Stop Using WordPress? The EmDash Security Case Is Stronger Than Ever

WordPress faces 11,334 new vulnerabilities in 2025, but EmDash's plugin sandbox offers a fundamentally different security approach.

By Central
EmDash's V8 isolate sandbox prevents plugin vulnerabilities from cascading, unlike WordPress's shared process architecture.
Highlights
  • In 2025, security researchers disclosed 11,334 new WordPress vulnerabilities, a 42% increase from the previous year.
  • 96% of all WordPress security issues come from plugins, not from core or hosting.
  • EmDash runs every plugin inside its own V8 isolate, preventing compromised plugins from accessing the database or file system.

The advice you hear everywhere goes like this: WordPress powers 43% of the web. It has 60,000 plugins, 20 years of battle testing, and an ecosystem nothing else touches. Don’t switch to a beta CMS from Cloudflare — that’s reckless.

That advice sounds reasonable. It’s also incomplete in a way that could cost you everything.

The plugin sandbox isn't a feature. It's a fundamentally different approach to security.

Here’s what the conventional wisdom misses: the threat model has changed. The question isn’t whether EmDash is more feature-complete than WordPress today. It isn’t. The question is whether the architectural risk of running WordPress is still acceptable for your specific use case. For a growing number of site owners, the answer is no.

The Numbers Are Worse Than You Think

Let’s start with what the “stick with WordPress” crowd doesn’t say out loud.

In 2025, security researchers disclosed 11,334 new WordPress vulnerabilities. That’s a 42% increase from the year before. Nearly half of those were exploitable without any authentication. And 96% of all WordPress security issues come from plugins — not from WordPress core, not from PHP, not from your hosting provider.

Think about what that means. You install a contact form plugin. It has a bug. An attacker doesn’t need to crack your password. They don’t need to find a hole in WordPress itself. They just exploit that contact form plugin, and suddenly they have full access to your database, your file system, your user data.

The median time from disclosure to mass exploitation? Five hours. Roughly half of high-impact exploits happen within the first 24 hours.

This isn’t a hypothetical. Around 4.7 million WordPress sites get hacked every single year. That’s 13,000 sites per day. Every day.

The advice to “stick with WordPress” treats this as background noise — the cost of doing business. But for a small publisher, a freelancer, or a business owner who can’t afford a dedicated security team, that cost is existential.

What the Plugin Sandbox Actually Changes

EmDash — Cloudflare’s open-source CMS built on TypeScript and Astro — doesn’t fix WordPress. It replaces the architecture that makes WordPress vulnerable.

In WordPress, every plugin runs in the same process. There’s no sandbox. No isolation. A plugin calls global $wpdb and it has unrestricted access to every table in your database. That’s not a bug in the plugin. That’s how WordPress was designed.

EmDash flips this completely. Every plugin runs inside its own V8 isolate, powered by Cloudflare’s dynamic workers. The plugin declares exactly what it needs in a capability manifest. It can’t touch anything else.

A plugin that declares read content and send email can literally do nothing beyond those two actions. It cannot access your database. It cannot read your file system. It cannot make unrestricted network calls. If a compromised update tries to exfiltrate password hashes or phone home to a command server, the runtime physically blocks it.

This isn’t a policy. It’s architectural enforcement — V8 isolates, Linux namespaces, seccomp filters, and hardware memory protection keys all working together.

Even themes can’t touch the database. They get read-only access through an API.

One compromised plugin cannot take down your entire site. It cannot read your other plugins’ data. It cannot start crypto mining on your server. It cannot escalate to admin access. The blast radius is limited to what the manifest explicitly allows.

That’s not a marginal improvement. That’s a fundamentally different security posture.

The Framework: Architecture Risk Spectrum

Here’s the mental model I use to evaluate CMS choices. I call it the Architecture Risk Spectrum.

On one end, you have systems where every extension runs with full privileges. The security model trusts that extensions will behave. WordPress sits here. So do most traditional CMS platforms built before the modern security era.

On the other end, you have systems where extensions run in isolated contexts with explicit capability declarations. The security model assumes extensions could be compromised and limits the damage. EmDash sits here.

The insight is simple: if you operate a site where a breach would be catastrophic — a membership site with payment data, a media site with a large user base, a business site that generates your primary revenue — you should gravitate toward the isolated end of the spectrum. If a compromised plugin can read your entire database, you’re one vulnerability away from disaster.

WordPress’s model was fine in 2003 when plugins were fewer and simpler. In 2026, with 62,000 plugins, many of which are abandoned, poorly maintained, or written with minimal security awareness, the risk profile has shifted.

What About the Counterarguments?

I’ve read the criticism. It’s substantial. Let me address the strongest ones directly.

“The sandbox only works on Cloudflare’s paid plan.”

True. The dynamic workers feature that powers plugin isolation requires Cloudflare’s Workers Paid plan, starting at $5 per month. Self-hosted EmDash on a regular Node.js server runs plugins in-process without isolation.

This is a real limitation. But consider the alternative. A managed WordPress site on WP Engine costs around $525 the first year. EmDash on Cloudflare’s paid plan costs $75 per year. Even with the vendor dependency, the economics favor EmDash for anyone starting fresh.

“It’s vendor lock-in disguised as open source.”

Also true. EmDash’s code is MIT licensed. You can fork it, read it, run it locally. But the features that differentiate it — the sandbox, the edge deployment, the serverless scaling — require Cloudflare’s infrastructure.

But let’s be honest about what “vendor lock-in” means in practice. WordPress is free software that requires $20 to $60 per month in managed hosting, plus $300 per year in premium plugins. That’s not freedom. That’s a different lock-in model.

The question is which lock-in you prefer: paying for infrastructure that handles security for you, or paying for plugins that create most of your security risk.

“Zero ecosystem. 60,000 plugins vs. zero.”

This is the strongest argument against EmDash today. WordPress has WooCommerce powering 35% of e-commerce. Elementor on 10 million sites. Yoast SEO on another 10 million. The average WordPress site runs 12 to 15 plugins.

EmDash launched with essentially zero third-party plugins. History is brutal here. Ghost launched over a decade ago with better technology. It has 0.1% market share. Craft CMS, Statamic — technically excellent, ecosystem starved.

But EmDash’s counter-strategy is different. It ships with a built-in MCP server, agent skills, and CLI tools designed for AI-assisted development. The MIT license removes the GPL friction that keeps commercial developers away. And Joost de Valk — the founder of Yoast SEO, used on 10 million WordPress sites — called EmDash the most interesting thing to happen to content management in years.

When the creator of the most popular WordPress SEO plugin takes a project seriously, the ecosystem argument starts to weaken.

The Risk Calculus Has Changed

Here’s the honest take. If you’re building a greenfield content site in 2026, and security matters to you — not theoretically, but practically — EmDash is worth a serious look. Not because it’s better than WordPress today. Because its architecture eliminates a class of risk that WordPress cannot fix without a complete rewrite.

WordPress will be around for decades. It’s battle-tested. It has an ecosystem that no competitor can match. But its security model is structurally broken. The advice to “stick with WordPress” assumes that broken model is acceptable.

For many sites, it still is. A simple blog with a few plugins, a static site with minimal interactivity, a brochure site with no user accounts — the risk is low. The conventional wisdom applies.

But for sites with payment processing, user authentication, membership systems, or sensitive data, the calculus changes. One compromised plugin can destroy everything. And with 11,334 new vulnerabilities in 2025 alone, the probability that your site will be affected is higher than most people want to admit.

The Edge Case No One Talks About

Here’s the nuance that doesn’t fit the pro-WordPress narrative.

Consider a site that has already been compromised once. A site that has suffered a plugin vulnerability, lost data, or dealt with a malware cleanup. For those site owners, the “stick with it” advice rings hollow. They’ve experienced the cost of the architectural risk firsthand.

EmDash’s sandbox doesn’t just reduce the probability of a breach. It reduces the blast radius of a breach. A compromised plugin on EmDash cannot cascade. It cannot spread to other plugins, the database, or the file system. The damage is contained.

For anyone who has gone through a WordPress security incident — the cleanup, the lost trust, the downtime — that containment is worth more than the ecosystem gap.

The Bottom Line

The conventional wisdom says don’t switch. And for most use cases, that’s still the right call. WordPress works. It has the plugins. It has the community. It has the track record.

But the conventional wisdom is not a security argument. It’s a convenience argument. And convenience has a cost.

EmDash is version 0.1.0. It has bugs. It has a long way to go before it can replace WordPress for the majority of sites. But its architectural foundation is sound in a way that WordPress’s has never been. The plugin sandbox isn’t a feature. It’s a fundamentally different approach to security.

If you’re starting fresh and security is your top priority, the safer bet might not be the 24-year-old platform with a broken permission model. It might be the two-month-old beta that got the architecture right.

Questions answered
  • How many WordPress vulnerabilities were disclosed in 2025?Security researchers disclosed 11,334 new WordPress vulnerabilities in 2025, a 42% increase from the year before.
  • What percentage of WordPress security issues come from plugins?96% of all WordPress security issues come from plugins, not from WordPress core, PHP, or hosting.
  • How does EmDash's plugin sandbox work?EmDash runs every plugin inside its own V8 isolate, and the plugin declares exactly what it needs in a capability manifest. It cannot access the database, file system, or make unrestricted network calls.
Share This Article