{"id":97990,"date":"2026-10-03T00:38:00","date_gmt":"2026-10-03T04:38:00","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=97990"},"modified":"2026-09-29T07:48:41","modified_gmt":"2026-09-29T11:48:41","slug":"matt-mullenweg-emdash-review-97990","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/matt-mullenweg-emdash-review-97990\/","title":{"rendered":"What Matt Mullenweg Actually Said About EmDash (And What He Missed)"},"content":{"rendered":"<p>The co-creator of WordPress reviewed his own would-be replacement. <a href=\"https:\/\/ma.tt\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Matt Mullenweg<\/a> published a detailed response to <a href=\"https:\/\/emdash.dev\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">EmDash<\/a> days after Cloudflare&#8217;s April 1 launch. He called the product &#8220;very solid&#8221; and praised its &#8220;excellent engineering.&#8221; He also said it was built to sell more <a href=\"https:\/\/www.cloudflare.com\/\" target=\"_blank\" rel=\"sponsored noopener noreferrer\" data-iacss-external=\"1\">Cloudflare<\/a> services. Both statements are true. The gap between them is where this story gets interesting.<\/p>\n<p>EmDash is a full-stack CMS built on TypeScript and Astro, running on Cloudflare&#8217;s V8 isolate infrastructure. It launched as version 0.1.0, MIT-licensed, with a plugin sandbox that physically prevents plugins from touching your database unless you explicitly allow it. Mullenweg&#8217;s review is the most credible outside analysis the project has received so far. Here&#8217;s what he actually said, what he skipped, and what both sides reveal about where CMS architecture is heading.<\/p>\n<h2>The Review That Mattered Most<\/h2>\n<p>Mullenweg published his thoughts on his personal blog days after EmDash&#8217;s April 1 announcement. He opened by acknowledging the engineering effort. The product is &#8220;very solid,&#8221; he wrote. &#8220;There&#8217;s some excellent engineering.&#8221; That alone is notable \u2014 Mullenweg has no incentive to praise a direct competitor&#8217;s architecture.<\/p>\n<p>But he immediately pushed back on the branding. EmDash calls itself &#8220;the spiritual successor to WordPress.&#8221; Mullenweg rejected that framing. He argued the project was created to drive Cloudflare service sales, not to democratize publishing. He pointed to the five Cloudflare products EmDash requires \u2014 Workers for compute, D1 for database, R2 for storage, KV for sessions, and Workers AI \u2014 each a separate billing line.<\/p>\n<p>He&#8217;s right about the architecture. Every EmDash site on Cloudflare uses at least five distinct services. You cannot replicate that stack outside Cloudflare&#8217;s runtime. The code is MIT-licensed, but the security model that differentiates EmDash from WordPress requires Cloudflare&#8217;s paid dynamic workers. The free tier runs plugins in-process with no isolation. The headline feature costs $5 a month.<\/p>\n<h2>Why the Plugin Sandbox Changes the Conversation<\/h2>\n<p>The plugin sandbox is EmDash&#8217;s single most important technical decision. WordPress plugins run in the same process as the core. A contact form plugin can call <code>wpdb<\/code>codecodecodecodecode and read every table in your database. There is no permission system, no capability manifest, no runtime enforcement. In 2025, security researchers disclosed 11,334 new WordPress vulnerabilities. 96% came from plugins. The median time from disclosure to mass exploitation was 5 hours.<\/p>\n<p>EmDash flips this. Every plugin declares its capabilities in a manifest. A plugin that requests <code>read content<\/code>codecodecodecodecode and <code>email send<\/code>codecodecodecodecode literally cannot do anything else \u2014 no file system access, no database queries, no unrestricted network calls. The runtime enforces the boundary at the V8 isolate level. Each plugin runs in its own lightweight sandbox that spins up in milliseconds and disappears when the work is done.<\/p>\n<p>Mullenweg acknowledged this is a genuine improvement. He didn&#8217;t dismiss it. But he noted that the full sandbox only works on Cloudflare&#8217;s runtime. Self-host on any Node.js server and plugins run in-process. The feature that justifies EmDash&#8217;s existence is tied to a single vendor&#8217;s infrastructure. That&#8217;s not a hypothetical limitation \u2014 it&#8217;s the architectural trade-off the team made to solve the security problem.<\/p>\n<h2>The AI-Native Architecture Mullenweg Called &#8220;Brilliant&#8221;<\/h2>\n<p>This is where Mullenweg&#8217;s review shifted from measured to enthusiastic. EmDash ships with a built-in MCP server \u2014 the Model Context Protocol that Anthropic created for <a href=\"https:\/\/overcentral.com\/en\/meta-muse-ai-agent-80441\/\" title=\"Meta Launches Muse AI Agent, Needs User Trust\" data-iacss-internal=\"1\">AI agent<\/a> communication. Every instance also includes agent skills files: structured documentation that tells AI coding tools exactly how to operate the CMS. Point Claude, Cursor, or GitHub Copilot at an EmDash site and the agent knows how to create content types, migrate themes, or import WordPress data without custom prompting.<\/p>\n<p>Mullenweg called this &#8220;amazing&#8221; and &#8220;a brilliant strategy.&#8221; He said WordPress needs to do the same &#8220;as soon as possible.&#8221; That&#8217;s the co-creator of the world&#8217;s most popular CMS telling his own community to copy a competitor&#8217;s AI integration pattern. It&#8217;s not just validation \u2014 it&#8217;s a signal that the CMS landscape is shifting faster than most people realize.<\/p>\n<p>The agent skills approach matters because it changes who can build for the platform. WordPress&#8217;s 60,000 plugins represent decades of human effort. EmDash launched with zero third-party plugins. But the MCP server and agent skills mean that AI can generate plugins and themes programmatically. The MIT license removes the GPL friction that keeps commercial developers away from WordPress. A developer can keep their plugin code closed-source or sell it on a per-use basis via the built-in 402 payment protocol. That economic model is fundamentally different from WordPress&#8217;s plugin marketplace.<\/p>\n<h2>The Vendor Lock-In Question Mullenweg Raised<\/h2>\n<p>Mullenweg&#8217;s core criticism is that EmDash was &#8220;created to sell more Cloudflare services.&#8221; He&#8217;s not wrong. The architecture locks you into Cloudflare&#8217;s runtime for the full feature set. D1 is SQLite-based and not portable to MySQL or Postgres without rewriting storage layers. R2 is S3-compatible, but the worker isolate sandbox has no equivalent anywhere else. You cannot replicate that security model on a $5 VPS.<\/p>\n<p>But let&#8217;s be honest about WordPress&#8217;s own lock-in. Free software that requires $20 to $60 a month in managed hosting plus $300 a year in premium plugins isn&#8217;t truly free. The GPL license creates legal complexity for enterprises. The ecosystem&#8217;s dependency on a single plugin repository became a liability in 2024 when Mullenweg blocked WP Engine from the plugin directory, cutting off security updates for millions of sites. That incident proved that the infrastructure serving nearly half the web has no formal governance beyond one person&#8217;s discretion.<\/p>\n<p>Different lock-in models, both worth understanding. EmDash&#8217;s lock-in is architectural \u2014 you can&#8217;t take the security model elsewhere. WordPress&#8217;s lock-in is ecosystem-based \u2014 you can move the code anywhere, but you can&#8217;t take the plugins and themes that make it useful. Neither is clearly better. They&#8217;re different shapes of the same problem.<\/p>\n<h2>What Mullenweg Didn&#8217;t Address<\/h2>\n<p>Mullenweg&#8217;s review covered the engineering and the AI strategy. He didn&#8217;t address the things that will determine whether EmDash actually gains adoption.<\/p>\n<p><strong>The ecosystem gap.<\/strong> WordPress has 62,000 plugins. WooCommerce powers 35% of all e-commerce. Elementor runs on 10 million sites. The average WordPress site uses 12 to 15 plugins. EmDash launched with zero third-party plugins. The AI-assisted generation strategy is clever, but it assumes that AI can produce production-quality plugins faster than the community can review and adopt them. History is not kind to this assumption. Ghost launched over a decade ago with better technology than WordPress and holds 0.1% market share. Craft CMS and Statamic are technically excellent and ecosystem-starved.<\/p>\n<p><strong>The migration cost.<\/strong> EmDash&#8217;s WordPress import tool handles posts, pages, and media. It <a href=\"https:\/\/overcentral.com\/en\/rascal-does-not-dream-trailer-release-80139\/\" title=\"Rascal Does Not Dream Drops Trailer for Final Film\" data-iacss-internal=\"1\">does not<\/a> migrate plugins, themes, custom functionality, WooCommerce stores, membership systems, or SEO configurations. WordPress stores content as HTML. EmDash uses portable text \u2014 structured JSON. For any site with custom blocks or complex layouts, that&#8217;s a serious engineering project, not a weekend migration.<\/p>\n<p><strong>The billing model.<\/strong> EmDash is serverless. Every page view, admin click, and API call triggers Cloudflare Worker invocations. The paid plan starts at $5 a month with 10 million requests. After that, you pay $0.30 per additional million requests plus CPU time, D1 reads, R2 operations, and KV lookups. One page view can hit four or five billing meters simultaneously. There is no spending cap. A distributed bot attack from thousands of IPs can run up a $13,000 bill overnight \u2014 and you cannot set a global request limit to stop it. Cloudflare offers CPU time limits and WAF rate limiting, but those control request duration, not request volume. Small publishers and bloggers who migrate from WordPress for security reasons are exactly the people least equipped to monitor and configure those protections.<\/p>\n<h2>A Practitioner&#8217;s Take<\/h2>\n<p>I&#8217;ve built sites on WordPress for ten years and worked with Sanity, Payload, and Statamic. Here&#8217;s where I land.<\/p>\n<p>EmDash&#8217;s plugin sandbox is the most architecturally coherent solution to the WordPress plugin security problem I&#8217;ve seen. It&#8217;s not a plugin that tries to monitor bad behavior \u2014 it&#8217;s a runtime that physically prevents it. That distinction matters. The V8 isolate model eliminates the attack surface behind 91% of WordPress breaches at the architectural level, not the policy level.<\/p>\n<p>The AI-native design is not a gimmick. The MCP server and agent skills mean that content migration, theme porting, and plugin generation can be automated in ways that WordPress&#8217;s PHP-based ecosystem cannot match without a full rewrite. Mullenweg&#8217;s admission that WordPress needs to copy this strategy is telling.<\/p>\n<p>But architecture is not adoption. EmDash is version 0.1.0. It has 89 commits on GitHub. It was built in two months with significant AI coding assistance. The authentication system has known bugs \u2014 passkey creation fails on some Linux setups, and the magic link fallback returns a 404. The content editor is functional but sparse compared to Gutenberg. The default theme is a bare-bones blog layout.<\/p>\n<p>For a greenfield content site where the team is comfortable with TypeScript and the terminal, EmDash is worth serious evaluation. For an existing WordPress business with customers, plugins, and revenue, it&#8217;s not ready. The ecosystem that makes WordPress valuable \u2014 the 60,000 plugins, the millions of developers, the hosting providers on every continent \u2014 took 24 years to build. EmDash has none of that. AI can accelerate code generation, but it cannot accelerate trust.<\/p>\n<p>The real competition is not about which CMS has better technology. It&#8217;s about which one can build a community that values security over familiarity, and whether that community can grow fast enough to matter before the next wave of tooling makes both platforms obsolete.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The co-creator of WordPress reviewed his own would-be replacement. Matt Mullenweg published a detailed response to EmDash days after Cloudflare&#8217;s April 1 launch. He called the product &#8220;very solid&#8221; and praised its &#8220;excellent engineering.&#8221; He also said it was built to sell more Cloudflare services. Both statements are true. The gap between them is where [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":98841,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/97990.png","fifu_image_alt":"What Matt Mullenweg Actually Said About EmDash (And What He Missed)","footnotes":""},"categories":[31],"tags":[],"class_list":["post-97990","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology"],"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/97990.png","fifu_image_alt":"What Matt Mullenweg Actually Said About EmDash (And What He Missed)","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/97990","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=97990"}],"version-history":[{"count":2,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/97990\/revisions"}],"predecessor-version":[{"id":98842,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/97990\/revisions\/98842"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/98841"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=97990"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=97990"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=97990"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}