EmDash 1.0 is the WordPress follow-up I wanted

EmDash 1.0 brings sandboxed plugins, a registry you can leave, and an admin that agents can drive. Those are the pieces I wanted when this site left WordPress.

EmDash 1.0 shipped today, and this is the WordPress replacement I have been waiting for. Lessons in Tech has run on EmDash since April, when plenty of readers assumed the April 1 launch might have been a prank. The code was real. I moved this site off managed WordPress onto Node, SQLite, and nginx. Six months of fixes later, it has reached a stable 1.0 release.

Matt Kane asks what WordPress would look like if you built it today. EmDash keeps its easy editing and extensibility while replacing parts I had learned to tolerate. For 1.0, the team hardened migrations, media, localization, and editorial workflows. The release notes now reserve future breaking changes for a major version.

A launch week already happened

Cloudflare moved its blog before 1.0 for Agents Week in July. It published 28 posts in nine days and served nearly three million pageviews. In August, Cloudflare’s edge absorbed a 28,000-request-per-second DDoS attack. That proves EmDash scales - though this site is a rounding error of volume compared to Cloudflare’s site.

Plugins with a fence around them

WordPress plugins share the PHP process with the site. A plugin can read the database, write files, and open network connections. A buggy or compromised plugin becomes the whole site's problem. Patchstack found that 96% of the WordPress ecosystem vulnerabilities it counted in 2024 were in plugins. That matches how this site used to feel: every plugin brought its own security history and its own upgrade day.

EmDash registry plugins run in sandboxes: Dynamic Workers on Cloudflare or isolated services in a separate workerd process on Node, as this site uses. At install time, you approve declared capabilities, including network access. A plugin gets private storage, not direct access to the site or other plugins, yet can offer hooks, settings, admin pages, widgets, blocks, and API routes. Native plugins run inside the server process without that isolation; they cannot be published to the registry.

A directory you can walk away from

The official WordPress plugin directory is a central gatekeeper for discovery and distribution through that catalog. A publisher can distribute a plugin elsewhere, but losing the official listing still matters. EmDash changes who controls a plugin’s identity and release record.

EmDash 1.0 launches a registry on AT Protocol, the protocol behind Bluesky. Publishers use their own Atmosphere accounts for signed package and release records, with bundles hosted at public URLs. EmDash runs a default catalog and labeler, but others can index the same records under their own policies. Its aggregator, labeler, and Astro listing loader are open source. Installation verifies the signed record and downloaded bundle.

The shelf will look thin next to WordPress for a while, especially if you need a particular plugin. The included agent skills can help scaffold one, port it from WordPress, and map concepts onto EmDash and Astro. Matt Kane says an agent can often build something useful in minutes. I would still test the result. A hackathon is coming, and existing plugins can enter.

WordPress is GPL. EmDash is MIT, so private themes and plugins are an option. Nearly 200 outside contributors have already landed work, along with a triage group and maintainers beyond Cloudflare staff. The media and image library was rebuilt for this release, and contributors have translated EmDash into 25 languages.

Editors and agents on the same site

WordPress got one thing exactly right: the admin ships with the site. EmDash keeps that, as an Astro integration. One app to patch, proxy, and back up.

WordPress can be connected to agent tools, but EmDash includes them in the core experience. A built-in MCP server uses OAuth with granular access controls, and agents can also work through the API and CLI. Skill files map WordPress ideas onto EmDash and Astro, so an agent has a guide to the site it is changing.

Posts live as Portable Text, structured JSON, whereas WordPress block content uses HTML with metadata in comments. That separation makes it easier to present content in another app. The CLI can display it as Markdown, which is how I worked on this post. You still get TipTap, visual editing, drafts, revisions, scheduling, search, menus, taxonomies, and widgets.

Sign-in is passkey-first, with OAuth and magic links available, and the roles you already know: Administrator, Editor, Author, Contributor. Passkeys behind nginx were a real beta headache here. Current releases are in much better shape.

The importer takes posts, pages, media, and taxonomies from a WXR file, the WordPress REST API, or WordPress.com. Starters cover a blog, a marketing site, and a portfolio. EmDash Build , an alpha site builder a host can run itself, is up for a look.

Hosting without a PHP stack

WordPress grew up on a rented server, PHP, and caching layers. EmDash can deploy to Cloudflare on a free plan and handle spikes on its infrastructure, or run on a Node server anywhere you choose. This site is run on an independent shared server: nginx, systemd, SQLite, uploads on disk, and an Astro front end. D1 and R2 are options for a Cloudflare deployment. For my setup, backups include the database and uploaded media.

Try it

Managed WordPress might still makes sense when you need its vast plugin catalog or want someone else to handle the PHP stack. EmDash blows past it where I care most: bounded plugin permissions, publisher-controlled releases, useful agent access, and a stack I can explain. EmDash 1.0 makes that choice easier to recommend beyond my own site.

npm create emdash@latest

Or hand an agent the docs:

Look at https://docs.emdashcms.com/llms.txt and help me build a site

No comments yet