{"id":97993,"date":"2026-10-03T07:50:00","date_gmt":"2026-10-03T11:50:00","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=97993"},"modified":"2026-09-29T07:49:11","modified_gmt":"2026-09-29T11:49:11","slug":"emdash-capability-manifest-limitations-97993","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/emdash-capability-manifest-limitations-97993\/","title":{"rendered":"EmDash\u2019s Capability Manifest System: Why It\u2019s Not a Silver Bullet"},"content":{"rendered":"<p>Everyone says the same thing. Plugin sandboxing fixes WordPress security. Capability manifests let you declare exactly what a plugin can do\u2014read content, send email, nothing else. <em>That\u2019s the fix.<\/em> Cloudflare\u2019s EmDash builds this into its core: every plugin runs in an isolated V8 worker, and it can only touch what you explicitly allow.<\/p>\n<p>It sounds airtight.<\/p>\n<p>It isn\u2019t.<\/p>\n<p>The capability manifest system is a genuine architectural improvement over WordPress\u2019s all-or-nothing plugin model. But the common advice\u2014that manifests alone prevent plugin abuse\u2014misses where the system bends, breaks, or simply shifts the risk to a different place. Understanding those gaps is what separates a realistic evaluation from marketing copy.<\/p>\n<h2>What the Manifest Actually Controls<\/h2>\n<p>EmDash requires every plugin to declare its capabilities in a structured manifest. A plugin that sends email upon post publication declares <code>read:content<\/code>codecode and <code>email:send<\/code>codecode. That\u2019s it. The runtime\u2014a dynamic worker running on Cloudflare\u2019s V8 isolates\u2014enforces those boundaries at the hardware level. No database queries beyond what\u2019s declared. No file system access. No unrestricted network calls.<\/p>\n<p>The source material confirms this: <em>\u201cA plugin that declares read content and send email can literally do nothing else.\u201d<\/em> That\u2019s a powerful statement. It means a compromised plugin cannot exfiltrate password hashes, modify other plugins\u2019 data, or mine cryptocurrency on your server.<\/p>\n<p>So what\u2019s the catch?<\/p>\n<h2>The Manifest Trust Problem<\/h2>\n<p>The system assumes the plugin developer declares capabilities honestly. That assumption is fragile.<\/p>\n<p>A plugin that needs to read content and send email is trivial to audit. But consider a backup plugin. It needs to read <em>everything<\/em>\u2014posts, media, users, settings\u2014write files to remote storage, and make network calls to an S3-compatible endpoint. Its manifest would declare something like <code>read:all<\/code>codecode, <code>write:all<\/code>codecode, <code>network:outbound<\/code>codecode. That\u2019s essentially the same level of access a WordPress plugin has by default. The sandbox still isolates the plugin from the core, but the granted permissions are broad enough to cause catastrophic damage if the plugin is malicious or compromised.<\/p>\n<p>The capability manifest doesn\u2019t prevent abuse of the capabilities it grants. It only prevents <em>unauthorized<\/em> access. A backup plugin with a backdoor can still read every user email and send them to an attacker\u2019s server\u2014because \u201csend email\u201d or \u201cnetwork outbound\u201d is in its manifest.<\/p>\n<p><em>That\u2019s not a flaw in the architecture.<\/em> It\u2019s a limitation of any permission system. But the common framing\u2014\u201cplugins can only do what they declare\u201d\u2014implies a level of safety that evaporates once a plugin needs anything beyond trivial access.<\/p>\n<h2>The Self-Hosted Blind Spot<\/h2>\n<p>Here\u2019s the detail most commentators skip. The full sandbox requires Cloudflare\u2019s dynamic workers, which are only available on the Workers Paid plan ($5+\/month). Self-host EmDash on a regular Node.js server, and plugins run <em>in-process<\/em>\u2014no isolation, no capability enforcement. The same code, the same security model, but with zero sandboxing.<\/p>\n<p>The source material is explicit: <em>\u201cThe full sandbox only works on Cloudflare\u2019s runtime. Self-host M- on a regular Node.js server and plugins run in process without isolation.\u201d<\/em><\/p>\n<p>So the advice \u201cEmDash fixes plugin security\u201d is only true if you pay Cloudflare. If you self-host, you\u2019re running a CMS with no plugin ecosystem, no security advantage over WordPress, and a brand new attack surface. That\u2019s not a minor caveat\u2014it\u2019s a fundamental dependency.<\/p>\n<p>Worse, even on Cloudflare\u2019s free tier, plugins run in \u201cin-process mode\u201d without sandboxing. The headline feature requires a monthly subscription.<\/p>\n<h2>The Billing Risk Nobody Mentions<\/h2>\n<p>Capability manifests don\u2019t control cost. Every plugin invocation is a Cloudflare Workers request. Every request hits multiple billing meters: Workers compute, D1 database reads, R2 storage operations, KV lookups. A DDoS attack or a runaway plugin can generate thousands of billable requests <a href=\"https:\/\/overcentral.com\/en\/meta-launches-zgateway-proxy-handles-1-billion-ops-per-second\/\" title=\"Meta Launches ZGateway Proxy, Handles 1 Billion Ops Per Second\" data-iacss-internal=\"1\">per second<\/a>.<\/p>\n<p>The source material from a critic points out: <em>\u201cIf you use Cloudflare\u2019s new CMS called M-Dash, you can wake up one morning to a bill of $13,000\u2026 there is nothing built into the platform to stop it.\u201d<\/em><\/p>\n<p>The capability manifest can limit what a plugin does, but it cannot limit how often a plugin fires. A plugin that sends email on every post publish could be abused by an attacker who publishes thousands of posts programmatically. The manifest says \u201cemail:send\u201d is allowed\u2014it doesn\u2019t say \u201cemail:send up to 100 times <a href=\"https:\/\/overcentral.com\/en\/muse-voice-transcribe-pricing-80418\/\" title=\"Meta Prices Muse Voice Transcribe at $0.18 Per Hour\" data-iacss-internal=\"1\">per hour<\/a>.\u201d<\/p>\n<p>Cloudflare offers CPU time limits per request and WAF rate limiting, but those are per-IP, not per-plugin. A distributed bot attack bypasses them. The advice to \u201cjust use manifests\u201d ignores this operational risk entirely.<\/p>\n<h2>The Ecosystem Catch-22<\/h2>\n<p>WordPress has 60,000+ plugins. EmDash launched with zero. The capability manifest system is elegant, but it only matters if plugins exist to install. Building a plugin ecosystem from scratch takes years\u2014even with AI-assisted porting.<\/p>\n<p>The source material from a supporter acknowledges: <em>\u201cIt\u2019s a v0.1.0 beta with 38 GitHub stars, three contributors, and zero production deployments.\u201d<\/em><\/p>\n<p>The common advice to \u201cswitch to EmDash for security\u201d assumes the plugin you need will be available. Right now, any non-trivial site (e-commerce, membership, forms, SEO) requires custom development. That development carries its own security risks\u2014bugs in custom code, incomplete manifests, misconfigured permissions. The manifest system doesn\u2019t prevent those; it only enforces what the developer declares.<\/p>\n<h2>When the System Works\u2014and When It Doesn\u2019t<\/h2>\n<p>EmDash\u2019s capability manifest is genuinely superior for plugins with narrow, well-defined scopes. A contact form plugin that only reads content and sends email? The sandbox contains it perfectly. An SEO plugin that needs to read all content and write metadata? Still manageable\u2014the manifest is auditable, and the runtime enforces the boundary.<\/p>\n<p>But for plugins that require broad, multi-system access\u2014backup, migration, caching, analytics\u2014the manifest grants permissions so wide that the sandbox offers little practical protection. The attack surface shifts from \u201cplugin can do anything\u201d to \u201cplugin can do many things, and we trust its manifest.\u201d<\/p>\n<p>The advice everyone gives\u2014\u201cuse capability manifests to prevent plugin abuse\u201d\u2014is incomplete. It works for simple plugins. It fails for complex ones. It requires Cloudflare\u2019s paid infrastructure. It ignores billing risk. And it assumes an ecosystem that doesn\u2019t exist yet.<\/p>\n<p>That\u2019s not an argument against EmDash. It\u2019s an argument for understanding the tool\u2019s actual boundaries before betting a business on it.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Everyone says the same thing. Plugin sandboxing fixes WordPress security. Capability manifests let you declare exactly what a plugin can do\u2014read content, send email, nothing else. That\u2019s the fix. Cloudflare\u2019s EmDash builds this into its core: every plugin runs in an isolated V8 worker, and it can only touch what you explicitly allow. It sounds [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":98874,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/97993.png","fifu_image_alt":"EmDash\u2019s Capability Manifest System: Why It\u2019s Not a Silver Bullet","footnotes":""},"categories":[31],"tags":[],"class_list":["post-97993","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology"],"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/97993.png","fifu_image_alt":"EmDash\u2019s Capability Manifest System: Why It\u2019s Not a Silver Bullet","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/97993","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=97993"}],"version-history":[{"count":1,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/97993\/revisions"}],"predecessor-version":[{"id":98340,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/97993\/revisions\/98340"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/98874"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=97993"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=97993"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=97993"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}