{"id":98076,"date":"2026-10-11T15:02:00","date_gmt":"2026-10-11T19:02:00","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=98076"},"modified":"2026-09-29T08:14:36","modified_gmt":"2026-09-29T12:14:36","slug":"emdash-cloudflare-workers-d1-r2-98076","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/emdash-cloudflare-workers-d1-r2-98076\/","title":{"rendered":"EmDash\u2019s Place in the Cloudflare Ecosystem: Workers, D1, R2, and More"},"content":{"rendered":"<p>EmDash isn\u2019t just another CMS. It\u2019s a deliberate assembly of Cloudflare\u2019s infrastructure products, each chosen to solve a specific problem that WordPress architecture can\u2019t touch. The CMS runs on Workers for compute, D1 for the database, R2 for media storage, and KV for session state. Every one of those products has a billing meter, a performance profile, and a lock-in trade-off. Understanding how they fit together \u2014 and where they break \u2014 is the only way to decide if EmDash is worth your time.<\/p>\n<h2>The Serverless Foundation: Workers and V8 Isolates<\/h2>\n<p>WordPress runs on a persistent PHP process. EmDash runs on <a href=\"https:\/\/workers.cloudflare.com\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Cloudflare Workers<\/a> \u2014 stateless JavaScript functions that execute at the edge, across 330+ data centers. The difference isn\u2019t just speed; it\u2019s the billing model.<\/p>\n<h3>How Workers Power Every Request<\/h3>\n<p>Every page view, admin panel click, and API call on an EmDash site translates to a Worker invocation. The paid Workers plan starts at $5 per month and includes 10 million requests. After that, you pay $0.30 per additional million requests, plus CPU time charges.<\/p>\n<p>Consider a typical blog with 50,000 monthly visits. Each visit triggers one Worker request for the HTML page, plus additional requests for images, CSS, and JavaScript \u2014 roughly 3\u20135 requests per page view depending on caching. That\u2019s 150,000 to 250,000 Worker requests per month, well within the free tier\u2019s 100,000 requests per day limit. But if a post goes viral and hits 500,000 visits in a day, you\u2019re suddenly looking at 1.5 million requests \u2014 still inside the paid plan\u2019s 10 million monthly allowance, but edging closer to the overage threshold.<\/p>\n<h3>The Cold Start Problem \u2014 Solved by V8 Isolates<\/h3>\n<p>Workers spin up in milliseconds, not seconds. Cloudflare\u2019s V8 isolates are the engine behind that speed. A Docker container takes 3\u20135 seconds to cold start. A V8 isolate starts in under 5 milliseconds, uses roughly 10 times less memory, and scales down to zero when idle.<\/p>\n<p>For EmDash, this means a plugin that only runs on the \u201cpost_published\u201d hook doesn\u2019t waste resources sitting idle. The isolate spawns, executes the plugin\u2019s code, and terminates \u2014 all within a few hundred milliseconds. In WordPress, that same plugin lives in the same process as every other plugin, consuming memory and CPU even when it\u2019s not doing anything.<\/p>\n<h3>The Catch: Sandboxed Plugins Require Paid Workers<\/h3>\n<p>The headline security feature \u2014 sandboxed plugins \u2014 only works with Cloudflare\u2019s Dynamic Workers, which require the Workers Paid plan ($5\/month). On the free Workers tier, plugins run \u201cin process\u201d with no isolation. Self-host EmDash on a Node.js server and sandboxing isn\u2019t available at all.<\/p>\n<p>This isn\u2019t a bug. It\u2019s a deliberate architectural dependency. The sandbox is enforced by V8 isolates and Linux namespaces, not by EmDash\u2019s code. Without Cloudflare\u2019s runtime, the security advantage evaporates.<\/p>\n<h2>D1: The Database That Scales to Zero<\/h2>\n<p>EmDash uses D1, Cloudflare\u2019s serverless SQLite database, as its default storage engine. D1 is built on SQLite, but with a global replication layer that lets you run queries at the edge.<\/p>\n<h3>What D1 Means for Content Management<\/h3>\n<p>WordPress stores content in MySQL or MariaDB tables. That database runs on a persistent server, consuming resources even when no one is visiting your site. D1, by contrast, is serverless. You pay only for the storage and reads you actually use.<\/p>\n<p>A typical blog with 1,000 posts and 10,000 monthly visits might store 5 MB of content data. D1\u2019s free tier includes 5 GB of storage and 1 million monthly read rows. That\u2019s more than enough for most small sites. The paid plan starts at $0.85 per month for 1 GB of storage and 10 million read rows.<\/p>\n<h3>The Migration Pain Point<\/h3>\n<p>WordPress stores content as HTML in MySQL tables. EmDash stores content as portable text \u2014 a structured JSON format. When you migrate a WordPress site to EmDash, you\u2019re not doing a simple database dump. The migration tool converts HTML to portable text, but it only handles posts, pages, media, and custom fields. It does not migrate plugins, themes, WooCommerce products, or user roles.<\/p>\n<p>For a site with 500 posts and 30 custom blocks, the migration took roughly 15 minutes in tests. But a site with 2,000 products and 50 WooCommerce extensions would require weeks of manual conversion.<\/p>\n<h3>The Vendor Lock-in Reality<\/h3>\n<p>D1 is not portable. You cannot export a D1 database and import it into PostgreSQL or MySQL. The closest you get is a SQLite dump, but that loses the global replication and edge query routing. If you ever want to leave Cloudflare, you\u2019re rebuilding your data layer from scratch.<\/p>\n<p>Compare that to WordPress. You can export a MySQL dump, import it into any MySQL-compatible host, and your site keeps running. Same code, same database, same functionality. EmDash\u2019s data is technically portable (SQLite is an open format), but the runtime that makes it perform is not.<\/p>\n<h2>R2: Object Storage With Zero Egress Fees<\/h2>\n<p>Media files \u2014 images, videos, PDFs \u2014 are the biggest cost driver for any CMS. WordPress stores them on the local filesystem or an S3-compatible bucket, but egress fees from AWS or Google Cloud can eat into your budget fast.<\/p>\n<h3>How R2 Changes the Economics<\/h3>\n<p>R2 is Cloudflare\u2019s object storage, designed to be S3-compatible but with no egress fees. That means you can serve a 2 MB image to 1 million visitors without paying a cent in bandwidth charges.<\/p>\n<p>A typical portfolio site with 500 images (average size 500 KB) would use about 250 MB of storage. R2\u2019s free tier includes 10 GB of storage and 10 million monthly read operations. After that, storage costs $0.015 per GB per month, and operations are $0.01 per million reads.<\/p>\n<h3>The Hidden Cost: Operations per Request<\/h3>\n<p>Every page view on EmDash can trigger multiple R2 operations \u2014 one for the featured image, one for inline images, one for the CSS file. If a page has 10 images, that\u2019s 10 read operations per visitor. At 50,000 monthly visitors, you\u2019re looking at 500,000 reads per month. Still within the free tier, but add a video file and the numbers climb fast.<\/p>\n<h3>The Egress Advantage Over WordPress<\/h3>\n<p>A managed WordPress host like WP Engine charges for bandwidth above a certain threshold. WP Engine\u2019s Starter plan includes 50 GB of bandwidth. A site with 100,000 monthly visitors and 2 MB per page view would exceed that limit and incur overage charges. R2\u2019s zero-egress model eliminates that entirely.<\/p>\n<h2>KV: Session State Without a Database Hit<\/h2>\n<p>EmDash uses Cloudflare KV (key-value store) for session management and transient data. KV is designed for high-read, low-write workloads \u2014 perfect for caching user sessions, rate limits, and plugin state.<\/p>\n<h3>How KV Avoids Database Bottlenecks<\/h3>\n<p>In WordPress, session data is stored in the <code>wp_options<\/code>codecodecodecode table or in the database directly. Every page load queries the database to check if the user is logged in. With KV, that lookup happens at the edge \u2014 sub-millisecond latency, no database hit.<\/p>\n<p>EmDash\u2019s passkey authentication uses KV to store the public key for each user. When a user logs in, the Workers runtime checks KV for the key, verifies the signature, and grants access. No database query, no password hash to leak.<\/p>\n<h3>The Consistency Trade-Off<\/h3>\n<p>KV is eventually consistent. A write to KV can take up to 60 seconds to propagate globally. That\u2019s fine for session data \u2014 a user won\u2019t notice a 10-second delay in their login session being available everywhere. But it\u2019s not suitable for transactional data like payment confirmations or inventory counts.<\/p>\n<h2>The Five-Product Dependency<\/h2>\n<p>Every EmDash site on Cloudflare uses at least five separate products: Workers, D1, R2, KV, and Workers AI (for automated moderation and SEO suggestions). Each product has its own billing meter, rate limits, and performance characteristics.<\/p>\n<h3>The $13,000 Bill Scenario<\/h3>\n<p>A Reddit user calculated that a sustained DDoS attack of 10,000 requests <a href=\"https:\/\/overcentral.com\/en\/meta-launches-zgateway-proxy-handles-1-billion-ops-per-second\/\" title=\"Meta Launches ZGateway Proxy, Handles 1 Billion Ops Per Second\" data-iacss-internal=\"1\">per second<\/a> could generate 26 billion billable requests in a month \u2014 far beyond the paid plan\u2019s 10 million allowance. At $0.30 per million requests, that\u2019s $7,800 in Workers charges alone. Add D1 read rows, R2 operations, and KV lookups, and the total exceeds $13,000.<\/p>\n<p>Cloudflare does not offer a global spending cap. You can set CPU time limits per request and configure rate limiting, but a distributed bot attack from thousands of different IPs bypasses those protections. The site stays online, the Workers keep firing, and your credit card keeps getting charged.<\/p>\n<h3>Contrast With WordPress Flat Pricing<\/h3>\n<p>A managed WordPress host charges a flat $20-$50 per month regardless of traffic spikes. The server might crash under load, but the bill doesn\u2019t change. EmDash inverts that: the site scales perfectly, but the bill is unpredictable.<\/p>\n<h2>AI-Native Architecture: MCP Server and Agent Skills<\/h2>\n<p>EmDash ships with a built-in MCP server (Model Context Protocol) that lets <a href=\"https:\/\/overcentral.com\/en\/rogue-ai-agents-liability-vacuum-97898\/\" title=\"Rogue AI agents expose liability vacuum as OpenAI faces claims\" data-iacss-internal=\"1\">AI agents<\/a> interact with the CMS programmatically. This is not an afterthought \u2014 it\u2019s the architectural foundation.<\/p>\n<h3>What the MCP Server Does<\/h3>\n<p>An MCP-compatible agent (Claude, Cursor, GitHub Copilot) can connect to your EmDash instance and perform tasks like:<\/p>\n<ul>\n<li>Search all posts for a specific phrase and replace it<\/li>\n<li>Create a new custom content type with 10 fields<\/li>\n<li>Generate a new theme from a WordPress export<\/li>\n<li>Migrate a WooCommerce product list from a CSV file<\/li>\n<\/ul>\n<p>The agent reads the skills files \u2014 structured documentation that tells the AI exactly what it can do \u2014 and executes tasks using the CLI or API. No custom prompting required.<\/p>\n<h3>The Yoast de Valk Validation<\/h3>\n<p>Joost de Valk, founder of Yoast SEO (used on 10 million WordPress sites), called EmDash\u2019s AI integration \u201cthe most interesting thing to happen to content management in years.\u201d He specifically praised the MCP server and agent skills as a \u201cbrilliant strategy\u201d that WordPress needs to copy as soon as possible.<\/p>\n<h2>The Plugin Sandbox: Architectural Security, Not Policy<\/h2>\n<p>The defining feature of EmDash is the plugin sandbox. Every plugin runs in its own V8 isolate, with a capability manifest that declares exactly what it can access.<\/p>\n<h3>How It Works in Practice<\/h3>\n<p>A plugin that sends email notifications when a post is published declares two capabilities: <code>read:content<\/code>codecodecodecode and <code>email:send<\/code>codecodecodecode. It cannot access the database, the file system, or make network calls. The runtime enforces this at the hardware level using Linux namespaces and seccomp filters.<\/p>\n<p>Compare that to WordPress. A contact form plugin has the same database access as your payment processor. One compromised plugin \u2014 and 4.7 million WordPress sites get hacked every year, with 91% of vulnerabilities coming from plugins \u2014 can read your entire user database.<\/p>\n<h3>The Dynamic Worker Execution<\/h3>\n<p>When a plugin hook fires, EmDash creates a dynamic worker with the plugin\u2019s code and the declared capabilities. The worker starts in under 5 milliseconds, executes the code, and terminates. No persistent process, no shared memory, no way for a bug in one plugin to affect another.<\/p>\n<h2>The Open Source License: MIT, Not GPL<\/h2>\n<p>EmDash is MIT-licensed, not GPL. That\u2019s a deliberate <a href=\"https:\/\/overcentral.com\/en\/ichra-choice-arrangements-label-97925\/\" title=\"ICHRA Gets CHOICE Arrangements Label from CMS, SBA\" data-iacss-internal=\"1\">choice<\/a> with real consequences.<\/p>\n<h3>What MIT Means for Developers<\/h3>\n<p>MIT license allows anyone to use, modify, and distribute the code without requiring derivative works to use the same license. That means a developer can build a commercial plugin, keep it closed-source, and sell it without worrying about GPL\u2019s \u201cviral\u201d clause.<\/p>\n<p>In WordPress, every plugin and theme must be GPL-licensed because of how deeply they integrate with the core. That restriction has driven many commercial developers away. EmDash\u2019s MIT license removes that friction.<\/p>\n<h3>The Vendor Lock-In Trade-Off<\/h3>\n<p>The code is MIT, but the runtime that powers every meaningful feature \u2014 the V8 isolate sandbox, the dynamic workers, the D1 database \u2014 is proprietary Cloudflare infrastructure. You can fork the code and run it on any Node.js server, but you lose the sandbox, the edge performance, and the zero-egress storage.<\/p>\n<p>One Hacker News commenter summed it up: \u201cOpen source, but architecturally locked in.\u201d<\/p>\n<h2>Who Should Use EmDash Today<\/h2>\n<p>EmDash is version 0.1.0. It has 38 GitHub stars, three core contributors, and zero production deployments outside Cloudflare\u2019s internal use.<\/p>\n<h3>The Greenfield TypeScript Developer<\/h3>\n<p>If you\u2019re starting a new content site from scratch, comfortable with TypeScript and the terminal, and security is your top priority, EmDash is worth a serious look. The sandbox model is genuinely superior to anything WordPress offers. The serverless pricing can be cheaper than managed WordPress hosting \u2014 $5 per month for the paid plan vs. $20-$50 for a managed host.<\/p>\n<h3>The Business With Existing WordPress Infrastructure<\/h3>\n<p>If you have 50 plugins, a WooCommerce store, and a custom theme, EmDash is not for you. The migration tool only imports content, not plugins, themes, or custom functionality. You\u2019d be rebuilding everything from scratch, and the plugin ecosystem is empty.<\/p>\n<h3>The Agency Building Client Sites<\/h3>\n<p>Agencies need portability, predictable costs, and a community of developers they can hire. EmDash offers none of those today. Your client site would be locked into Cloudflare infrastructure with no realistic exit strategy.<\/p>\n<h2>The Billing Protection Gap<\/h2>\n<p>Cloudflare does not offer a global spending cap for Workers, D1, R2, or KV. You can set per-worker CPU time limits and configure rate limiting, but those only control how long each request runs, not how many requests you can get billed for.<\/p>\n<p>A small business owner who migrates from WordPress to EmDash expecting predictable $5\/month hosting could wake up to a $500 bill after a traffic spike. The platform has no built-in notification or throttling mechanism to prevent that.<\/p>\n<h2>The Future: 12 to 18 Months<\/h2>\n<p>EmDash\u2019s architecture is the most coherent challenge to WordPress in years. The plugin sandbox, the serverless scaling, and the AI-native design are all genuinely innovative. But architecture is not adoption.<\/p>\n<p>In 12 to 18 months, if Cloudflare builds a real plugin ecosystem, adds spending caps, and reaches a stable 1.0 release, EmDash could become a serious option for new sites. Until then, it\u2019s a developer preview \u2014 impressive, but not production-ready for anyone who needs a reliable, ecosystem-rich CMS.<\/p>\n<p>The question isn\u2019t whether EmDash will replace WordPress. It\u2019s whether Cloudflare will invest the years of community building and feature development required to compete with 60,000 plugins and 24 years of battle testing. The technology is ready. The ecosystem is not.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>EmDash isn\u2019t just another CMS. It\u2019s a deliberate assembly of Cloudflare\u2019s infrastructure products, each chosen to solve a specific problem that WordPress architecture can\u2019t touch. The CMS runs on Workers for compute, D1 for the database, R2 for media storage, and KV for session state. Every one of those products has a billing meter, a [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":100282,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/98076.png","fifu_image_alt":"EmDash\u2019s Place in the Cloudflare Ecosystem: Workers, D1, R2, and More","footnotes":""},"categories":[31],"tags":[],"class_list":["post-98076","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology"],"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/98076.png","fifu_image_alt":"EmDash\u2019s Place in the Cloudflare Ecosystem: Workers, D1, R2, and More","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/98076","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=98076"}],"version-history":[{"count":1,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/98076\/revisions"}],"predecessor-version":[{"id":100283,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/98076\/revisions\/100283"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/100282"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=98076"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=98076"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=98076"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}