Cloudflare released EmDash 1.0, an open source CMS on Astro that it calls a spiritual successor to WordPress, with plugins that run in a sandbox. It imports WordPress content but not themes or PHP plugins, so it suits some sites today and not others.
What Shipped on September 28
Cloudflare released EmDash 1.0 on September 28, during its Birthday Week. EmDash is a free, MIT-licensed CMS built on Astro, which Cloudflare introduced in April and describes as a spiritual successor to WordPress. Editors work in an admin interface, developers build the site in Astro, and agents can work through its API, CLI or built-in MCP server. Cloudflare moved its own blog onto it in August.
It is not tied to Cloudflare. EmDash runs on Cloudflare Workers with D1, or on Node.js 22.16 or later with SQLite, PostgreSQL or libSQL, and its documentation includes a Docker setup.
The Plugin Model Is the Real Difference
In WordPress, a plugin runs inside the same PHP process as the rest of the site, with access to the database, the file system and the network. EmDash's sandboxed plugins run in an isolated runtime instead. Each one gets its own storage and nothing else, and it can read content, handle media or reach a network host only if it declares that ability and an administrator approves it. Cloudflare compares installing one to installing a mobile app, where you see what it wants before it runs.
Two details in the documentation matter before anyone relies on that:
- Only sandboxed plugins are isolated. Native plugins, the format needed for custom React admin screens or Astro components on the public site, run in the same process as the site and are not a security boundary.
- The sandbox needs a runner. On Cloudflare it uses Dynamic Workers, which require the Workers Paid plan, and on Node.js it starts
workerdas a separate process. It is not available on deployments that use Hyperdrive.
Plugins are published to a registry built on AT Protocol, where each release is signed by its author and checked by EmDash before it installs. Only free plugins are supported for now.
What Moves From WordPress and What Does Not
EmDash imports a WordPress site from a standard WXR export or through its own exporter plugin. The import covers posts, pages, custom post types, taxonomies, authors and media, and the exporter adds menus, site settings, Yoast or Rank Math SEO fields and ACF values where the target fields match. Gutenberg content is converted to EmDash's own rich-text format.
Three things do not come across on their own:
- The theme. Astro replaces the WordPress template hierarchy, so the design is rebuilt as Astro pages and components.
- The plugins. PHP plugins do not run on EmDash. Each one is replaced, ported as an EmDash plugin, or dropped.
- Some content details. Shortcodes, page-builder markup and plugin blocks need checking by hand, and private or scheduled posts arrive as drafts. The documentation advises keeping the WordPress site live until the new one has been verified.
Who Should Consider It
A content site with a small editorial team and few plugins is the natural fit, especially one that is due for a redesign anyway, with developers comfortable in JavaScript. The same goes for agencies and hosting companies building many small sites, which is the use Cloudflare designed the platform features around.
Who Should Stay on WordPress for Now
A WooCommerce store should stay, since EmDash's first e-commerce plugin has only just been announced. So should a site built on a page builder, or one that depends on membership, booking or course plugins with no EmDash equivalent. The plugin risk EmDash addresses is real for those sites too, but it is well handled by the usual discipline of a short plugin list, prompt updates and a web application firewall. When a WordPress vulnerability does land, our triage of the wp2shell bug shows how to tell quickly whether it reaches your site.
Keeping a WordPress site fast with a lean, audited plugin list is part of WordPress Speed Optimization.
Sources
Or read how we handle it in WordPress Speed Optimization.
Related News
What The New Spectra RCE Means For Multi Author WordPress Sites
Wordfence disclosed CVE-2026-7465 on May 30, 2026, a remote code execution flaw in the Spectra Gutenberg Blocks plugin (versions up to 2.19.25, fixed in 2.19.26). It needs only Contributor access, so the real exposure is sites with open registration or many low-trust authors. Who is at risk and how to close it.
SecurityThe wp2shell WordPress RCE Is Real, but Three Conditions Decide Whether Your Site Is Actually Exposed
wp2shell (CVE-2026-63030) chains a REST API batch route confusion with the author__not_in SQL injection (CVE-2026-60137) into a pre-auth RCE on WordPress core, fixed July 17 in 6.9.5, 7.0.2 and 6.8.6. The headline is true: an anonymous request can run code on a default install. But three conditions decide real exposure, the version, whether a persistent object cache is in use, and whether auto-updates already patched you. Here is what NVD and WordPress actually say, the CVSS scores that disagree, and a two-minute check for your own sites.
WordPressWordPress 6.9.2 Security Release Is Now Available
WordPress 6.9.2 shipped as a March 2026 security release, making it the safer reference point than older 6.8-focused update coverage.