Cloudflare launched EmDash on April 1st, 2026. A spiritual successor to WordPress. Open source. MIT licensed. And free to use.
That last part is technically true. But it’s also the most misleading claim in the entire announcement.
Don't trade a predictable $20 hosting bill for a mystery bill with no ceiling.
The free tier of EmDash gives you a CMS that runs on Cloudflare Workers. You get 100,000 requests per day, 10 million per month. Sounds generous. But here’s what they don’t put in bold: the feature that makes EmDash worth considering — sandboxed plugin isolation — requires the paid plan. Without it, you’re running a version 0.1 CMS with zero plugins and no security advantage over WordPress.
The Plugin Sandbox Is Paywalled
EmDash’s defining pitch is plugin security. Every plugin runs in its own V8 isolate via dynamic workers. No database access unless explicitly granted. No file system access. No network calls unless declared.
That’s the headline. The reason anyone would migrate.
But dynamic workers require the Cloudflare Workers Paid plan. $5 a month minimum. If you deploy on the free tier, you get error code 10195. Switch to a paid plan. The sandbox — the entire reason EmDash exists — is not free.
Self-hosting doesn’t save you either. Run EmDash on your own Node.js server and sandboxed plugins don’t work at all. They run in-process. No isolation. No security advantage. You’re left with a beta CMS, zero plugin ecosystem, and the same attack surface as WordPress.
The code is free. The engine that makes it worth using is a monthly subscription.
The $13,000 Midnight Bill
Serverless billing sounds great in theory. Pay for what you use. Scale to zero. No idle server costs.
In practice, it means every page view, every admin click, every API call is a billing event. Workers bill per request and per CPU millisecond. D1 database reads bill per row. R2 operations bill per operation. KV lookups bill per read and write. One page view can hit four or five different billing meters simultaneously.
Someone on the Cloudflare forum did the math. A basic DDoS-style attack — 10,000 IPs, one request per second each — generates 26 billion requests in a month. On the paid plan, that’s roughly $13,000.
And here’s the kicker: Cloudflare does not offer a global spending cap. No kill switch. No way to say “stop charging me at $X.” You can set CPU time limits per request. You can configure rate limiting through WAF rules. But rate limiting is per IP, not a global request cap. A distributed bot attack from thousands of different IPs goes right through it.
WordPress hosting costs $20 a month. Flat. Predictable. If you get 10 visitors or 10 million, your bill stays the same. Your server might crash, but your credit card won’t.
EmDash flips that completely. And for small bloggers, freelancers, and publishers — the exact audience Cloudflare is targeting — that’s not a feature. It’s a liability.
The Strongest Counterargument — And Why It Fails
Proponents of EmDash will say this: Cloudflare’s pricing is transparent. You know the per-unit costs upfront. You can monitor usage in the dashboard. You can set CPU time limits and WAF rules. Responsible operators manage their infrastructure. This is not a hidden cost problem; it’s a user education problem.
Fair point. Transparency matters. And yes, experienced developers can monitor dashboards and configure rate limits.
But here’s the dismantling: the people Cloudflare is targeting with EmDash are not experienced developers. They’re bloggers, small publishers, freelancers migrating from WordPress because they heard it’s insecure. These are people who want to publish content and not think about infrastructure. EmDash demands the opposite. It requires you to understand Workers billing, D1 pricing, WAF configuration, and CPU time limits — just to avoid a surprise bill. There is no built-in spending cap. No automated kill switch. No safety net. The most vulnerable users — the ones with the least infrastructure knowledge — are the most exposed to the worst-case scenario. That’s not a transparency problem. That’s a design problem.
Vendor Lock-In Disguised as Open Source
EmDash is MIT licensed. The code is on GitHub. You can fork it. Read it. Run it locally.
But every meaningful feature requires Cloudflare infrastructure. The plugin sandbox requires dynamic workers, which only exist on Cloudflare’s paid runtime. The database uses D1, which is SQLite-compatible but not portable to Postgres or MySQL without rewriting. Media storage uses R2, which is S3-compatible but tightly integrated with Workers. Sessions use KV.
A production EmDash site on Cloudflare uses at minimum five separate Cloudflare products. Workers, D1, R2, KV, and Workers AI. Each is a separate billing line. None are portable.
Contrast that with WordPress. You can host it on a $5 VPS. Move it to AWS. Run it on a Raspberry Pi. Same code. Same functionality. Same cost structure. That portability is the actual spirit of open source. EmDash doesn’t have it.
The Real Second-Order Effect Everyone Misses
Here’s what most coverage of EmDash overlooks: the billing unpredictability creates a perverse incentive for Cloudflare to not build a spending cap.
Think about it. Cloudflare makes money when your site gets traffic. More requests, more database reads, more KV lookups, more billable events. A spending cap would limit their revenue from successful sites. It would also protect users from attacks, which is the right thing to do. But it would cap upside.
WordPress hosting providers have the opposite incentive. A flat-rate host makes the same $20 whether you get 100 visitors or 100,000. They’re incentivized to keep your site running efficiently. They lose money when you get DDoSed, not gain it.
EmDash’s architecture aligns Cloudflare’s revenue with your site’s traffic. That doesn’t make it malicious. But it does make the absence of a spending cap structurally convenient for the vendor. And that’s a problem no amount of “transparent pricing” documentation solves.
Who EmDash Is Actually For — Right Now
If you’re a developer who loves TypeScript and Astro and wants to experiment, EmDash is interesting. Spin up the playground. Watch it evolve. Contribute on GitHub.
But if you’re a small business owner, a blogger, a freelancer, or an agency building client sites, EmDash is not ready for you. The cost model is unpredictable. The plugin ecosystem is zero. The security sandbox requires a paid plan. The authentication system has known bugs. The editor loses content in certain edge cases.
WordPress, for all its flaws, gives you predictable costs, 60,000 plugins, 20 years of battle testing, and hosting on any provider on the planet. You can maintain your WordPress site properly — keep plugins updated, run backups, use a decent host, run a security scanner — and eliminate the practical risk EmDash’s architecture is designed to solve.
Don’t trade a predictable $20 hosting bill for a mystery bill with no ceiling.
- What is the hidden cost of the EmDash free tier?The free tier lacks plugin sandboxing, which requires the Cloudflare Workers Paid plan. Serverless billing can lead to unpredictable costs, such as $13,000 from a DDoS attack.
- Does EmDash have a spending cap?No, Cloudflare does not offer a global spending cap. You can set CPU time limits per request, but rate limiting is per IP, not a global cap.
- Who should not use EmDash right now?Small business owners, bloggers, freelancers, and agencies should avoid EmDash due to unpredictable costs, zero plugin ecosystem, and the paywalled security sandbox.