Tuesday, September 29, 2026 Newsletter Advertise
Breaking
Products

Cloudflare ships EmDash 1.0 CMS with decentralized plugin registry

Cloudflare says its open source Astro-based CMS is now stable, with sandboxed plugins and a registry built on AT Protocol rather than a central marketplace.

Cloudflare ships EmDash 1.0 CMS with decentralized plugin registry. Source: Cloudflare

Cloudflare on September 28, 2026 released EmDash 1.0, describing it as a stable, free and open source content management system built on Astro, alongside a decentralized plugin registry that the company says lets developers publish extensions without handing identity and releases to a central marketplace.

What Cloudflare released

EmDash was introduced on April 1 as what Cloudflare called the "spiritual successor to WordPress", a framing that led some in the industry to wonder whether the project was an April Fools' joke. Cloudflare said it was not, and that version 1.0 is ready to power a production website, an agency's vibe-coding platform or a hosting company's site-building experience.

According to the company, developers build with Astro, editors manage content through the EmDash admin, and agents can work through the API, CLI or a built-in MCP server. Cloudflare said the past five months of work with contributors and production users focused on data safety, database migrations, editorial workflows, localization, plugin security, performance and the reliability of the admin, API, MCP and media experiences.

EmDash is released under the MIT license. Cloudflare said more than 175 people have contributed across more than 1,800 commits, that contributors have translated the software into 25 languages, and that over 800 people are in the project's Discord community. The company also credited Noah Pham, who joined Cloudflare as an intern and became EmDash's second maintainer alongside Matt, with more than 80 changes.

A registry built on AT Protocol

Cloudflare said traditional plugin registries combine three roles — publisher account, authoritative package record and discovery catalog — which makes one company the gatekeeper for both identity and distribution. EmDash instead separates the plugin from the catalog, with publishers retaining control of their packages and release history.

The registry is built on AT Protocol, which Cloudflare described as a decentralized network protocol that powers Bluesky. Plugin authors publish with an Atmosphere account, and package and release records are signed by the publisher and stored in the publisher's own account. Cloudflare said atproto repositories use signed Merkle Search Trees, so EmDash can verify a release record independently and then check the plugin's checksum, package name, version, requested access and any required build provenance.

The company said it hosts the default registry services and has open-sourced them, including the aggregator behind the registry, a labeler service that uses Workers AI to moderate package descriptions, and an Astro live content loader. Catalog moderation can hide material but does not rewrite a release or take ownership of a plugin, Cloudflare said. Free plugins are supported today, with paid plugins an aim for the future.

Sandboxed plugins and platform features

Cloudflare contrasted its model with WordPress, where it said plugins run inside the same PHP process with direct access to the database, filesystem and network. EmDash sandboxed plugins each run in an isolated runtime with access only to their own private storage, gaining further abilities only when declared by the plugin and approved by the site administrator.

On Cloudflare, each plugin runs as a Dynamic Worker through the Worker Loader; on Node.js, EmDash starts workerd, the open-source Workers runtime, as a separate process and runs each plugin as an isolated service inside it, the company said.

Cloudflare also said it migrated its own blog to EmDash in August under a "Customer Zero" approach, requiring readiness for millions of pageviews per week and spikes up to 5,000 requests per second of legitimate traffic. Optional KV object caching, a Hyperdrive database adapter and Workers Cache compatibility came out of that project. Separately, the company released an alpha of EmDash Build, an open-source AI site builder that gives each project its own Cloudflare Sandbox container and tracks changes as git commits via Artifacts.

What to do

  • Create a new EmDash site locally via the CLI by running: npm create emdash@latest, or set one up from the Cloudflare dashboard.
  • Try the EmDash playground site, or the EmDash Build demo at build.emdashcms.com, before committing to a migration.
  • Plugin developers can follow the step-by-step guide in the EmDash documentation for creating and publishing a plugin to the registry.
  • Review the plugin sandbox documentation for setup details and runtime differences between Cloudflare and Node.js deployments.
  • Before installing a plugin, check the abilities it requests in EmDash, since the runtime limits it to administrator-approved access.
  • Contributors, including translators, testers, designers and documentation writers, can join the EmDash community on Discord.
Key facts and where they come from
  • Cloudflare released EmDash 1.0 as a free, open source CMS built on Astro.
    Today, we are releasing EmDash 1.0: a stable, free, and open source CMS built on Astro
  • The project uses the MIT license.
    EmDash is completely free and open source, using the flexible and permissive MIT license.
  • The plugin registry is built on AT Protocol.
    The registry is built on AT Protocol (atproto), a decentralized network protocol that powers Bluesky and a growing ecosystem of applications.
  • More than 175 people contributed across more than 1,800 commits.
    more than 175 people have contributed to the project, across more than 1,800 commits
  • Contributors translated EmDash into 25 languages.
    Contributors have translated EmDash into 25 languages, from Arabic to Ukrainian.
  • Plugins run isolated, without default access to site content, media, users or network.
    Each plugin runs in an isolated runtime with access to its own private storage, but not to the site’s content, media, users, secrets, environment, filesystem, or network.
  • Plugin isolation uses Dynamic Workers on Cloudflare and workerd on Node.js.
    On Cloudflare, EmDash runs each plugin as a Dynamic Worker through the Worker Loader. On Node.js, EmDash starts workerd — the open-source Workers runtime — as a separate process
  • Cloudflare migrated its own blog to EmDash in August.
    In August, we migrated the Cloudflare Blog to EmDash as part of our “Customer Zero” approach.
  • The blog migration required handling spikes up to 5,000 requests per second of legitimate traffic.
    being ready for millions of pageviews per week, spikes up to 5,000 requests per second (RPS) of legitimate traffic, or sporadic DDoS attacks
  • An alpha of EmDash Build, an AI site builder, was released and open-sourced.
    We are also releasing and open-sourcing an alpha of EmDash Build, an AI site builder that hosting providers, website builders, and platforms can run themselves
  • The registry currently supports free plugins only.
    The registry supports free plugins today, and we aim to add support for paid plugins in future

Read the original from Cloudflare →

The TechUpscale Brief

The day's cyber, AI and tech news in one short email, every weekday morning. Free. Unsubscribe anytime.

I'm most interested in

More Products