{"id":97975,"date":"2026-10-01T12:38:00","date_gmt":"2026-10-01T16:38:00","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=97975"},"modified":"2026-09-29T07:45:47","modified_gmt":"2026-09-29T11:45:47","slug":"emdash-vendor-lock-in-cost-97975","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/emdash-vendor-lock-in-cost-97975\/","title":{"rendered":"EmDash and the Hidden Cost of Vendor Lock-In"},"content":{"rendered":"<p>You&#8217;ve read the pitch. Cloudflare&#8217;s EmDash is the spiritual successor to WordPress. TypeScript, not PHP. Sandboxed plugins. Serverless by design. MIT licensed. Open source.<\/p>\n\n<p>That last part is doing a lot of heavy lifting.<\/p>\n\n<p>Open source code doesn&#8217;t mean portable infrastructure. And portable infrastructure doesn&#8217;t mean portable operations. The gap between those three things is where the real cost lives. Most early coverage of EmDash skips this entirely. They compare feature lists. They run the playground. They declare it promising or premature.<\/p>\n\n<p>The lock-in question is more subtle than &#8220;can I fork the repo.&#8221; You can. You absolutely can. The question is whether the thing you fork still works the way you need it to.<\/p>\n\n<h2>The Five Layers of EmDash Lock-In<\/h2><h3>Layer One: The V8 Isolate Sandbox<\/h3><p>This is EmDash&#8217;s headline feature. Every plugin runs in its own isolated container. It cannot touch your database, file system, or user sessions unless the capability manifest explicitly allows it. That&#8217;s the architectural fix for WordPress&#8217;s biggest vulnerability class.<\/p>\n\n<p>But here&#8217;s the non-obvious part: that sandbox only exists on Cloudflare&#8217;s runtime. Dynamic Workers are a Cloudflare-specific product. They run on Cloudflare&#8217;s infrastructure, orchestrated by Cloudflare&#8217;s control plane, billed through Cloudflare&#8217;s pricing model.<\/p>\n\n<p>Self-host EmDash on a Node.js server and plugins run in-process. No isolation. No security advantage over WordPress. The feature that justifies the entire project \u2014 the solution to 96% of WordPress vulnerabilities \u2014 requires you to be on Cloudflare&#8217;s paid plan.<\/p>\n\n<p>The code is MIT. The runtime that makes it valuable is proprietary.<\/p>\n\n<h3>Layer Two: The Runtime Dependency<\/h3><p>WordPress runs anywhere you can put PHP and MySQL. A $5 VPS. A Raspberry Pi. AWS, GCP, Azure, literally any shared host from 2004. That portability is not an accident. It&#8217;s the result of 24 years of compatibility engineering.<\/p>\n\n<p>EmDash runs on two runtimes: Cloudflare Workers and Node.js. Those are not equivalent.<\/p>\n\n<p>On Workers, you get the full feature set. D1 for database. R2 for storage. KV for sessions. Workers AI for inference. The entire Cloudflare ecosystem is available, and the CMS is designed to use it. The deployment tooling assumes Cloudflare. The CLI defaults to Cloudflare. The playground spins up on Cloudflare.<\/p>\n\n<p>On Node.js, you get SQLite and local storage. No sandboxed plugins. No edge deployment. No automatic CDN. No zero-egress storage. You are running a headless CMS with a local database and no plugin security model. The experience is fundamentally different.<\/p>\n\n<p>This is not a bug. It&#8217;s a design <a href=\"https:\/\/overcentral.com\/en\/ichra-choice-arrangements-label-97925\/\" title=\"ICHRA Gets CHOICE Arrangements Label from CMS, SBA\" data-iacss-internal=\"1\">choice<\/a>. EmDash is built to demonstrate Cloudflare&#8217;s infrastructure. The Node.js option exists for development and evaluation, not for production parity.<\/p>\n\n<h3>Layer Three: The Database<\/h3><p>WordPress uses MySQL or MariaDB. You can dump the database, move it to another host, and restore it. The SQL is standard. The schema is documented. Migration tools exist for every platform.<\/p>\n\n<p>EmDash uses D1 on Cloudflare and SQLite everywhere else. D1 is built on SQLite, but it&#8217;s not portable SQLite. It&#8217;s a distributed SQLite implementation that runs across Cloudflare&#8217;s edge network. You cannot export a D1 database and import it into PostgreSQL, MySQL, or even vanilla SQLite without rewriting the storage layer.<\/p>\n\n<p>The migration path out of EmDash is not &#8220;dump and restore.&#8221; It&#8217;s &#8220;extract and transform.&#8221; Every relationship, every content type definition, every field configuration \u2014 you write custom scripts for all of it.<\/p>\n\n<p>The import tool works one direction. WordPress to EmDash. There is no EmDash to anywhere.<\/p>\n\n<h3>Layer Four: The Storage<\/h3><p>WordPress stores media files in a directory. <code>wp-content\/uploads<\/code>codecodecodecode. You can rsync it, SCP it, mount it via NFS, or sync it to S3 with a plugin. The storage model is simple and portable.<\/p>\n\n<p>EmDash on Cloudflare uses R2. R2 is S3-compatible, which sounds portable. It is, at the API level. But the migration is not API-compatible. You download objects from R2 and upload them to S3, or <a href=\"https:\/\/www.google.com\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Google<\/a> Cloud Storage, or Backblaze. You rebuild the URL structure. You update every media reference in the database.<\/p>\n\n<p>That&#8217;s a migration project, not a migration script.<\/p>\n\n<h2>Layer Five: The Billing Model<\/h2><p>This is where the lock-in becomes financially dangerous.<\/p>\n\n<p>WordPress hosting is predictable. You pay a flat monthly rate. Traffic spikes might crash your server, but they don&#8217;t increase your bill. You know what you owe before the month starts.<\/p>\n\n<p>EmDash on Cloudflare is serverless. You pay per request, per CPU millisecond, per database read, per storage operation. One page view can hit five different billing meters simultaneously. Workers, D1, R2, KV, and possibly Workers AI if you use moderation features.<\/p>\n\n<p>The paid plan starts at $5\/month and includes 10 million requests. That sounds generous. It is, for a small blog. But the cost scales with traffic, and there is no spending cap. Cloudflare does not offer a kill switch. If your site gets hit by a botnet, your workers keep firing and your credit card keeps charging.<\/p>\n\n<p>Someone on the Cloudflare forum calculated the math: a basic DDoS with 10,000 IPs making one request <a href=\"https:\/\/overcentral.com\/en\/meta-launches-zgateway-proxy-handles-1-billion-ops-per-second\/\" title=\"Meta Launches ZGateway Proxy, Handles 1 Billion Ops Per Second\" data-iacss-internal=\"1\">per second<\/a> each would generate 26 billion requests in a month. At $0.30 per million over the included 10 million, that&#8217;s $7,800 in request charges alone. Plus CPU time, database reads, and storage operations. The total could exceed $13,000.<\/p>\n\n<p>WordPress on a $20\/month VPS would crash under that load. Your site goes down. Your bill stays the same. EmDash would stay up and bill you for the privilege.<\/p>\n\n<h3>What the Enthusiasts Miss<\/h3><p>The developer preview crowd runs EmDash on the playground. They deploy a demo blog. They write one post. They never see a bill. They conclude the architecture is brilliant and the economics are compelling.<\/p>\n\n<p>They are right about the architecture. The plugin sandbox is genuinely innovative. The V8 isolate model is faster and more secure than anything WordPress offers. The economics are compelling \u2014 for a site that gets zero traffic.<\/p>\n\n<p>The moment you deploy a production site that actually gets visitors, the calculus changes. Every visitor costs money. Every admin panel interaction costs money. Every plugin hook firing costs money. The costs are small per unit, but they add up, and they are unpredictable.<\/p>\n\n<h3>The Ecosystem Trap<\/h3><p>WordPress has 60,000+ plugins. WooCommerce powers 35% of e-commerce. Elementor runs on 10 million sites. Yoast SEO on another 10 million. The average WordPress site runs 12-15 plugins. That&#8217;s not bloat. That&#8217;s functionality that businesses actually need.<\/p>\n\n<p>EmDash launched with zero third-party plugins. The counter-strategy is AI: the MCP server lets <a href=\"https:\/\/overcentral.com\/en\/rogue-ai-agents-liability-vacuum-97898\/\" title=\"Rogue AI agents expose liability vacuum as OpenAI faces claims\" data-iacss-internal=\"1\">AI agents<\/a> generate plugins and themes programmatically. The MIT license removes GPL friction. The theory is that developers will build what they need on demand.<\/p>\n\n<p>That theory assumes every business has a developer on staff who understands TypeScript, Astro, and Cloudflare Workers. Many do not. They have a content manager who knows how to install plugins from a marketplace. EmDash offers no marketplace. It offers a CLI and an MCP endpoint.<\/p>\n\n<p>For an agency building client sites, the ecosystem vacuum is a hard stop. You cannot deliver WooCommerce, Gravity Forms, or LearnDash functionality in EmDash today. You can build custom equivalents, but that takes weeks or months per feature. WordPress delivers them in an afternoon.<\/p>\n\n<h3>The Governance Angle Nobody Discusses<\/h3><p>WordPress&#8217;s governance problems are real. The 2024 WP Engine dispute proved that one person&#8217;s discretion can affect millions of sites. EmDash is governed by Cloudflare, a for-profit company with fiduciary duties to shareholders. That&#8217;s not inherently worse, but it is different.<\/p>\n\n<p>Cloudflare&#8217;s incentives are clear. EmDash exists to sell Cloudflare services. Every feature that makes EmDash compelling \u2014 the sandbox, the edge deployment, the zero-egress storage, the AI integration \u2014 requires Cloudflare infrastructure. The project will never prioritize portability over platform stickiness because that would undermine its business model.<\/p>\n\n<p>This is not a conspiracy. It&#8217;s the normal operation of a company building open-source software to drive commercial adoption. The lock-in is intentional. It&#8217;s the product.<\/p>\n\n<h3>When EmDash Makes Sense<\/h3><p>There is a narrow use case where EmDash is genuinely compelling: greenfield content sites built by TypeScript developers who want to experiment with edge computing and don&#8217;t mind vendor dependency. A personal blog. A documentation site. A marketing site for a tech company that already runs on Cloudflare.<\/p>\n\n<p>For everything else, the lock-in costs exceed the architectural benefits.<\/p>\n\n<p>WordPress is not better technology. It is older, slower, and structurally less secure. But it is portable. You can move it. You can host it anywhere. You can hire developers who know it. You can find plugins for edge cases you haven&#8217;t imagined yet. That portability has real economic value, and EmDash trades it for performance and security guarantees that only work inside Cloudflare&#8217;s walls.<\/p>\n\n<h3>The Real Test<\/h3><p>EmDash needs to answer one question it currently avoids: what is the exit strategy?<\/p>\n\n<p>Every WordPress site has one. Export the database, download the uploads folder, move to a new host. The process is documented, tested, and reliable.<\/p>\n\n<p>Every EmDash site on Cloudflare has no documented exit strategy. The code is open source. The data is technically portable. But the path from Cloudflare to anywhere else is unpaved. No migration tool. No supported destination. No guarantee that self-hosted EmDash will run your plugins or render your themes the same way.<\/p>\n\n<p>Until that exists, EmDash is not a WordPress alternative. It&#8217;s a Cloudflare feature with a CMS skin.<\/p>\n<div id=\"rank-math-faq\" class=\"rank-math-block\">\n<div class=\"rank-math-list \">\n<div id=\"faq-question-1\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">Can I migrate my EmDash site off Cloudflare?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>The code is MIT licensed and you can run it on any Node.js server. But the sandboxed plugin system, which is EmDash&#8217;s main security feature, only works on Cloudflare&#8217;s paid runtime. Your database (D1) and storage (R2) are also Cloudflare-specific. There is no migration tool to move data out. The exit path requires custom scripting and will lose the security model.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-2\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">Does EmDash have spending caps?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>No. Cloudflare does not offer a global request cap or kill switch. A traffic spike or DDoS attack can generate unlimited billable requests. The paid plan includes 10 million requests, but overage charges can accumulate quickly with no upper limit.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-3\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">How many plugins does EmDash have?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Zero third-party plugins at launch. The platform relies on AI agents (via MCP server) and custom development to generate functionality. There is no plugin marketplace.<\/p>\n\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>You&#8217;ve read the pitch. Cloudflare&#8217;s EmDash is the spiritual successor to WordPress. TypeScript, not PHP. Sandboxed plugins. Serverless by design. MIT licensed. Open source. That last part is doing a lot of heavy lifting. Open source code doesn&#8217;t mean portable infrastructure. And portable infrastructure doesn&#8217;t mean portable operations. The gap between those three things is [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":98739,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/97975.png","fifu_image_alt":"EmDash and the Hidden Cost of Vendor Lock-In","footnotes":""},"categories":[31],"tags":[],"class_list":["post-97975","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology"],"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/97975.png","fifu_image_alt":"EmDash and the Hidden Cost of Vendor Lock-In","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/97975","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=97975"}],"version-history":[{"count":2,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/97975\/revisions"}],"predecessor-version":[{"id":98740,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/97975\/revisions\/98740"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/98739"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=97975"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=97975"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=97975"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}