EmDash vs Drupal: Why “Drupal Is Too Complex” Misses the Point

A deep dive into why Drupal's steep learning curve is a strength for complex sites, not a reason to switch to EmDash.

By Central
Comparing EmDash's serverless, AI-native architecture with Drupal's mature ecosystem for structured content.
Highlights
  • EmDash's plugin sandbox eliminates the 96% of WordPress vulnerabilities that come from plugins.
  • Drupal offers over 47,000 contributed modules, while EmDash launched with zero plugins.
  • For complex editorial workflows and custom permissions, Drupal's learning curve pays off in flexibility and stability.

Everyone says it: Drupal is overkill. Too steep a learning curve. Too much configuration. For most content sites, you’re better off with a modern CMS like EmDasha—serverless, AI-native, built in TypeScript. The advice sounds sensible. It’s also incomplete in ways that matter.

EmDash, Cloudflare’s v0.1.0 spiritual successor to WordPress, launched on April 1, 2026. It’s written entirely in TypeScript, powered by Astro, and runs on V8 isolates at the edge. Plugins are sandboxed via dynamic workers. It has a built-in MCP server for AI agents. MIT licensed. All impressive.

The common advice—'Drupal is too complex, use something modern'—ignores the reality that complexity is a feature when the problem is complex.

Drupal is 25 years old. It runs on PHP and MySQL. Its plugin-like module ecosystem has over 47,000 contributed modules. It’s used by governments, universities, and enterprises worldwide. Its learning curve is real. But the gap between “hard to learn” and “wrong tool” is vast.

This article explains where the common advice breaks down—and why Drupal still wins for specific use cases that EmDash hasn’t touched.

The Comparison: EmDash vs Drupal at a Glance

Attribute EmDash Drupal
Architecture Serverless, V8 isolates, Cloudflare Workers Traditional LAMP stack, can run on any server
Content Modeling Custom content types via admin UI (database-stored) Full entity system with fields, bundles, and views in code
Plugin Security Sandboxed via dynamic workers (paid Cloudflare plan) Module runs in same process; no sandbox; relies on community review
AI Integration Built-in MCP server, agent skills, CLI No native AI; requires contributed modules or custom code
Ecosystem 0 plugins at launch; zero theme marketplace 47,000+ modules, thousands of themes, dedicated hosting providers
Learning Curve Moderate (TypeScript, Astro, CLI setup) Steep (custom entity types, Views, hooks, YAML configuration)
Cost Free tier for hobbled version; paid plan (~$5/month) for sandbox; unpredictable serverless billing Open source; hosting from $5/month VPS to managed enterprise; predictable flat rate

Recommendation: If you need structured content with complex editorial workflows, multiple content types, and custom permissions out of the box—and you want to avoid vendor lock-in—choose Drupal. If you’re building a simple blog, a marketing site, or a portfolio, and you want serverless scalability with AI agents from day one, EmDash is worth a serious look. The advice “Drupal is too complex” only holds when your use case is simple.

What EmDash Gets Right – and Why It’s Still v0.1

EmDash’s headline feature is the plugin sandbox. Every plugin runs in its own V8 isolate, a lightweight execution context that spins up in milliseconds. It must declare capabilities in a manifest: “read content, send email.” No database access, no file system access, no unrestricted network calls. This architecturally eliminates the 96% of WordPress vulnerabilities that come from plugins.

Authentication uses passkeys by default—no passwords to leak or brute force. The admin dashboard is clean and familiar to WordPress users. Built-in SEO, custom content types, a front-end editor, and a WordPress migration tool. All MIT licensed.

But it’s version 0.1.0. The sandbox feature requires Cloudflare’s paid plan with dynamic workers—$5/month minimum. Self-host on Node.js and you lose the sandbox entirely. The plugin ecosystem is zero. The theme ecosystem is zero. The content types you create in the admin UI are stored in the database, not as code—a regression for anyone who wants infrastructure-as-code. And the billing model is serverless: unpredictable per-request costs with no global spending cap. A DDoS attack or a viral post can generate a surprise bill.

Drupal, by contrast, has been battle-tested for two decades. Its content modeling is far more mature.

Where Drupal’s Architecture Still Dominates

Content Modeling That’s Actually Modeled

Drupal’s entity system is its superpower. You define content types, fields, and bundles in code (via YAML or PHP). Each field can be a text, image, reference, taxonomy term, date, file, or custom. You can create relationships between entities, build views with filters and sorts, and expose everything via REST or GraphQL.

EmDash lets you create custom content types through the admin UI. That’s fine for a simple blog or portfolio. But the fields are stored in the database, not version-controlled. If you migrate a site, you have to recreate those types manually or rely on a dump. There’s no code-first approach to schema management.

Drupal’s approach scales to complex information architectures: a university with courses, faculty, departments, events, publications, and news—all interrelated. EmDash’s current model breaks down here.

Workflows and Permissions

Drupal has a built-in workflow engine for content moderation: draft, review, published, archived. Each transition can trigger actions. Permissions are granular per content type and per role. Need an editor who can only publish articles but not pages? Done.

EmDash has role-based access control (admin, editor, author, contributor) but no workflow states. No content moderation pipelines. No custom permissions per content type. For a newsroom or a corporate site with multiple authors and reviewers, that’s a dealbreaker.

Multisite Without a Vendor Lock

Drupal’s multisite feature lets you run dozens or hundreds of sites from a single codebase. Common modules, themes, and updates. Each site gets its own database and files. No vendor dependency.

EmDash is designed for single-site deployments on Cloudflare. Running multiple sites means separate instances, separate billing, separate infrastructure. You can’t share a plugin or theme across sites without copying code. There’s no multisite concept.

Predictable Costs

Drupal hosting is a flat monthly fee: $20 on a VPS, $100 on managed, $500+ on enterprise. Same bill whether you get 100 visitors or 100,000. Traffic spikes might slow your site, but they don’t empty your bank account.

EmDash’s serverless billing is unpredictable. Workers, D1 database reads, R2 operations, KV lookups—each page view can hit four or five billing meters. No global spending cap. Cloudflare offers rate limiting and CPU time limits, but those don’t cap total requests. A distributed bot attack can rack up thousands of dollars. One forum post estimated $13,000 from a modest DDoS.

The Ecosystem Gap: Modules vs Agents

Drupal’s 47,000 modules cover every conceivable need: e-commerce (Commerce), SEO (Metatag, XML Sitemap), forms (Webform), calendars (Calendar), forums, translations, accessibility, workflows, performance, security. You install, configure, and move on.

EmDash launched with zero third-party plugins. Its counter-strategy is AI: a built-in MCP server and agent skills files that let AI coding tools generate plugins and themes on the fly. That’s clever. But it assumes every site owner can or wants to use AI agents to build missing functionality. For a business that needs e-commerce, forms, and SEO tools today, EmDash is weeks of custom development. Drupal has all of that in an afternoon.

Where the Common Advice Fails: The University Scenario

Imagine a university with 15 departments, each publishing news, events, course listings, faculty profiles, and research papers. Content types are interconnected: a news article references a department and a faculty member. Editors need workflow states. Some content is restricted to authenticated users. The site must scale to 50,000 daily visitors with predictable costs.

The common advice says: “Drupal is too complex; use a modern CMS like EmDash.” Let’s test that.

EmDash can handle the content types, but you’ll build them in the admin UI. No code, no version control. Workflow states? Not built-in. Custom permissions per content type? Not built-in. Multisite for each department? Not built-in. Serverless billing? Unpredictable at scale.

Drupal handles all of this out of the box or with a few contributed modules. The learning curve is real—but for this use case, the time invested in learning Drupal pays back in flexibility, stability, and predictable costs. The “too complex” advice assumes simplicity is always better. It’s not.

The Honest Take

EmDash is the most architecturally coherent challenge to WordPress in years. The plugin sandbox, the serverless model, the AI-native design—these are genuine innovations. For a greenfield blog or marketing site where security and performance matter, and where you’re comfortable with TypeScript and CLI tools, EmDash is worth a serious look.

Drupal is not for everyone. It’s for sites that need structured content, editorial workflows, custom permissions, and a predictable hosting bill. Its ecosystem is mature. Its community is large. Its architecture is battle-tested.

The common advice—”Drupal is too complex, use something modern”—ignores the reality that complexity is a feature when the problem is complex. EmDash solves a different set of problems. Drupal solves another. The right choice depends on what you’re building, not on what’s trending.

One thing EmDash has that Drupal doesn’t: a built-in path for AI agents to manage content programmatically. Drupal’s community will need to solve that soon. The next version of Drupal (11) is already incorporating decoupled features and API-first design. The race isn’t over.

Questions answered
  • What is EmDash?EmDash is a serverless, AI-native CMS built in TypeScript, launched on April 1, 2026, as a spiritual successor to WordPress.
  • Why is Drupal considered too complex?Drupal has a steep learning curve due to custom entity types, Views, hooks, and YAML configuration, but this complexity is beneficial for complex use cases.
  • Which CMS is better for simple blogs?EmDash is better for simple blogs, marketing sites, or portfolios, offering serverless scalability and AI integration from day one.
  • What are the key differences between EmDash and Drupal?EmDash uses serverless V8 isolates and has built-in AI, while Drupal runs on a traditional LAMP stack with a mature module ecosystem and predictable hosting costs.
Share This Article