{"id":98000,"date":"2026-10-04T00:38:00","date_gmt":"2026-10-04T04:38:00","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=98000"},"modified":"2026-09-29T07:51:27","modified_gmt":"2026-09-29T11:51:27","slug":"emdash-cms-wordpress-alternative-98000","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/emdash-cms-wordpress-alternative-98000\/","title":{"rendered":"Stop Using WordPress for New Projects? The Case for Starting With EmDash"},"content":{"rendered":"<p>You already know the numbers. 96% of WordPress security vulnerabilities come from plugins. In 2025 alone, researchers found over 11,000 new vulnerabilities, nearly half exploitable without authentication. WordPress powers 43% of the web, but its plugin architecture is a structural flaw, not a bug.<\/p>\n<p><a href=\"https:\/\/www.cloudflare.com\/emDash\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">EmDash<\/a>, Cloudflare&#8217;s new CMS, doesn&#8217;t patch that flaw. It eliminates it. Every plugin runs in its own V8 isolate via dynamic workers, with a capability manifest that grants only what you declare. No database access unless you say so. No file system access. No network calls without permission. This isn&#8217;t a security plugin bolted on. It&#8217;s the architecture.<\/p>\n<p>The question isn&#8217;t whether EmDash can replace WordPress today. It can&#8217;t. The ecosystem is zero. The question is whether starting a new project on EmDash is smarter than starting on WordPress. For a growing number of use cases, the answer is yes.<\/p>\n<h2>The Plugin Paradox \u2013 Why WordPress&#8217;s Greatest Strength Is Its Greatest Liability<\/h2>\n<p>WordPress&#8217;s plugin ecosystem is its moat. Over 60,000 plugins, from WooCommerce to Yoast SEO, form an economy that no competitor can match. But that moat is also a trap. Every plugin runs in the same process as the core, with full access to the database, file system, and user sessions. One compromised contact form plugin and an attacker reads your entire user table.<\/p>\n<p>This is not a failure of individual plugin authors. It is how WordPress was designed. The architecture trusts code by default. There is no sandbox, no permission system, no isolation. The median time from vulnerability disclosure to mass exploitation is five hours. Half of high-impact exploits happen within the first 24 hours.<\/p>\n<p>Cloudflare&#8217;s lead engineer Matt Cain recognized this. He built EmDash with dynamic workers, a product Cloudflare originally created for securely executing AI-generated code. The same mechanism isolates plugins. A plugin that declares <code>read content<\/code>codecodecodecode and <code>send email<\/code>codecodecodecode can literally do nothing else. No database queries, no crypto mining, no exfiltration of password hashes. The runtime enforces the boundary at the hardware level using V8 isolates, Linux namespaces, seccomp filters, and memory protection keys.<\/p>\n<p>This is the &#8220;Sandbox-First&#8221; model. It inverts the trust assumption. Code is guilty until proven innocent, and innocence is declared upfront.<\/p>\n<h2>The Ecosystem Gap \u2013 Why Zero Plugins Is Actually an Advantage for New Projects<\/h2>\n<p>The most common objection to EmDash is the missing ecosystem. WordPress has 60,000 plugins; EmDash has zero. That sounds fatal.<\/p>\n<p>But consider what you actually need for a new project. A blog, a marketing site, a portfolio, a small e-commerce store. The features you need are standard: SEO metadata, contact forms, caching, analytics, user management. EmDash ships with SEO built-in, a form builder, automated moderation, and role-based access control. You don&#8217;t need a plugin for these things. They are core.<\/p>\n<p>The problem with WordPress is not the number of plugins. It&#8217;s that you end up installing 12 to 15 plugins for a simple site, each one a potential attack surface. Each plugin also introduces update friction, compatibility risk, and license management overhead. The &#8220;plugin tax&#8221; is real \u2013 not just in cost, but in maintenance burden.<\/p>\n<p>EmDash&#8217;s zero-plugin state is not a weakness. It is a clean slate. You only add a plugin when you genuinely need a capability that does not exist in core. And when you do, that plugin runs in a sandbox. It cannot break your site, cannot read your database, cannot phone home. The security model means you can install plugins without the anxiety that comes with WordPress.<\/p>\n<p>For a new project, starting with a secure, minimal core and adding only what you need is architecturally superior to starting with a sprawling, insecure core and pruning later.<\/p>\n<h2>The Cost Trap \u2013 Predictable vs. Unpredictable Billing<\/h2>\n<p>Critics point out that EmDash&#8217;s serverless billing model can be unpredictable. A DDoS attack or bot crawl could rack up charges with no built-in spending cap. One forum post estimated $13,000 for 10,000 APIs making one request <a href=\"https:\/\/overcentral.com\/en\/meta-launches-zgateway-proxy-handles-1-billion-ops-per-second\/\" title=\"Meta Launches ZGateway Proxy, Handles 1 Billion Ops Per Second\" data-iacss-internal=\"1\">per second<\/a> each.<\/p>\n<p>That scenario is real. But it is also manageable. Cloudflare offers rate limiting via WAF rules, CPU time limits per request, and alerts. The risk is that small business owners won&#8217;t configure these protections. Fair criticism.<\/p>\n<p>Compare to WordPress. Managed hosting costs $20 to $60 per month, plus $300 per year in premium plugins. That&#8217;s predictable. But it&#8217;s also a flat fee that doesn&#8217;t scale down. You pay for capacity you don&#8217;t use. EmDash&#8217;s paid plan starts at $5 per month and includes 10 million requests. For a small blog, that&#8217;s effectively free. For a site with 100,000 visits per day, the cost is still under $10 per month. The risk of runaway billing exists, but it is a risk you can mitigate with proper configuration. WordPress&#8217;s cost is guaranteed, but it&#8217;s also higher for what you get.<\/p>\n<p>The real cost trap is the hidden one: the time spent managing plugin updates, security patches, and compatibility issues. WordPress developers spend hours every month on maintenance. EmDash&#8217;s architecture reduces that dramatically. Plugins are isolated, so a plugin update cannot break the site. Core updates are handled by the runtime. The time saved is real.<\/p>\n<h2>The AI-Native Advantage \u2013 Why EmDash&#8217;s MCP Server Changes the Game<\/h2>\n<p>WordPress is retrofitting AI. EmDash was built for it. Every instance ships with a built-in MCP server and agent skills files. You can point Claude, Cursor, or any MCP-compatible agent at your CMS and say, &#8220;Build me a new custom content type&#8221; or &#8220;Migrate this old theme.&#8221; The agent reads the skills files, knows the API, and executes.<\/p>\n<p>This is not a gimmick. It is a fundamental shift in how content management works. The traditional workflow is: install a plugin, configure it, write content. The new workflow is: describe what you want, the agent builds it, you review and publish.<\/p>\n<p>The co-creator of WordPress, Matt Mullenweg, reviewed EmDash and called its agent skills approach &#8220;amazing&#8221; and said WordPress needs to copy it as soon as possible. That&#8217;s validation from the source.<\/p>\n<p>For a new project, starting with an AI-native CMS means you can skip months of plugin research and configuration. You can generate custom post types, fields, and templates on demand. The MIT license removes the GPL friction that kept commercial developers away from WordPress. You can keep your code proprietary, sell plugins with any license, and monetize per-use via the built-in 402 payment protocol.<\/p>\n<h2>The Vendor Lock-In Trade-Off \u2013 Open Source, But Architecturally Tied<\/h2>\n<p>EmDash is MIT licensed. The code is on GitHub. You can run it on any Node.js server. But the headline feature \u2013 plugin sandboxing \u2013 requires Cloudflare&#8217;s paid infrastructure. Dynamic workers are a Cloudflare product. Without them, plugins run in-process with no isolation. Self-hosted EmDash loses its primary advantage.<\/p>\n<p>This is the &#8220;Open Source, But Architecturally Locked In&#8221; problem. WordPress runs on any server with PHP and MySQL. You can switch hosts in an afternoon. EmDash&#8217;s data is portable \u2013 D1 is SQLite, R2 is S3 compatible \u2013 but the security model is not.<\/p>\n<p>That said, WordPress has its own lock-in. Managed hosting costs $20 to $60 per month, plus premium plugins that you cannot easily move. The difference is that WordPress&#8217;s lock-in is economic; EmDash&#8217;s is architectural. For a new project, architectural lock-in is acceptable if the architecture is better. You are not migrating a production site. You are building from scratch.<\/p>\n<h2>The Framework \u2013 &#8220;Ecosystem Debt&#8221; vs. &#8220;Architecture Equity&#8221;<\/h2>\n<p>Here is the mental model: Every CMS <a href=\"https:\/\/overcentral.com\/en\/ichra-choice-arrangements-label-97925\/\" title=\"ICHRA Gets CHOICE Arrangements Label from CMS, SBA\" data-iacss-internal=\"1\">choice<\/a> involves a trade-off between ecosystem debt and architecture equity.<\/p>\n<p>WordPress has enormous ecosystem debt. You inherit 60,000 plugins, but you also inherit their vulnerabilities, their update cycles, their compatibility issues, and their licensing constraints. That debt compounds over time. The more plugins you install, the more debt you accrue.<\/p>\n<p>EmDash has low ecosystem debt. You start with zero plugins, but you also start with zero vulnerabilities, zero update friction, and zero license headaches. You build architecture equity: a sandboxed runtime, a modern frontend stack (Astro, TypeScript), and an AI-native API. That equity compounds as you add features that are designed into the core, not bolted on.<\/p>\n<p>For a new project, you want to minimize ecosystem debt and maximize architecture equity. EmDash wins on both dimensions. WordPress wins only if you need a plugin that does not exist in EmDash&#8217;s core and cannot be built quickly with AI.<\/p>\n<h2>The Honest Take \u2013 Who Should Start on EmDash Today<\/h2>\n<ul>\n<li><strong>Greenfield content sites<\/strong> \u2013 blogs, marketing sites, portfolios. EmDash&#8217;s built-in features cover everything you need. The security model is superior. The cost is lower. The AI integration is ready.<\/li>\n<li><strong>TypeScript\/JavaScript-first teams<\/strong> \u2013 if your team already uses Astro, Tailwind, or Node.js, EmDash is a natural fit. No PHP to learn, no legacy stack.<\/li>\n<li><strong>Security-conscious projects<\/strong> \u2013 if the site handles sensitive data (memberships, payments, user-generated content), EmDash&#8217;s sandboxed plugin model is a genuine advantage.<\/li>\n<li><strong>AI-heavy workflows<\/strong> \u2013 if you plan to use agents for content generation, migration, or site management, EmDash&#8217;s MCP server and skills files make that easy.<\/li>\n<\/ul>\n<p>Who should stick with WordPress:<\/p>\n<ul>\n<li><strong>Sites that depend on specific plugins<\/strong> \u2013 WooCommerce stores with custom shipping logic, membership sites with complex access rules, sites using niche plugins that have no EmDash equivalent.<\/li>\n<li><strong>Teams that need ecosystem hiring<\/strong> \u2013 if <a href=\"https:\/\/overcentral.com\/en\/wardogs-recon-myth-busted-81574\/\" title=\"The WARDOGS Recon Myth You Need to Stop Believing\" data-iacss-internal=\"1\">you need to<\/a> hire WordPress developers, they are abundant. EmDash developers are rare today.<\/li>\n<li><strong>Sites that cannot afford any vendor risk<\/strong> \u2013 if you need absolute portability and zero dependence on a single provider, WordPress on a VPS is still the gold standard.<\/li>\n<\/ul>\n<h2>The Edge Case \u2013 When the Architecture Fails<\/h2>\n<p>EmDash&#8217;s sandbox model is not a silver bullet. Dynamic workers are fast, but they are not free. Every plugin invocation incurs a cold start cost, though it&#8217;s measured in milliseconds. For high-traffic sites with dozens of plugin hooks, that latency adds up.<\/p>\n<p>More critically, some plugins need deep integration. A caching plugin, for example, needs to intercept requests and modify responses. A sandboxed plugin cannot do that. It can only hook into events. For plugins that need to modify the core request lifecycle, EmDash&#8217;s model is insufficient. Those plugins must be installed as trusted NPM modules, which run outside the sandbox.<\/p>\n<p>This means the sandbox solves the &#8220;bad plugin&#8221; problem but not the &#8220;necessary but powerful plugin&#8221; problem. The architecture is not a complete security solution. It is a significant improvement, but it still requires trust for plugins that need elevated permissions.<\/p>\n<p>EmDash is version 0.1.0. It will evolve. But today, that edge case is real. If your project requires plugins that need deep system access, WordPress remains the safer bet.<\/p>\n<h2>Closing<\/h2>\n<p>The &#8220;Sandbox-First&#8221; model EmDash introduces will become the standard for new CMS projects. WordPress&#8217;s plugin architecture is a relic of a time when security was an afterthought. The ecosystem is powerful, but it is also a trap. Starting a new project on EmDash means building on a foundation that is secure, modern, and AI-ready. The ecosystem will come. The architecture is already here.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>You already know the numbers. 96% of WordPress security vulnerabilities come from plugins. In 2025 alone, researchers found over 11,000 new vulnerabilities, nearly half exploitable without authentication. WordPress powers 43% of the web, but its plugin architecture is a structural flaw, not a bug. EmDash, Cloudflare&#8217;s new CMS, doesn&#8217;t patch that flaw. It eliminates it. [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":99077,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/98000.png","fifu_image_alt":"Stop Using WordPress for New Projects? The Case for Starting With EmDash","footnotes":""},"categories":[31],"tags":[],"class_list":["post-98000","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology"],"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/98000.png","fifu_image_alt":"Stop Using WordPress for New Projects? The Case for Starting With EmDash","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/98000","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=98000"}],"version-history":[{"count":2,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/98000\/revisions"}],"predecessor-version":[{"id":99078,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/98000\/revisions\/99078"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/99077"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=98000"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=98000"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=98000"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}