{"id":97980,"date":"2026-10-02T00:38:00","date_gmt":"2026-10-02T04:38:00","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=97980"},"modified":"2026-09-29T07:47:00","modified_gmt":"2026-09-29T11:47:00","slug":"emdash-cms-cloudflare-engineers-questions-97980","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/emdash-cms-cloudflare-engineers-questions-97980\/","title":{"rendered":"EmDash CMS: 10 Questions Cloudflare Engineers Answered"},"content":{"rendered":"<h2>1. How does EmDash\u2019s plugin sandbox actually work under the hood?<\/h2><p>The plugin sandbox isn\u2019t just a permission layer\u2014it\u2019s a full V8 isolate powered by Cloudflare\u2019s dynamic workers. Each plugin runs in its own lightweight context that spins up in about 5 milliseconds and disappears when execution ends. The plugin declares exactly what it needs in a capability manifest: read content, send email, but nothing else. The runtime enforces that boundary at the hardware level using Linux namespaces, seccomp filters, and memory protection keys. A compromised plugin cannot touch the database, file system, or network unless explicitly granted. This is not policy\u2014it\u2019s architectural enforcement. The cold start penalty is essentially zero because V8 isolates reuse an existing Node.js process and create a sandboxed context, not a full container.<\/p>\n\n<h2>2. Why did Cloudflare choose MIT over GPL?<\/h2><p>The GPL\u2019s copyleft nature creates compliance overhead for enterprises. Any plugin or theme that integrates deeply with WordPress core must adopt GPL, which forces commercial developers to either open-source their code or avoid the ecosystem entirely. Cloudflare wanted to remove that friction. With MIT, developers can keep plugins closed-source, license them under any terms, and even use <a href=\"https:\/\/overcentral.com\/en\/rogue-ai-agents-liability-vacuum-97898\/\" title=\"Rogue AI agents expose liability vacuum as OpenAI faces claims\" data-iacss-internal=\"1\">AI agents<\/a> to generate code without worrying about viral licensing. The lead engineer spent weeks with lawyers to ensure EmDash had no derivative relationship with WordPress\u2014no reference to its source code, different language, different architecture. MIT also simplifies the <a href=\"https:\/\/overcentral.com\/en\/meta-muse-ai-agent-80441\/\" title=\"Meta Launches Muse AI Agent, Needs User Trust\" data-iacss-internal=\"1\">AI agent<\/a> play: agents can read, modify, and generate plugins without triggering license restrictions.<\/p>\n\n<h2>3. What\u2019s the real cost of running EmDash on Cloudflare?<\/h2><p>Serverless billing is unpredictable. Every page view can hit multiple meters: Workers (per request and CPU time), D1 database reads, R2 storage operations, KV lookups, and potentially Workers AI. A single user action might trigger four or five separate billing events. Cloudflare offers no global spending cap\u2014you can wake up to a $13,000 bill from a DDoS attack, as one forum post calculated. The paid plan starts at $5\/month for 10 million Workers requests, but after that you pay $0.30 per million plus CPU time. For a small blog with steady traffic, costs stay low. But for any site that could be targeted by bots, the lack of a kill switch is a <a href=\"https:\/\/overcentral.com\/en\/ai-labs-human-extinction-risk-81407\/\" title=\"AI Labs Raise Real Risk of Human Extinction\" data-iacss-internal=\"1\">real risk<\/a>. The sandbox feature (dynamic workers) requires the paid plan\u2014free tier gives you in-process plugins with no isolation.<\/p>\n\n<h2>4. How does EmDash handle WordPress migrations in practice?<\/h2><p>The migration tool imports content only: posts, pages, media, custom post types (via WXR export). It does not migrate plugins, themes, WooCommerce data, forms, SEO configurations, or any custom functionality. Those must be rebuilt from scratch. Content format conversion is a deeper issue: WordPress stores content as HTML, while EmDash uses portable text (structured JSON). That means custom blocks, advanced layouts, and complex content structures require manual re-engineering. The import tool does map Yoast SEO fields to EmDash\u2019s built-in SEO, and you can install a plugin to streamline the process. But for any site with more than basic blog posts, migration is a serious engineering project, not a one-click affair.<\/p>\n\n<h2>5. Why is EmDash considered \u201cAI native\u201d?<\/h2><p>Most CMS platforms bolt AI on as a plugin\u2014a grammar checker, a title generator. EmDash builds AI into the architecture. Every instance ships with a built-in MCP (Model Context Protocol) server, so agents like Claude, Cursor, or Copilot can connect directly and manage content, schema, plugins, and deployments. There\u2019s also a CLI and structured agent skills files that tell AI agents exactly how to operate the CMS without custom prompting. The non-obvious part: agents can generate and deploy plugins and themes programmatically. Because plugins run in isolated sandboxes (dynamic workers), an AI can create a new plugin, test it, and deploy it without ever having access to the core database or file system. That\u2019s a fundamentally different security model for agent-generated code.<\/p>\n\n<h2>6. What is the significance of dynamic workers beyond plugin security?<\/h2><p>Dynamic workers are not just for plugins. They allow any piece of untrusted code to run in a secure, isolated environment with millisecond cold starts. That\u2019s a game-changer for AI agent workflows. For example, an LLM can generate a script to analyze data, create a dynamic worker with that code, pass it the data, and get back results\u2014without the LLM ever seeing the raw data. This pattern separates computation from data access. Cloudflare\u2019s Craig Dennis demonstrated this with a chat agent that generated dashboards from sensitive data without exposing it. The same mechanism could power custom hooks, webhook handlers, or even user-submitted code. Dynamic workers turn the CMS into a secure execution platform, not just a content repository.<\/p>\n\n<h2>7. How does EmDash\u2019s theming differ from WordPress?<\/h2><p>WordPress themes rely on functions.php, which has full access to the database and all core functions. That\u2019s a security risk. EmDash themes are built with Astro components, layouts, and CSS. They are strictly frontend\u2014they cannot perform database operations. Themes get read-only access to content through a well-defined API. Developers can use modern tools like Tailwind, TypeScript, and any Astro-compatible UI library. The theme is decoupled from the backend, so a compromised theme cannot steal data or modify settings. Selling themes is also easier: no GPL constraints, so you can license themes under MIT or any proprietary license. Performance is baked in because Astro ships zero JavaScript by default.<\/p>\n\n<h2>8. What are the current limitations that make it unsuitable for production?<\/h2><p>Version 0.1.0 with about 89 commits. Zero third-party plugins or themes. No hosting partners outside Cloudflare. Known bugs: passkey authentication fails on some Linux setups, magic link fallback returns 404, multi-tab editing can lose content (no real-time conflict resolution). The admin UI has contrast issues and feels sparse. There is no visual drag-and-drop editor, no page builder, no WooCommerce equivalent. The full security model requires Cloudflare\u2019s paid Workers plan. Self-hosting on Node.js loses the sandbox entirely. As one reviewer put it: \u201cBad architecture in beta with zero ecosystem doesn\u2019t beat good enough with 60,000 plugins and 20 years of battle testing.\u201d For any business, production use is reckless.<\/p>\n\n<h2>9. How does EmDash\u2019s architecture compare to headless CMS approaches?<\/h2><p>EmDash is full-stack, like WordPress: it handles both backend and frontend in one repository. But unlike WordPress, it uses Astro for the frontend, which can be static or server-rendered. That gives you the simplicity of a monolithic deploy with the performance of a modern framework. You are not forced to go headless, but you can use the API to connect a separate frontend if needed. The difference from typical headless CMS (like Contentful or Sanity) is that EmDash owns the frontend layer, so you don\u2019t need a separate deployment for the admin and the site. The tradeoff: you are locked into Astro for theming, and the CMS\u2019s data is structured JSON (portable text), not arbitrary content models.<\/p>\n\n<h2>10. What did WordPress co-founder Matt Mullenweg actually say about EmDash?<\/h2><p>Mullenweg published a detailed review. He pushed back on the \u201cspiritual successor\u201d branding, calling it a vehicle to sell Cloudflare services. He questioned the open-source-but-vendor-locked dynamic. But he also wrote: \u201cThe product is very solid. There\u2019s some excellent engineering.\u201d He specifically praised the agent skills approach as \u201ca brilliant strategy\u201d and said WordPress needs to do the same as soon as possible. That\u2019s the non-obvious take: even the creator of WordPress acknowledged that EmDash\u2019s AI-native architecture is a genuine innovation worth copying. He didn\u2019t dismiss the project; he recognized the threat and the opportunity. The review is a signal that the CMS landscape is shifting, even if EmDash itself is far from ready.<\/p>\n<div id=\"rank-math-faq\" class=\"rank-math-block\">\n<div class=\"rank-math-list \">\n<div id=\"faq-question-1\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">How does EmDash\u2019s plugin sandbox actually work under the hood?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Each plugin runs in its own V8 isolate via dynamic workers, with a capability manifest that declares exact permissions. The runtime enforces boundaries at the hardware and kernel level, preventing any unauthorized access to database, file system, or network.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-2\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">Why did Cloudflare choose MIT over GPL?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>MIT removes the copylef compliance burden for enterprises and commercial developers, allowing closed-source plugins, flexible licensing, and AI-generated code without legal friction. EmDash was built from scratch with no WordPress code reference.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-3\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">What\u2019s the real cost of running EmDash on Cloudflare?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Serverless billing is unpredictable and hits multiple meters per request. There is no global spending cap, so a DDoS attack can generate huge bills. The sandbox plugin feature requires the $5\/month paid plan.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-4\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">How does EmDash handle WordPress migrations in practice?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Migration imports only content (posts, pages, media, custom types) via WXR. Plugins, themes, and custom functionality must be rebuilt. Content format conversion from HTML to portable text adds complexity for sites with custom blocks.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-5\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">Why is EmDash considered \u201cAI native\u201d?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>EmDash includes a built-in MCP server, CLI, and agent skills files, allowing AI agents to manage content, schema, and even generate plugins and themes. The sandbox architecture lets agents run generated code without exposing core data.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-6\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">What is the significance of dynamic workers beyond plugin security?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Dynamic workers enable secure execution of any untrusted code, such as AI-generated scripts, in isolated environments. They allow agents to process data without accessing it directly, and can power custom hooks, webhooks, and user-submitted code.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-7\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">How does EmDash\u2019s theming differ from WordPress?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>EmDash themes are built with Astro components and are strictly frontend\u2014they cannot access the database. Themes use a read-only API, support modern tools like Tailwind and TypeScript, and are free from GPL licensing constraints.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-8\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">What are the current limitations that make it unsuitable for production?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Version 0.1.0 with no plugin ecosystem, known authentication bugs, multi-tab content loss, and sandbox only on Cloudflare paid plan. Self-hosting loses the security model. Not production-ready for any business.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-9\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">How does EmDash\u2019s architecture compare to headless CMS approaches?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>EmDash is full-stack with Astro front and backend in one repo, unlike headless CMS that separate admin and frontend. It offers monolithic simplicity with modern performance, but you can use its API for a decoupled frontend if needed.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-10\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">What did WordPress co-founder Matt Mullenweg actually say about EmDash?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Mullenweg called the product solid and praised the AI agent skills as brilliant, but criticized the spiritual successor branding and vendor lock-in. He acknowledged that WordPress needs to adopt similar AI capabilities.<\/p>\n\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>1. How does EmDash\u2019s plugin sandbox actually work under the hood? The plugin sandbox isn\u2019t just a permission layer\u2014it\u2019s a full V8 isolate powered by Cloudflare\u2019s dynamic workers. Each plugin runs in its own lightweight context that spins up in about 5 milliseconds and disappears when execution ends. The plugin declares exactly what it needs [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":98766,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/97980.png","fifu_image_alt":"EmDash CMS: 10 Questions Cloudflare Engineers Answered","footnotes":""},"categories":[31],"tags":[],"class_list":["post-97980","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology"],"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/97980.png","fifu_image_alt":"EmDash CMS: 10 Questions Cloudflare Engineers Answered","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/97980","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=97980"}],"version-history":[{"count":1,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/97980\/revisions"}],"predecessor-version":[{"id":98317,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/97980\/revisions\/98317"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/98766"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=97980"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=97980"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=97980"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}