EmDash CMS vs Payload CMS: Why the Common Advice Is Wrong

A deep dive into why the standard recommendation for Payload CMS may not suit modern projects, and how EmDash CMS offers a compelling alternative.

By Central
Comparing EmDash CMS and Payload CMS: architecture, security, ecosystem, and the right choice for your next project.
Highlights
  • EmDash CMS ships built-in SEO, media management, and forms, reducing the need for plugins in greenfield projects.
  • Payload CMS plugins run in the same process with full database access, while EmDash sandboxes plugins via Cloudflare Workers for enhanced security.
  • The common advice favoring Payload CMS overlooks EmDash's radical architecture, which is better for security, scalability, and AI integration.

“Just go with Payload CMS — it’s battle-tested, has a proper ecosystem, and isn’t an April Fools joke.” That’s what everyone says when you ask about TypeScript content management systems. And for good reason. Payload has been around since 2021, powers thousands of production sites, and offers a mature admin UI with custom fields, access control, and a plugin marketplace.

But this advice is incomplete. It assumes every project needs the same things: maximum plugin availability, a traditional hosting model, and years of community validation. The reality is that a growing number of projects need something fundamentally different — and EmDash CMS, Cloudflare’s spiritual successor to WordPress, delivers that difference.

The architecture is not a compromise — it's a step forward.

Here’s why the standard recommendation misses the mark, and how to actually choose between these two TypeScript CMS platforms.

EmDash CMS vs Payload CMS: Key Differences at a Glance

Attribute EmDash CMS Payload CMS
Architecture Full-stack (admin + frontend built with Astro) Headless (admin separate from frontend)
Plugin Security Sandboxed via Cloudflare Dynamic Workers (V8 isolates) Plugins run in the same process, full database access
Hosting Default Serverless on Cloudflare (D1, R2, Workers) Self-hosted on any Node.js server (SQLite/PostgreSQL)
AI Integration Built-in MCP server, CLI, agent skills Plugin-based, no native MCP support
Ecosystem Maturity 0.1.0 beta, ~38 GitHub stars at launch v2.0 stable, thousands of stars, active plugin marketplace
Pricing Model Pay-per-request (predictable only with flat-rate hosting) Fixed hosting cost, no surprise bills
License MIT MIT (core), plugins vary

The table makes one thing obvious: these are not close competitors. They serve different architectural philosophies. The common advice treats “maturity” as a universal trump card, but for specific use cases, EmDash’s radical architecture is actually the safer bet.

Why the Ecosystem Argument Fails for Greenfield Projects

The most common objection to EmDash is the ecosystem gap. “WordPress has 60,000 plugins, Payload has dozens, EmDash has zero.” That’s true today. But it’s a static view of a moving target.

Consider what you’re actually building. A greenfield blog, a marketing site, or a portfolio rarely needs 15 plugins. You need structured content, SEO, media management, and maybe forms. EmDash ships all of that in core — custom content types, built-in SEO fields, a form builder, and image optimization via R2. Payload requires plugins for some of these, and those plugins come with their own upgrade cycles and security profiles.

The real question isn’t “how many plugins exist?” It’s “how many do you need right now?” For a project starting from scratch, EmDash’s out-of-the-box feature set covers the vast majority of common use cases. The ecosystem argument only matters when you need a specific integration (e.g., Stripe, Shopify, a particular analytics tool) that doesn’t exist yet. For those cases, Payload wins today. But for everything else, EmDash’s built-in features are a cleaner starting point.

Security: The Architecture That Changes Everything

Here’s the number that should make every Payload user pause. 96% of WordPress vulnerabilities come from plugins. That’s not a WordPress problem — it’s a plugin architecture problem. Every plugin in WordPress (and in most CMS platforms, including Payload) runs in the same process with unrestricted database access.

Payload is built on Express.js and MongoDB/PostgreSQL. When you install a Payload plugin, it can read, write, and delete any collection. It can execute raw SQL or MongoDB queries. There is no sandbox. The plugin author is trusted by default.

EmDash CMS completely flips this model. Every plugin runs inside its own V8 isolate via Cloudflare’s Dynamic Workers. The plugin declares a capability manifest — “read content, send email” — and the runtime enforces that boundary. The plugin cannot access the database, the file system, or other plugins. It cannot make outbound network calls unless explicitly granted.

This isn’t a feature improvement. It’s a fundamental security upgrade. In 2025, security researchers disclosed 11,334 new WordPress vulnerabilities, 91% from plugins. The median time from disclosure to mass exploitation was 5 hours. A single compromised plugin in Payload can exfiltrate your entire user database. In EmDash, that same plugin literally cannot read your user collection.

If you’re building a site where data security is non-negotiable — a membership platform, a SaaS dashboard, a healthcare portal — EmDash’s sandbox is the only responsible choice. The common advice ignores this because it assumes “mature ecosystem” equals “secure by default.” It doesn’t.

Hosting and Scalability: Serverless vs Self-Hosted

Payload CMS requires a Node.js server. You can deploy it on a VPS, AWS EC2, or a PaaS like Railway. You pay a fixed monthly cost regardless of traffic. That’s predictable and simple. But it doesn’t scale automatically. A traffic spike can crash your server or force you to upgrade.

EmDash CMS is serverless by design. It runs on Cloudflare Workers, which spin up in milliseconds per request and scale to zero when idle. For a blog that gets 100 visitors a day, the cost is near zero (the free tier includes 10 million worker requests). For a site that gets 100,000 visitors daily, the $5 plan covers roughly 3% of its monthly request allowance.

The catch: serverless billing is unpredictable. Without spending caps, a DDoS attack can rack up thousands of dollars in charges. Cloudflare does offer rate limiting via WAF, but it’s not a global spending cap. For small businesses on tight budgets, this risk is real. Payload’s fixed hosting cost eliminates that worry.

But for projects that expect traffic spikes — a product launch, a viral blog post, a seasonal campaign — EmDash’s auto-scaling is a lifesaver. Payload would require manual scaling or a load balancer. EmDash just handles it.

AI Readiness: Built-In vs Bolted On

Every CMS now claims AI integration. Most of them bolt a chatbot onto the admin panel. EmDash CMS took a different approach: it ships with a built-in MCP (Model Context Protocol) server from day one. Any MCP-compatible AI agent — Claude, Cursor, GitHub Copilot — can connect directly to your CMS and perform structured tasks: create content types, migrate themes, update 100 posts at once, generate new plugins.

Payload has no native MCP support. You can build custom API endpoints for AI agents, but that’s development work. EmDash’s agent skills files tell the AI exactly how to operate the CMS without custom prompting. The co-creator of WordPress, Matt Mullenweg, called this “a brilliant strategy” and said WordPress needs to do the same as soon as possible.

If your workflow already involves AI coding agents, EmDash is the only TypeScript CMS that treats AI as a first-class user. That’s not a niche scenario — it’s the direction the industry is heading.

The Real Deal: When to Choose Each

Choose Payload CMS when:

  • You need a specific plugin that doesn’t exist in EmDash yet.
  • You have an existing Node.js infrastructure and want to self-host.
  • Your budget requires fixed, predictable hosting costs.
  • You’re building a complex application with many custom integrations.
  • You need a mature admin UI with granular access control today.

Choose EmDash CMS when:

  • You’re starting a greenfield content site (blog, marketing, portfolio).
  • Security is your top priority — especially if handling user data.
  • You want serverless scaling without managing infrastructure.
  • You’re already using AI agents in your development workflow.
  • You want a CMS that costs near zero for low-traffic sites.

The Missed Nuance: Vendor Lock-In vs Architecture Lock-In

The common advice warns about EmDash’s vendor lock-in. “You need Cloudflare for the sandbox feature — that’s lock-in.” True. But Payload has its own lock-in: you’re locked into the Express/Node.js ecosystem and whatever database you choose. Switching from Payload to another CMS is a full migration project.

EmDash’s code is MIT licensed. You can fork it, run it on any Node.js server, and move your data (SQLite or PostgreSQL) to any host. The sandbox feature is tied to Cloudflare’s runtime, but that’s a single feature. The rest of the CMS is portable. Payload’s data model is tightly coupled to its API layer — migrating out requires rebuilding your frontend against a new backend.

Neither is truly portable. But EmDash’s lock-in is a feature you can optionally pay for. Payload’s lock-in is the entire architecture.

Final Recommendation

If you’re building a site that needs security, scalability, and AI integration from day one, stop following the common advice. EmDash CMS is the right choice despite its infancy. The architecture is not a compromise — it’s a step forward.

If you need a proven, plugin-rich CMS for a complex application today, Payload remains the safer bet. But don’t confuse “safe” with “right.” The best CMS for your project depends on what you’re building, not on how many plugins exist.

Try EmDash’s playground at emdashcms.com. Deploy a Payload project to Railway. Compare them yourself. The common advice is wrong for a growing set of use cases — and that set will only grow as EmDash matures.

Questions answered
  • What is the main difference between EmDash CMS and Payload CMS?EmDash CMS is a full-stack CMS built with Astro and runs serverless on Cloudflare, while Payload CMS is a headless CMS that can be self-hosted on any Node.js server.
  • Why is the ecosystem argument against EmDash CMS considered weak?For greenfield projects, EmDash ships all essential features in core, so the need for plugins is minimal. The ecosystem argument only matters for specific integrations that don't exist yet.
  • How does security differ between EmDash CMS and Payload CMS?EmDash sandboxes plugins via Cloudflare Workers, preventing full database access, while Payload plugins run in the same process with full database access, increasing risk.
Share This Article