help, but it does not provide a hard spending cap to prevent surprise bills.

The most dangerous thing about EmDash isn’t a bug or a security flaw. It’s the fact that the software has no kill switch for your wallet.

Cloudflare’s new CMS, the self-proclaimed spiritual successor to WordPress, runs on serverless infrastructure. Every page view, every admin click, every plugin execution fires a Cloudflare Worker. Workers bill per request and per CPU millisecond. There is no global spending cap. No “stop billing me at $X” toggle. Nothing built into the platform that says “this is too much, shut it down.”

WordPress's greatest strength isn't its technology. It's its predictability.

One developer on Cloudflare’s own forum did the math. A basic DDoS attack — 10,000 distinct IP addresses, one request per second each — generates 26 billion billable requests in a month. The paid plan includes 10 million. After that, you’re paying $0.30 per additional million requests, plus CPU time, plus D1 database reads, plus R2 storage operations, plus KV lookups. Every page render can hit four or five different billing meters simultaneously.

And there is nothing you can do to stop it.

This isn’t a hypothetical. It’s a structural property of how serverless billing works. And it’s the thing most coverage of EmDash is missing.

What EmDash Actually Is

Let’s be fair. EmDash is architecturally impressive.

Built entirely in TypeScript on top of Astro 6, it’s a full-stack, open-source CMS released under MIT license on April 1, 2026. Cloudflare calls it the spiritual successor to WordPress. The lead engineer, Matt Cain (an Astro core team member), built most of it in about two months with significant AI assistance.

The headline feature is the plugin sandbox. WordPress plugins run in the same process as the core — full database access, full file system access, full network access. In 2025, security researchers disclosed 11,334 new WordPress vulnerabilities. 96% came from plugins. EmDash flips that: every plugin runs inside its own V8 isolate via Cloudflare’s dynamic workers. A plugin declares exactly what it needs in a capability manifest — “read content” and “send email” — and the runtime enforces that boundary physically. No database access unless granted. No file system access. No unrestricted network calls.

That’s genuinely clever. The architecture is sound.

The sandbox also solves a licensing problem. WordPress plugins are forced into GPL because of how deeply they integrate with WordPress core. EmDash plugins don’t share code with the core system. You can keep your intellectual property closed source or MIT. Combined with the built-in 402 payment protocol, developers can monetize on a per-use basis without centralized marketplace gatekeeping.

EmDash ships with a built-in MCP server, meaning AI agents can manage content directly. Passkey authentication (WebAuthn) is the default — no passwords to leak. WordPress import tool is included. Three starter templates (blog, marketing site, portfolio) come out of the box. You can try it right now at emdashcms.com/playground — a full instance spins up in your browser, no install required.

All of this is real. All of it matters. None of it helps you when the billing meter runs.

The Billing Problem No One Warns You About

Traditional WordPress hosting gives you a flat rate. $20 a month. $50 a month. If you get 10 visitors or 10 million, your server might slow down or crash, but your bill stays the same. You know what you’re paying.

EmDash flips that completely.

The paid plan starts at $5 a month and includes 10 million Worker requests. After that, $0.30 per additional million requests. CPU time charges on top. D1 database reads bill per row. R2 storage operations bill per operation. KV lookups bill per read and write.

Let’s be concrete. One page view can trigger:

  • A Worker invocation (billed per request + CPU ms)
  • Multiple D1 queries (billed per row read)
  • R2 media lookups (billed per operation)
  • KV session reads (billed per read)

Try predicting that monthly cost as a small business owner. You can’t.

Cloudflare offers some mitigations. You can set CPU time limits per individual request. You can configure rate limiting through WAF rules. But rate limiting is per IP, not a global request cap. A distributed bot attack from thousands of different IPs goes right through it. CPU limits only control how long each request runs, not how many requests you get billed for.

And there is no global spending cap. No kill switch. Your site keeps running. Workers keep firing. Your credit card keeps getting charged.

Think about who EmDash is targeting. Bloggers. Small publishers. People migrating from WordPress because they heard it’s insecure. These are not people who configure WAF rules and monitor Cloudflare dashboards daily. They want to publish content and not think about infrastructure.

EmDash gives them the exact opposite.

The Hidden Vendor Lock-In

Here’s the part that makes this worse.

Cloudflare is marketing EmDash as free open-source MIT licensed. The code is on GitHub. You can fork it, read it, run it locally. But the moment you try to actually deploy it to Cloudflare — which is where it’s designed to run — you hit a wall.

The headline feature of EmDash is sandboxed plugins. That’s the entire pitch. WordPress plugins are insecure because they have full database access. EmDash sandboxes every plugin in its own isolated environment.

Except that sandboxing requires something called dynamic workers. And dynamic workers require the Cloudflare Workers paid plan. Try to deploy on the free tier and you get error code 10195. Switch to a paid plan.

So let’s be honest about what “free and open source” means here. The code is free. The feature that makes it worth using is not.

It gets worse if you self-host. Cloudflare says you can run EmDash on any Node.js server — your own hardware, AWS, wherever. But when you self-host, there is currently no support for sandboxed plugins at all. The only feature they’re using to differentiate from WordPress just disappears. You’re left running a brand-new CMS with zero plugins and no security advantage over WordPress.

Every EmDash site on Cloudflare uses at minimum five Cloudflare products: Workers for compute, D1 for database, R2 for media storage, KV for sessions, and Workers AI. Each is a separate billing line. None are predictable. None are portable.

You can’t take a D1 database and move it to AWS. You can’t migrate R2 buckets to Azure without rewriting your entire storage layer. You can’t replicate the Worker isolate sandbox anywhere else at all.

The code is MIT. The runtime that powers every meaningful feature is proprietary Cloudflare infrastructure.

Contrast that with WordPress. You can host it on a $5 VPS. You can move it to AWS. You can run it on a Raspberry Pi. Same code, same functionality, anywhere. That portability is the actual spirit of WordPress. And EmDash doesn’t have it — despite claiming to be the spiritual successor.

The Ecosystem Gap

WordPress has over 60,000 plugins. WooCommerce powers 35% of all e-commerce. Elementor runs on 10 million sites. Yoast SEO, another 10 million. The average WordPress site runs 12 to 15 plugins.

EmDash launched with essentially zero third-party plugins. History is brutal here. Ghost launched over a decade ago with better technology than WordPress. It has 0.1% market share. Craft CMS, Statamic — technically excellent, ecosystem-starved.

EmDash’s counter-strategy is AI. The built-in MCP server means AI coding tools can generate plugins and themes programmatically. The MIT license removes GPL friction. Joost de Valk, the founder of Yoast SEO (used on 10 million WordPress sites), called EmDash the most interesting thing to happen to content management in years.

But signals don’t ship features.

The migration tool only imports content — posts, pages, media. It doesn’t migrate your plugins, your theme, your custom functionality, your WooCommerce store, your membership system, your forms, your SEO configuration. All of that, you’re building from scratch. WordPress stores content as HTML. EmDash uses portable text (structured JSON). For any site with custom blocks, advanced layouts, or complex content structures, that’s a serious engineering project.

One reviewer tested the beta and ran into bugs immediately. Passkey authentication didn’t work on their Linux setup. The magic link fallback returned a page-not-found error.

This is not production software.

The Second-Order Effect: Misaligned Incentives

Here’s what most coverage misses.

The lack of a spending cap isn’t a technical oversight. It’s a structural feature of the business model. Cloudflare profits from usage. Every Worker invocation, every D1 read, every R2 operation — that’s revenue. There is no built-in incentive for Cloudflare to help you spend less.

Traditional hosting aligns incentives differently. You pay a flat rate. The host wants you to stay within that rate because they’ve already collected their money. They may throttle you or ask you to upgrade, but they have no incentive to let your bill explode.

Serverless hosting passes the risk to the user. The user must actively manage infrastructure complexity to avoid financial ruin. That’s the opposite of the “spiritual successor to WordPress” promise of democratized publishing.

WordPress’s 5-minute install was successful precisely because it removed infrastructure thinking from the equation. You didn’t need to understand server provisioning or database optimization. You just installed and published.

EmDash requires you to understand Cloudflare’s entire product suite — Workers, D1, R2, KV, WAF rules, CPU time limits, rate limiting — just to run a website without getting a surprise bill.

That’s not democratization. That’s a different kind of gatekeeping.

How to Protect Your Wallet (If You Still Want to Try)

If you’re a developer who wants to experiment with EmDash, you can do it safely. Here’s how.

Use the playground first. The browser-based playground at emdashcms.com/playground lasts an hour. Break things. Learn the interface. No billing risk.

Self-host for development. Run EmDash on a local Node.js server with SQLite. You lose the plugin sandbox, but you get the CMS experience with zero cloud costs.

If you deploy to Cloudflare, start on the free tier. You won’t get dynamic workers (no sandboxed plugins), but you can test performance and understand your baseline usage before committing.

Set CPU time limits. This is the one mitigation Cloudflare does offer. Limit each Worker request to a maximum CPU duration. This prevents runaway code from consuming excessive resources.

Configure WAF rate limiting. Not a global cap, but it helps against basic bot traffic. Understand that distributed attacks bypass this.

Monitor daily. Check your Cloudflare dashboard for usage spikes. Set up notifications. If you see unexpected growth, investigate immediately.

Keep an exit plan. EmDash’s data is portable — D1 is SQLite, R2 is S3-compatible. But the security model isn’t. If you ever need to leave Cloudflare, you lose the plugin sandbox. Have a migration path back to a traditional CMS.

Don’t put a client’s business on it. Not yet. The architecture is smart. The billing model is not.

What This Means for the Future

The real test for EmDash isn’t whether it can match WordPress’s feature set. It’s whether Cloudflare adds a global spending cap.

Without one, EmDash is a developer toy with a trapdoor. The architecture solves real problems — plugin security, licensing friction, AI integration — but the billing model creates a different kind of vulnerability. One that hits your bank account instead of your database.

WordPress’s greatest strength isn’t its technology. It’s its predictability. You know what you’re paying. You know where you’re hosted. You know your site won’t generate a surprise $13,000 bill because of a bot attack.

EmDash needs to match that predictability to be a real WordPress alternative. Until then, it’s an impressive experiment with a dangerous blind spot.

Questions answered
  • What is EmDash?EmDash is a full-stack, open-source CMS built by Cloudflare on Astro 6, released under MIT license on April 1, 2026.
  • Why does EmDash have no spending cap?EmDash runs on serverless infrastructure where every action bills per request and CPU millisecond, with no built-in global spending limit.
  • How can I protect my wallet from EmDash bills?Set CPU duration limits on Workers, configure WAF rate limiting, monitor your dashboard daily, and keep an exit plan with portable data.
Share This Article