{"id":97968,"date":"2026-09-30T19:50:00","date_gmt":"2026-09-30T23:50:00","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=97968"},"modified":"2026-09-29T07:43:56","modified_gmt":"2026-09-29T11:43:56","slug":"emdas-security-wordpress-alternative-97968","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/emdas-security-wordpress-alternative-97968\/","title":{"rendered":"Stop Using WordPress? The EmDash Security Case Is Stronger Than Ever"},"content":{"rendered":"<p>The advice you hear everywhere goes like this: <em>WordPress powers 43% of the web. It has 60,000 plugins, 20 years of battle testing, and an ecosystem nothing else touches. Don&#8217;t switch to a beta CMS from Cloudflare \u2014 that&#8217;s reckless.<\/em><\/p>\n<p>That advice sounds reasonable. It&#8217;s also incomplete in a way that could cost you everything.<\/p>\n<p>Here&#8217;s what the conventional wisdom misses: the threat model has changed. The question isn&#8217;t whether EmDash is more feature-complete than WordPress today. It isn&#8217;t. The question is whether the architectural risk of running WordPress is still acceptable for your specific use case. For a growing number of site owners, the answer is no.<\/p>\n<h2>The Numbers Are Worse Than You Think<\/h2>\n<p>Let&#8217;s start with what the &#8220;stick with WordPress&#8221; crowd doesn&#8217;t say out loud.<\/p>\n<p>In 2025, security researchers disclosed 11,334 new WordPress vulnerabilities. That&#8217;s a 42% increase from the year before. Nearly half of those were exploitable without any authentication. And 96% of all WordPress security issues come from plugins \u2014 not from WordPress core, not from PHP, not from your hosting provider.<\/p>\n<p>Think about what that means. You install a contact form plugin. It has a bug. An attacker doesn&#8217;t need to crack your password. They don&#8217;t need to find a hole in WordPress itself. They just exploit that contact form plugin, and suddenly they have full access to your database, your file system, your user data.<\/p>\n<p>The median time from disclosure to mass exploitation? Five hours. Roughly half of high-impact exploits happen within the first 24 hours.<\/p>\n<p>This isn&#8217;t a hypothetical. Around 4.7 million WordPress sites get hacked every single year. That&#8217;s 13,000 sites per day. Every day.<\/p>\n<p>The advice to &#8220;stick with WordPress&#8221; treats this as background noise \u2014 the cost of doing business. But for a small publisher, a freelancer, or a business owner who can&#8217;t afford a dedicated security team, that cost is existential.<\/p>\n<h2>What the Plugin Sandbox Actually Changes<\/h2>\n<p>EmDash \u2014 Cloudflare&#8217;s open-source CMS built on TypeScript and Astro \u2014 doesn&#8217;t fix WordPress. It replaces the architecture that makes WordPress vulnerable.<\/p>\n<p>In WordPress, every plugin runs in the same process. There&#8217;s no sandbox. No isolation. A plugin calls <code>global $wpdb<\/code> and it has unrestricted access to every table in your database. That&#8217;s not a bug in the plugin. That&#8217;s how WordPress was designed.<\/p>\n<p>EmDash flips this completely. Every plugin runs inside its own V8 isolate, powered by Cloudflare&#8217;s dynamic workers. The plugin declares exactly what it needs in a capability manifest. It can&#8217;t touch anything else.<\/p>\n<p>A plugin that declares <code>read content<\/code> and <code>send email<\/code> can literally do nothing beyond those two actions. It cannot access your database. It cannot read your file system. It cannot make unrestricted network calls. If a compromised update tries to exfiltrate password hashes or phone home to a command server, the runtime physically blocks it.<\/p>\n<p>This isn&#8217;t a policy. It&#8217;s architectural enforcement \u2014 V8 isolates, Linux namespaces, seccomp filters, and hardware memory protection keys all working together.<\/p>\n<p>Even themes can&#8217;t touch the database. They get read-only access through an API.<\/p>\n<p>One compromised plugin cannot take down your entire site. It cannot read your other plugins&#8217; data. It cannot start crypto mining on your server. It cannot escalate to admin access. The blast radius is limited to what the manifest explicitly allows.<\/p>\n<p>That&#8217;s not a marginal improvement. That&#8217;s a fundamentally different security posture.<\/p>\n<h2>The Framework: Architecture Risk Spectrum<\/h2>\n<p>Here&#8217;s the mental model I use to evaluate CMS choices. I call it the <strong>Architecture Risk Spectrum<\/strong>.<\/p>\n<p>On one end, you have systems where every extension runs with full privileges. The security model trusts that extensions will behave. WordPress sits here. So do most traditional CMS platforms built before the modern security era.<\/p>\n<p>On the other end, you have systems where extensions run in isolated contexts with explicit capability declarations. The security model assumes extensions could be compromised and limits the damage. EmDash sits here.<\/p>\n<p>The insight is simple: if you operate a site where a breach would be catastrophic \u2014 a membership site with payment data, a media site with a large user base, a business site that generates your primary revenue \u2014 you should gravitate toward the isolated end of the spectrum. If a compromised plugin can read your entire database, you&#8217;re one vulnerability away from disaster.<\/p>\n<p>WordPress&#8217;s model was fine in 2003 when plugins were fewer and simpler. In 2026, with 62,000 plugins, many of which are abandoned, poorly maintained, or written with minimal security awareness, the risk profile has shifted.<\/p>\n<h2>What About the Counterarguments?<\/h2>\n<p>I&#8217;ve read the criticism. It&#8217;s substantial. Let me address the strongest ones directly.<\/p>\n<p><strong>&#8220;The sandbox only works on Cloudflare&#8217;s paid plan.&#8221;<\/strong><\/p>\n<p>True. The dynamic workers feature that powers plugin isolation requires Cloudflare&#8217;s Workers Paid plan, starting at $5 per month. Self-hosted EmDash on a regular Node.js server runs plugins in-process without isolation.<\/p>\n<p>This is a real limitation. But consider the alternative. A managed WordPress site on WP Engine costs around $525 the first year. EmDash on Cloudflare&#8217;s paid plan costs $75 per year. Even with the vendor dependency, the economics favor EmDash for anyone starting fresh.<\/p>\n<p><strong>&#8220;It&#8217;s vendor lock-in disguised as open source.&#8221;<\/strong><\/p>\n<p>Also true. EmDash&#8217;s code is MIT licensed. You can fork it, read it, run it locally. But the features that differentiate it \u2014 the sandbox, the edge deployment, the serverless scaling \u2014 require Cloudflare&#8217;s infrastructure.<\/p>\n<p>But let&#8217;s be honest about what &#8220;vendor lock-in&#8221; means in practice. WordPress is free software that requires $20 to $60 per month in managed hosting, plus $300 per year in premium plugins. That&#8217;s not freedom. That&#8217;s a different lock-in model.<\/p>\n<p>The question is which lock-in you prefer: paying for infrastructure that handles security for you, or paying for plugins that create most of your security risk.<\/p>\n<p><strong>&#8220;Zero ecosystem. 60,000 plugins vs. zero.&#8221;<\/strong><\/p>\n<p>This is the strongest argument against EmDash today. WordPress has WooCommerce powering 35% of e-commerce. Elementor on 10 million sites. Yoast SEO on another 10 million. The average WordPress site runs 12 to 15 plugins.<\/p>\n<p>EmDash launched with essentially zero third-party plugins. History is brutal here. Ghost launched over a decade ago with better technology. It has 0.1% market share. Craft CMS, Statamic \u2014 technically excellent, ecosystem starved.<\/p>\n<p>But EmDash&#8217;s counter-strategy is different. It ships with a built-in MCP server, agent skills, and CLI tools designed for AI-assisted development. The MIT license removes the GPL friction that keeps commercial developers away. And Joost de Valk \u2014 the founder of Yoast SEO, used on 10 million WordPress sites \u2014 called EmDash the most interesting thing to happen to content management in years.<\/p>\n<p>When the creator of the most popular WordPress SEO plugin takes a project seriously, the ecosystem argument starts to weaken.<\/p>\n<h2>The Risk Calculus Has Changed<\/h2>\n<p>Here&#8217;s the honest take. If you&#8217;re building a greenfield content site in 2026, and security matters to you \u2014 not theoretically, but practically \u2014 EmDash is worth a serious look. Not because it&#8217;s better than WordPress today. Because its architecture eliminates a class of risk that WordPress cannot fix without a complete rewrite.<\/p>\n<p>WordPress will be around for decades. It&#8217;s battle-tested. It has an ecosystem that no competitor can match. But its security model is structurally broken. The advice to &#8220;stick with WordPress&#8221; assumes that broken model is acceptable.<\/p>\n<p>For many sites, it still is. A simple blog with a few plugins, a static site with minimal interactivity, a brochure site with no user accounts \u2014 the risk is low. The conventional wisdom applies.<\/p>\n<p>But for sites with payment processing, user authentication, membership systems, or sensitive data, the calculus changes. One compromised plugin can destroy everything. And with 11,334 new vulnerabilities in 2025 alone, the probability that <em>your<\/em> site will be affected is higher than most people want to admit.<\/p>\n<h2>The Edge Case No One Talks About<\/h2>\n<p>Here&#8217;s the nuance that doesn&#8217;t fit the pro-WordPress narrative.<\/p>\n<p>Consider a site that has already been compromised once. A site that has suffered a plugin vulnerability, lost data, or dealt with a malware cleanup. For those site owners, the &#8220;stick with it&#8221; advice rings hollow. They&#8217;ve experienced the cost of the architectural risk firsthand.<\/p>\n<p>EmDash&#8217;s sandbox doesn&#8217;t just reduce the probability of a breach. It reduces the <em>blast radius<\/em> of a breach. A compromised plugin on EmDash cannot cascade. It cannot spread to other plugins, the database, or the file system. The damage is contained.<\/p>\n<p>For anyone who has gone through a WordPress security incident \u2014 the cleanup, the lost trust, the downtime \u2014 that containment is worth more than the ecosystem gap.<\/p>\n<h2>The Bottom Line<\/h2>\n<p>The conventional wisdom says don&#8217;t switch. And for most use cases, that&#8217;s still the right call. WordPress works. It has the plugins. It has the community. It has the track record.<\/p>\n<p>But the conventional wisdom is not a security argument. It&#8217;s a convenience argument. And convenience has a cost.<\/p>\n<p>EmDash is version 0.1.0. It has bugs. It has a long way to go before it can replace WordPress for the majority of sites. But its architectural foundation is sound in a way that WordPress&#8217;s has never been. The plugin sandbox isn&#8217;t a feature. It&#8217;s a fundamentally different approach to security.<\/p>\n<p>If you&#8217;re starting fresh and security is your top priority, the safer bet might not be the 24-year-old platform with a broken permission model. It might be the two-month-old beta that got the architecture right.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The advice you hear everywhere goes like this: WordPress powers 43% of the web. It has 60,000 plugins, 20 years of battle testing, and an ecosystem nothing else touches. Don&#8217;t switch to a beta CMS from Cloudflare \u2014 that&#8217;s reckless. That advice sounds reasonable. It&#8217;s also incomplete in a way that could cost you everything. [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":98677,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/97968.png","fifu_image_alt":"Stop Using WordPress? The EmDash Security Case Is Stronger Than Ever","footnotes":""},"categories":[31],"tags":[],"class_list":["post-97968","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology"],"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/97968.png","fifu_image_alt":"Stop Using WordPress? The EmDash Security Case Is Stronger Than Ever","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/97968","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=97968"}],"version-history":[{"count":1,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/97968\/revisions"}],"predecessor-version":[{"id":98145,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/97968\/revisions\/98145"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/98677"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=97968"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=97968"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=97968"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}