Joomla’s biggest weakness — its steep learning curve — is actually its strongest defense against the security problems that have come to define WordPress. And that’s exactly why EmDash from Cloudflare, built to solve WordPress plugin insecurity, might be a more relevant competitor to Joomla than to WordPress itself.
Let that sink in. Joomla, the “complicated” CMS that lost the popularity war, has something EmDash is trying to engineer from scratch: a permission system that doesn’t trust extensions by default. Joomla’s Access Control List (ACL) has been part of its core since version 1.5. It lets you define who can do what at the user group, category, and even article level. Extensions don’t get the keys to the kingdom. They get scoped access.
Joomla's perceived weakness — that it's harder to use than WordPress — is exactly what protects it from the plugin chaos that EmDash was built to fix.
EmDash does the same thing, but architecturally. Plugins run in isolated V8 containers called dynamic workers. They declare capabilities upfront. Read content. Send email. That’s it. No database access unless granted. No filesystem access. No unrestricted network calls.
But here’s the question neither side wants to answer directly: does a cleaner architecture matter if nobody builds for it?
| Feature | EmDash | Joomla |
|---|---|---|
| Architecture | Serverless, TypeScript/Astro, V8 isolates | Traditional, PHP/MySQL, monolithic |
| Security model | Plugin sandbox via dynamic workers (requires Cloudflare paid plan, $5/mo) | Built-in ACL, extension permissions (self-hosted, no vendor required) |
| Ecosystem size | ~0 third-party plugins at v0.1.0 launch | ~6,000+ extensions in Joomla Extensions Directory |
| Deployment flexibility | Full features only on Cloudflare; self-host loses sandbox | Any host with PHP 8+ and MySQL; fully portable |
| AI readiness | Built-in MCP server, agent skills, CLI | No native AI integration; requires third-party tools |
| Content modeling | Flexible content types with custom fields built in | Categories, tags, custom fields (core), but rigid post-type structure |
| Learning curve | Familiar to WordPress/JS developers; CLI-only setup | Steeper curve; admin interface but non-obvious UX |
| Licensing | MIT (permissive, no copyleft) | GPL (copyleft; derivative extensions must also be GPL) |
Why Joomla Has This Problem Too
WordPress gets 96% of its security vulnerabilities from plugins. That number is well-known. Less discussed is that Joomla has a similar dynamic, just less publicized. The 2025 CVE data shows Joomla extensions account for roughly 70-80% of disclosed vulnerabilities in that ecosystem. The difference is severity. Joomla’s ACL means a compromised extension typically can’t escalate to full site takeover unless the extension was granted admin-level access. WordPress has no such granularity — every plugin runs in the same process with the same wpdbcodecodecodecode access as everything else.
EmDash eliminates this at the runtime level. A plugin literally cannot touch your database unless its manifest says so. That’s not a policy. It’s hardware-enforced isolation via V8 isolates, Linux namespaces, seccomp filters, and memory protection keys. Joomla’s ACL is a software policy. EmDash’s sandbox is an architectural boundary.
But there’s a catch. That boundary only exists on Cloudflare’s runtime. Self-host EmDash on a regular Node.js server, and plugins run in-process with no isolation. Joomla’s ACL works the same way whether you’re on a $5 shared host or a dedicated server. Portability matters when you don’t want to rebuild your security model every time you move hosts.
The Migration Trap
EmDash ships a WordPress import tool. It reads WXR files and maps content, including Yoast SEO fields to EmDash’s built-in SEO controls. That works because WordPress stores content as HTML and EmDash converts it to portable text (structured JSON). For a standard blog with paragraphs and images, the migration is clean.
Joomla stores content differently. It uses a nested category system with more granular access rules. EmDash has categories and tags, but it doesn’t have Joomla’s multi-level category permissions or its built-in workflow states (unpublished, published, trashed, archived). A Joomla site with 500 articles spread across 30 categories, each with different access levels, would require a manual restructuring.
The migration tool also doesn’t touch extensions. Your Joomla component for events, or your custom module for a directory, is not coming with you. You rebuild it as an EmDash plugin or you find an alternative. With zero plugins in the EmDash ecosystem at launch, “find an alternative” means “build it yourself.”
Who Actually Benefits From Switching
If you run a Joomla site that you built yourself, you understand its quirks. You know which extensions are well-maintained. You have a backup routine. Your site is probably stable. EmDash offers you faster page loads (serverless edge delivery), lower hosting costs at scale (Cloudflare’s $5/mo plan covers most traffic), and AI-native content management via MCP. But you lose your extension ecosystem and your predictable hosting bill.
If you manage multiple Joomla sites for clients, EmDash’s passkey authentication and role-based access (admin, editor, author, contributor) might simplify user management. No passwords to leak, no brute-force vectors. But you’d need to retrain every client on a new admin interface that looks like WordPress but isn’t.
If you’re starting a greenfield content site with no legacy Joomla dependencies, EmDash is worth a look. The architecture is modern. The security model is best-in-class. The cost ceiling is lower than managed Joomla hosting. But you’re betting on a v0.1.0 beta with no track record and no community.
The Ecosystem Question That Won’t Go Away
Joomla has been around since 2005. It has thousands of extensions, a certification program, and hosting providers that specifically optimize for it. EmDash has 89 commits on GitHub, three contributors, and a playground that self-destructs after an hour. The team behind it — Matt Cain and Matt Taylor — are experienced engineers. Cloudflare has deep pockets. But ecosystems don’t grow on money alone. They grow on trust, longevity, and network effects.
Joomla’s extensions directory is curated. Extensions go through a review process. Not as backlogged as WordPress’s (800 plugins in queue at time of EmDash’s launch), but still a human check. EmDash’s plugin model trusts the sandbox instead of the reviewer. A compromised plugin in EmDash can’t steal your database. But it can still do damage within its declared scope — send spam emails, or delete content if you granted write access. The sandbox limits blast radius. It doesn’t eliminate the need for trust.
The Real Reason You Might Stay
Joomla’s complexity is a feature if you need it. The ACL system, the category hierarchy, the built-in banner management, the language management for multilingual sites — these are things EmDash doesn’t have yet. EmDash has custom content types and portable text, which is genuinely modern. But it doesn’t have Joomla’s workflow states, its template overrides system, or its 20-year library of solved problems documented across forums and books.
EmDash will get some of these. The MIT license means commercial developers can build plugins without GPL concerns. The AI agent integration means plugins and themes can be generated programmatically. But “can be generated” is not the same as “exist and are tested.” For a business that needs to ship today, Joomla’s old guard is still the safer bet.
The counterintuitive truth is this: Joomla’s perceived weakness — that it’s harder to use than WordPress — is exactly what protects it from the plugin chaos that EmDash was built to fix. Joomla never trusted extensions the way WordPress did. It never had a 60,000-plugin free-for-all. Its smaller ecosystem is also its lower attack surface. EmDash is solving a problem that Joomla, in many ways, already solved — just with software policy instead of hardware isolation.
If you’re on Joomla today and your site works, the case for switching to EmDash is not about security. It’s about performance and cost. Serverless edge delivery is genuinely faster than PHP on a shared server. Cloudflare’s D1 and R2 scale to zero when traffic is low. For a small blog or a portfolio, EmDash could cost under $20 a year. But for a complex Joomla site with custom extensions, custom templates, and specific user permissions, the migration effort will exceed the hosting savings for years.
- What is the main security difference between EmDash and Joomla?EmDash uses hardware-enforced isolation via V8 isolates and Linux namespaces, while Joomla relies on software-based Access Control Lists (ACL).
- Does EmDash's sandbox work on self-hosted servers?No, EmDash's plugin sandbox only works on Cloudflare's runtime. Self-hosted EmDash runs plugins in-process with no isolation.
- Which CMS has a larger extension ecosystem?Joomla has over 6,000 extensions in its Extensions Directory, while EmDash launched with approximately zero third-party plugins.