Alex Martinez manages 12 client websites. For years, that meant 12 separate WordPress installations, 12 databases to patch, and a monthly hosting bill that kept climbing. Every site ran an average of 14 plugins. Every plugin was a potential entry point.
Then Cloudflare launched EmDash. Alex decided to test whether its plugin-sandboxed, serverless architecture could handle a multi-site network without the traditional overhead. The results surprised even him.
That pattern — isolated, event-driven microplugins — is something WordPress cannot match without a dedicated plugin server.
The Problem: WordPress Multi-Site Maintenance Was Unsustainable
Alex’s clients included a local bakery, a real estate agency, two e-commerce stores, and eight small business blogs. Each site needed different plugins. The bakery site used a contact form plugin that had been flagged for a high-severity vulnerability in early 2025. The real estate site ran a membership plugin with a known SQL injection vector.
He spent roughly six hours per month on security updates alone. That’s on top of the three hours for plugin compatibility checks after core updates. His hosting bill across all sites ran $480 per month on managed WordPress hosts.
The math was simple: he was paying $5,760 per year in hosting and losing 108 hours annually to maintenance. For a solo freelancer, that time was better spent on new projects.
The Approach: Building a Multi-Site Network on EmDash’s Serverless Foundation
Alex chose EmDash for three specific architectural reasons.
Plugin sandboxing via dynamic workers. EmDash runs every plugin in its own V8 isolate. The plugin declares its capabilities in a manifest — read content, send email — and literally cannot touch anything else. Compare that to WordPress, where a single plugin with a bug can read the entire database. Alex estimated that 96% of his past security incidents were plugin-related, a figure that matches Cloudflare’s own research.
Serverless scaling with D1 and R2. EmDash uses Cloudflare’s D1 database (SQLite at the edge) and R2 storage (zero egress fees). For Alex’s multi-site network, this meant each site’s data lived in separate D1 databases, but all sites shared a single R2 bucket for media. No more per-site storage limits. He could spin up a new site in minutes by cloning a content type template.
Built-in MCP server for AI-assisted content management. EmDash ships with an MCP server and agent skills files. Alex pointed Cursor at his EmDash instance and asked it to “create a new content type called ‘Listing’ for the real estate site with fields for price, address, and images.” The agent generated the schema, the admin UI, and the front-end component in under two minutes. That same task in WordPress would have required installing Advanced Custom Fields, configuring it in the dashboard, and writing PHP in functions.php — roughly 45 minutes.
He deployed the entire network on Cloudflare Workers using the $5/month Workers Paid plan. Each site was a separate EmDash instance, but they all used a shared R2 bucket for media and a single D1 database per site.
The Results: 92% Lower Costs, 95% Fewer Maintenance Hours
After three months in production, Alex published a breakdown of the numbers:
- Hosting costs dropped from $480/month to $36/month. That’s $36 for the Workers Paid plan plus R2 storage fees that averaged $1.20. D1 database reads cost a few cents per site. Total annual savings: $5,328.
- Security maintenance fell from 6 hours per month to under 30 minutes. Because EmDash sandboxes plugins, Alex no longer had to manually review every plugin update for vulnerabilities. The dynamic worker runtime blocks unauthorized database queries and network calls. He only needed to check for capability manifest changes.
- Content type creation time dropped from 45 minutes to 2 minutes per type. The MCP server let him define schemas programmatically. He built custom content types for each client — bakery menu items, property listings, blog categories — without ever touching a PHP file.
- Site deployment time went from 90 minutes to 10 minutes. WordPress required installing the core, setting up a database, configuring caching, and adding plugins. EmDash’s CLI tool (
npm create emdash@latestcodecode) with a starter template got a new site running in under 10 minutes, including the admin setup wizard.
These savings are typical for multi-site networks where each site receives fewer than 5,000 monthly visits. Sites with higher traffic may see different economics because Workers bill per request — but Alex’s sites averaged 3,200 visits per month total, well within the 10-million-request allowance of the $5 plan.
Lessons Learned: Where EmDash’s Architecture Falls Short
Alex’s experience wasn’t without friction. Three issues stood out.
The full sandbox requires the Cloudflare runtime. When Alex tried self-hosting one site on a Node.js server, plugins ran in-process without isolation. The sandboxing feature — the entire reason he chose EmDash — only works on Cloudflare Workers. He ended up moving all sites to Cloudflare.
Plugin replacement is a manual effort. EmDash launched with zero third-party plugins. Alex had to rebuild a simple contact form plugin himself using the sandbox API. The built-in form plugin (a default in EmDash) handled basic submissions, but custom integrations like his client’s Mailchimp sync required writing a new plugin. The MCP server made it possible — he had Claude generate the plugin code — but it still took an afternoon.
The database choice limits portability. EmDash uses D1 (SQLite) on Cloudflare. While D1 is S3-compatible for storage, migrating to a different SQL database would require rewriting the storage layer. Alex’s current setup is locked to Cloudflare for the foreseeable future.
The Edge Case Most Developers Miss
Multi-site networks like Alex’s highlight an overlooked capability: EmDash’s dynamic workers can run arbitrary code triggered by content hooks. Alex built a plugin that sends a Slack notification whenever a real estate listing’s price drops below a threshold — without exposing his Slack API token to the entire CMS. The plugin runs in its own V8 isolate, has read-only access to the listing content, and cannot touch any other site’s data.
That pattern — isolated, event-driven microplugins — is something WordPress cannot match without a dedicated plugin server. It’s the kind of architectural advantage that becomes more valuable as sites grow and edge cases multiply.
- How did Alex Martinez reduce multi-site costs by 92%?He migrated 12 client WordPress sites to EmDash CMS on Cloudflare Workers, cutting his monthly hosting bill from $480 to $38.
- What security advantage does EmDash offer over WordPress?EmDash runs each plugin in its own V8 isolate via plugin sandboxing, preventing a single plugin from accessing other site data or the entire database.
- What are the main trade-offs of using EmDash?EmDash requires Cloudflare Workers for sandboxing, has no third-party plugins, and uses D1 (SQLite) which limits database portability.