20 ms·
EmDash – A spiritual successor to WordPress that solves plugin security
- Meneth 6mo ago"solve security" - that's an April Fools joke if I ever heard one.
- reddalo 6mo agoGiven how shitty it looks and behaves, I was 100% sure this was an April Fools. But after reading the serious comments here on HN, I'm not sure anymore...
- pixxel 6mo ago[dead]
- ymolodtsov 6mo agoYou can certainly solve WordPress well-known security issues by dropping WordPress, hard to argue with that.
- s99850 6mo ago[flagged]
- steffs 6mo ago[dead]
- vessenes 6mo agoHere to say -- great name. It's not just a reference to our modern times, it's a sign of brilliance. (I wrote this myself with no clanker support)
- echelon 6mo ago[flagged]
- bo0tzz 6mo agoI've been wanting a CMS on top of Cloudflare workers for a while, so I hope this pays off!
- OJFord 6mo agoPages is a thin layer over Workers, and a standard deployment target for most if not all that I've seen.
- bo0tzz 6mo agoI specifically want the entire thing to run on workers though; if I'm hosting a separate CMS backend elsewhere, I might as well have that serve the site.
- paulpopus 6mo agoPayload can be deployed to Cloudflare Workers: https://github.com/payloadcms/payload/tree/main/templates/with-cloudflare-d1 https://github.com/payloadcms/payload/tree/main/templates/wi...
- kocialnews 6mo agoThe power of WordPress is not the ease of use, but PHP. Anything built on PHP will be widely used, like Laravel
- echelon 6mo agoAll PHP is going to be replaced with single binary Rust apps. Talented teams will build the atoms for most apps - blogs, CMSes, ticket systems, forums - and it'll be easy for end users to configure. Rust is easy to code gen and deploy now. No barrier to understanding lifetimes. It's the language everyone should be using Claude Code to emit. Everyone is now a Rust engineer with 10 years of experience. (I'm not joking, just in case that needs clarification.) If you haven't tried writing a simple web service in Axum or Actix plus SQLx, you need to give it a try. You'll be amazed at how simple it is, and you'll be even more amazed at how performant and easy it is to work with. You do not need to know Rust or have any prior Rust experience. You'll pick it up along the way. It's easy and you'll learn it fast. Rust is a low-defect rate language to serialize to. The syntax begs you to handle errors, nulls, exceptional conditions within the language itself. This is naturally a good fit for most business problems. It doesn't hurt that the language is fast as hell and super portable either. If the job is now encoding business logic - this is the optimal serialization that I'm aware of. I write Go, Java, Python, TypeScript, PHP, Swift - I can't think of any better language for greenfield projects that don't have existing language/library requirements.
- kemayo 6mo agoI'm not sure you appreciate why PHP was successful. You might be completely right about all this, but the LAMP-stack "just upload this file to shared hosting" workflow is what made apps like WordPress win out, and the barrier remains significantly higher to do the equivalent with Rust.
- echelon 6mo agoHistorically successful. Draging a bunch of PHP files onto an FTP client is harder than modern dev practices. If you've got a modern frontend of any kind, you're already beyond this.
- nullable_bool 6mo agoIts kind of annoying that CF would use an LLM to build something and try to pass it off as something built from "the ground up". Its just copying the library that was already build and passing it off as their own.
- deleted 6mo ago[deleted]
- reddalo 6mo agoBut isn't this a well-curated April Fools?
- philipwhiuk 6mo agoThe problem is that it doesn't solve the network-effect problem. People aren't on WordPress because of WordPress. They're on WordPress because of WooCommerce, a million themes, BuddyPress, integrations for every stupid internal business API on the planet (many of which are terrible and were written by an idiot with a crayon). The APIs will have no testing because they are bad. In many cases the WordPress implementation of the API written in the codeblock, ran on page-load to the pain of the person responsible for SEO, is the API contract. And yes those plugins are also terrible, but they solve business problems, even if they are tech problems. You can't just launch a better wp-core and expect it to replace any of that. EmDash needs to actually run the existing insecure WP plugins to takeover.
- squidbeak 6mo agoYou seem to have missed the point. This is intended to be more secure in a new world where exploits will be cheap to discover. The factors you mention won't keep people onboard if systems are compromised every day in too many ways for fragmented security teams to keep on top of.
- philipwhiuk 6mo agoPeople running WordPress don't have security teams. If they get compromised they blat the server, re-upload a fresh copy, update the plugin affected and apologise for the week of downtime.
- embedding-shape 6mo ago> Our name for this new CMS is EmDash. We think of it as the spiritual successor to WordPress. It’s written entirely in TypeScript. It is serverless, but you can run it on your own hardware or any platform you choose. Plugins are securely sandboxed and can run in their own isolate, via Dynamic Workers, solving the fundamental security problem with the WordPress plugin architecture. And under the hood, EmDash is powered by Astro, the fastest web framework for content-driven websites. To me this sounds of the polar opposite of the direction CMS's need to go, instead simplify and go back to the "websites" roots where a website are static files wherever, it's fast, easy to cache and just so much easier to deal with than server-side rendered websites. But of course, then they wouldn't be able to sell their own "workers" product, so suddenly I think I might understand why they built it the way they built it, at the very least to dogfood their own stuff. I'm not sure it actually solves the "fundamental security problem" in actuality though, but I guess that remains to be seen.
- airza 6mo agoSure, but if I want to host my static files on a website where they are easily cached... cloudflare also offers this product?
- verdverm 6mo agoReminds me of Vercel and NextJS, where a popular framework design is constrained by, or optimally runs, on their infra, but then comes with pains or unusualness if self-hosted (eg. middleware). Vendor lock-in plays are a big red flag
- vasco 6mo agoThe question is then they'd be building some brand new thing not compatible with wordpress. Supposedly the proposition is to steal people away from wordpress. Not just get people building something from scratch looking for a new framework. I'm guessing the recent lawsuits also provide some momentum.
- tadfisher 6mo agoIt's not compatible with WordPress, though. It slurps a WordPress export, which is quite literally static data. They expect you to code up anything dynamic using their agent skill.
- halapro 6mo agoYes definitely compare it multiple times to WordPress and nobody will think of calling their lawyers. Is this April fools? With real products launching on this date you can't really be too sure.
- rvz 6mo agoNot an April fools joke. [0] [0] https://github.com/emdash-cms/emdash https://github.com/emdash-cms/emdash
- quantummagic 6mo agoThat makes it look more like an April fools joke. All the commits are from today.
- OJFord 6mo agoThat's not unusual though, large companies releasing something open source very often squash the history at launch.
- george_perez 6mo agoCloudflare specifically launches things on April 1st a lot of times. https://x.com/Cloudflare/status/1907055975057506793 https://x.com/Cloudflare/status/1907055975057506793 They announced 1.1.1.1 on April 1st way back in 2018 too.
- gman83 6mo agoGmail was also launched on April 1st. The fact that it came with 1GB of storage instead of Hotmail, which limited you to something like 20MB, made people think it was an April Fool's joke.
- bigbuppo 6mo agoThe best jokes are serious.
- 6mo ago
- squidbeak 6mo agoImpressive and created by agents. Another example for skeptics wondering where the AI apps are.
- allknowingfrog 6mo agoI think this is too soon to call. No one questions whether AI can build things. We question whether they can build stable things that work as expected and stay online in the long run.
- skybrian 6mo agoThis will largely be based on the maintainers’ priorities. Coding agents can audit and clean up code too, provided that you set the right goals.
- amarant 6mo agoI too have seen a lot of comments asking where the products are. If you're now moving the goal posts to "stay online in the long run" you're gonna have to wait until there's been a long run to stay online in. Agents aren't that old yet.
- saadn92 6mo agoThe stability question is real but I think it's framed wrong. The issue isn't whether an agent can write correct code in a single session -- they can, and pretty reliably now. It's whether there's a human with enough understanding of the codebase to debug it when something breaks at 2am. I run parallel coding agents on my own projects daily. The code they produce is fine. What worries me is the "just ship it" energy where nobody on the team deeply understands what got built. That's not an AI problem, it's been a problem with outsourced codebases forever. AI just makes it faster to accumulate code nobody fully groks. Cloudflare probably has the engineering depth to maintain this regardless of how it was built. A lot of other teams don't.
- carlos-menezes 6mo ago> "Failed to initialize playground" Impressive indeed!
- jmkni 6mo agoIt's kind of ironic that the name of this product is also the most obvious marker of LLM generated content
- benob 6mo ago"That allows us to license the open source project under the more permissive MIT license."
- Aurornis 6mo agoThat's the joke.
- jmkni 6mo agoOh I am slow lol Is this an April fools?
- vetrom 6mo agoFunctional April Fools, the best kind. A couple years ago Eleiko, a weightlifting equipment company did one, the 'Heavy Mug', a 19 poundish steel coffee cup with a handle in the style of a knurled bar, and actually did a limited run of them.
- ascorbic 6mo agoName is a joke, but the project is real
- megnu 6mo agoThe UI doesn't seem geared to power users. E.g. Why is the featured image taking up so much space above the content editing area when it's sized appropriately for the sidebar? Imagine you need to update the text of several posts... Well, now you gotta scroll down half the page to the content area of each one. And all that padding gets you quite the narrow content area. Not to mention it looks like a very basic TinyMCE. Seems like more of a POC than an actual "spiritual successor".
- mrcwinn 6mo agoIt’s written in typescript, not PHP. How does this improve security if no one uses it because they’ve invested so much in the WP plugin ecosystem?
- pxtail 6mo agoGood one, at last, April fools joke with some effort.
- 8organicbits 6mo agoI don't think it's the code that makes WordPress valuable. I've been learning WordPress recently and haven't been too impressed with the internals. WordPress is valuable because of the ecosystem and support. I have no doubt that WordPress will still be a thing in ten years. What's the support plan for EmDash? I see commits are mostly from a single developer. E: Oh, I think it's an April fools joke, I'm embarrassed. E2: Apparently not a joke.
- gbibas 6mo ago[flagged]
- jimnotgym 6mo agoI did that once, employed someone on Fiverr to do a WordPress site. They installed a load of plugins for no reason, made a mess, then gave me my money back. I went back to a static site. That has been my experience, low barrier to entry, low price, shoddy work. Or hire an agency, pay top dollar for little work.
- gbibas 6mo agoHa, yeah that's the other side of it — low barrier to entry cuts both ways. The WordPress talent pool is huge but unfiltered. Still, the fact that pool exists at all is what keeps WordPress dominant. Nobody's hiring Fiverr gigs to customize an EmDash site yet.
- hatmanstack 6mo agoThere might be pie on your face but they stole my line, https://github.com/HatmanStack/kill-wordpress https://github.com/HatmanStack/kill-wordpress
- 8organicbits 6mo agoI think you need to account for the base rate. There's a lot of WordPress plugin vulnerability disclosures because there's a lot of WordPress plugins and there are enough deployments of the plugins to make searching for those vulnerabilities is worthwhile. That site warns that WordPress plugins can be abandoned, but that's clearly not a WordPress specific issue. Sure some site could use SSG, but that's a different design. I certainly don't want to claim WordPress security is good, but I'm not sure that site is measuring anything meaningful.
- yeah879846 6mo ago"Failed to initialize playground"
- vntok 6mo agoTry again once or twice.
- ramesh31 6mo agoI really hope Cloudflare is ready and willing to stand by this thing for the next 20 years, and drive it as a first class product with a huge open source team. Because short of that you can just add this to the mile-long list of "successors to WordPress" we've been through over the decades. Maybe they're in it for the long haul. We'll see. But it takes time, and mountains of integrations and acceptance into the wider web authoring ecosystem for anything like this to gain real adoption.
- skybrian 6mo agoOne thing that makes it different this time is that coding agents will probably make it easy to port the most important plugins to the new system. Also, there are successful alternatives to Wordpress too, so the most likely outcome is that it becomes yet another alternative.
- ChrisArchitect 6mo agoHeld up getting into the details of this ambitious project because of the name! Ridiculous choice considering the associations with AI, slop, and even the general crowded namespace surrounding that. C'mon. (looks for cameras) Wait a minute, am I being Punk'D? Oh my god! Ashton, you really got me! Ha Ha! Ashton!
- 9864247888754 6mo ago[dead]
- woodylondon 6mo agoReading the comments below, have we all fallen for a 1st April Fools' joke? Actually, rebuilding WordPress without the ecosystem is kind of the point. For example, would Divi or the major page builders rebuild their entire products to support this? I doubt it
- AIorNot 6mo agoDamm Anthropic had a chance to say april fools too for the claude code leak!!
- bbx 6mo agoI'm all for creating new frameworks that are faster and more secure. But I don't see how this one relates to Wordpress (not in PHP, serverless, not "plug and play", dependent on Astro, "AI Native"…). It looks like a good open source project, but just call it a new CMS. I think calling it a "spiritual successor to WordPress" is just to gain some marketing points.
- tamimio 6mo agoWill be there a way to export all the posts to markdown so you never get locked in?
- spankalee 6mo agoIt's a shame they don't seem to try to address the divide between CMS's and static sites. Most WordPress sites could just be static, but WordPress has a nice editor interface, so they're not - unless you use a SSG plugin. Building that into the core workflow (which I believe Astro supports) and giving users a nice hosted editor that produces a static site would be welcome innovation.
- MattieTK 6mo agoEmDash with some aggressive caching and SWR is effectively this, and we're getting closer to that every day. When the cost of maintaining the data part of the CMS is effectively free, you're basically working with a static site anyway.
- Y-bar 6mo agoI haven’t used Wordpress for a few years. But with WP Super Cache (1) we also always did pretty much that: On saving a post/page the static HTML would be written to a cache directory and be the default content served to visitors. [1] https://wordpress.org/plugins/wp-super-cache/ https://wordpress.org/plugins/wp-super-cache/
- RobotToaster 6mo agoThe issue with static sites is they can't do comments.
- Closi 6mo agoThey can - it’s just more complex. You just put the comments into something like firebase/supabase etc or use one of many off the shelf solutions. Free tier is fine.
- egypturnash 6mo ago"Just" sure is doing a lot of heavy lifting in this sentence.
- andy_xor_andrew 6mo ago> x402 is an open, neutral standard for Internet-native payments. It lets anyone on the Internet easily charge, and any client pay on-demand, on a pay-per-use basis. A client, such as an agent, sends a HTTP request and receives a HTTP 402 Payment Required status code. In response, the client pays for access on-demand, and the server can let the client through to the requested content. Fascinating. Cloudflare is envisioning a future where agents are given debit cards by their owners, so they can autonomously send microtransactions to website owners to scrape content or possibly purchase goods on the owner's behalf. I don't know how I feel about that but there's no doubt it's a fascinating concept. Brb, setting up a honeypot that always responds with HTTP 402 Payment Required demanding 10cents per visit... That's the next "selling 1 million pixels on my website for $1 each", I guess
- danudey 6mo agoIf you can find a way to trick agents into always accepting your payment required then you could set up a tarpit generating trash content or an infinite string of redirects or "read this other page for more info", charging extra for each one.
- myhf 6mo ago> you could set up a tarpit generating trash content and you could call it "EmDash"
- TiredOfLife 6mo agoSo exactly like it is and has been for decades but instead of ads its micropayments
- akktor 6mo agohttps://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Status/402 https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/...
- nonameiguess 6mo agoIt's like the exploit from Office Space is finally legal.
- deleted 6mo ago[deleted]
- sourcecodeplz 6mo agoThis part is interesting: "Plugin security is the root of this problem. Marketplace businesses provide trust when parties otherwise cannot easily trust each other. In the case of the WordPress marketplace, the plugin security risk is so large and probable that many of your customers can only reasonably trust your plugin via the marketplace. But in order to be part of the marketplace your code must be licensed in a way that forces you to give it away for free everywhere other than that marketplace. You are locked in." There was much drama with wordpress some time ago and the plugin marketplace.
- _cloned 6mo agoPayload
- throwaway613746 6mo ago[dead]
- rodolphoarruda 6mo agoPlugin security is one thing. Plugin budget is another thing... much larger of a problem in some cases.
- deleted 6mo ago[deleted]
- rgbrenner 6mo ago> Solving scale-to-zero for WordPress hosting platforms > WordPress is not serverless Just not accurate. WordPress doesn't prevent this.. It's up to hosting providers to work on their infra so it can run in a serverless fashion. For example: https://www.agiler.io https://www.agiler.io That's serverless wordpress that scales to zero.. no changes to WordPress, plugins or anything else.. just platform infra.
- solarkraft 6mo agoLast time I checked Wordpress was completely fine living in a couple of PHP files on a webspace. That’s like the pinnacle of „serverless“, is it not?
- rgbrenner 6mo agomysql/mariadb and the shared filesystem requirements are a bit different than what lambda/etc provides. So not really, but it's all solvable clearly.
- droptablemain 6mo agoNot even a little bit.
- aplomb1026 6mo ago[dead]
- Levitating 6mo agoI don't like where any of this is going
- FlamingMoe 6mo agoA WordPress spiritual successor backed by Cloudflare sounds great in theory, but the headline feature, plugin isolation via Dynamic Workers, only works on Cloudflare's runtime. On any other host it's just a TypeScript CMS without the security model that justifies its existence. Open source but architecturally locked in.
- solarkraft 6mo agoI missed this. So they didn’t really solve much at all. I guess at least it’s compatible with other runtimes. But yeah, who would’ve guessed that Cloudflare software would (besides being vibeslop) prefer Cloudflare infra. This, of course, makes the software quite hard to adopt.
- zsoltkacsandi 6mo ago> Open source but architecturally locked in. You hit the nail on the head. Cloudflare's new business model is to find popular OSS projects, create a vibe coded alternative that only runs on Cloudflare's infrastructure.
- frizlab 6mo agoSadly, it looks more and more like it. It’s sad, because they were doing wonderful stuff.
- zsoltkacsandi 6mo agoAgreed. They are destroying their professional reputation.
- QuantumGood 6mo agoI think pretty much every corporation that can have had this thought, has had it. Really "any popular software" where they can provide similar functionality. And I think this is going to happen more often before it becomes less common.
- wmf 6mo ago
- amiga386 6mo ago> While EmDash aims to be compatible with WordPress functionality, no WordPress code was used to create EmDash. That allows us to license the open source project under the more permissive MIT license. Ha ha, that's really funny timing given the recent launch of Cleanroom As A Service, promising that you can licensewash other peoples' code quickly and easily: https://malus.sh/ https://malus.sh/ I'm not saying they did that, but it's ironic timing.
- lurkshark 6mo agoMalus is (well crafted) satire.
- richbell 6mo agohttps://fosdem.org/2026/schedule/event/SUVS7G-lets_end_open_source_together_with_this_one_simple_trick/ https://fosdem.org/2026/schedule/event/SUVS7G-lets_end_open_...
- earthlingdavey 6mo agoSo well crafted in-fact, that if you pay them, they will provide the service.
- riffic 6mo agoif this can implode the crooked "web hosting industry" that surrounds the lamp / wordpress ecosystem the better.
- paoliniluis 6mo agoWho wants to vibe code an open source Cloudflare?
- gsmiznith 6mo agoThis is great, but if the plugin ecosystem isn't compatible will it take off? Most WordPress users use at least one plugin: it is the appeal of the product.
- password4321 6mo agoIf you need a reliable source for WordPress plugins, check out https://github.com/fairpm/fair-plugin?tab=readme-ov-file#fair-connect https://github.com/fairpm/fair-plugin?tab=readme-ov-file#fai... A system for using Federated and Independent Repositories in WordPress
- solarkraft 6mo agoConvince me this isn’t vibeslop. If Cloudflare really have radically changed their software development philosophy lately, this would actually be an interesting project, being based on Astro and coming with some APIs for programmatic management. Them being so happy about the „cost of software development“ and not going very deep into ecosystem, community or project management doesn’t convince me that this is going to be a worthwhile project, even if, unlike their previous vibe coding demos, this one actually works.
- flakiness 6mo agoIf you read the first few sentences... > But for the past two months our agents have been working on an even more ambitious project: rebuilding the WordPress open source project from the ground up. They have honed their AI OSS troll marketing chop and every step goes far and far. I'll take it more seriously once they start open sourcing vibe coded projects they actually use in their production.
- ascorbic 6mo agoI'm the main engineer on this. I've also been on the Astro core team for two years, so I do think I understand real open source software and community. As the post implies, I did use a lot of agent time on this, but this isn't a vibe-coded weekend project. I've been working full time on this since mid-January.
- deleted 6mo ago[deleted]
- i_have_an_idea 6mo agowill all my custom Wordpress themes and plugins run on EmDash?
- billyhoffman 6mo agoFor plugins, no. 1- EmDash plugins are written in TypeScript, not PHP 2- EmDash plugins have a specific permissions model, where they need to explicitly request access to certain things. 3- WordPress plugins just invoke things. EmDash plugins have a defined API you use to talk to different capabilitites 4- Those capabilities are totally different, and at a different abstraction, than what WordPress provides. Beyond the look of the admin interface and publishing flow, I don't see how this is a "Spirtual Successor" to WordPress at all. Its a CMS, designed from scratch, for a serverless world, using CF proprietary capabilities (D1 Databases, R2 for image/media storage, their workers for running things).
- heipei 6mo agoSerious question: Who actually builds stuff on Cloudflare workers? I mean large software projects / services, and not just side projects where the ability to scale-to-zero is perhaps more important than the scale-to-infinity direction. I feel like Cloudflare keeps pushing workers with its full force yet I fail to see the appeal.
- odie5533 6mo agoIt's always seemed like a solution looking for a problem.
- CharlesW 6mo agoI'm building a commercial SaaS product on Workers. Although I've barely scratched the surface of what Cloudflare offers¹, so far it's been great. The value proposition is effectively the same as serverless in general: You worry about the product, they worry about deployment. Note that Cloudflare Workers is just one (albeit important) star in their constellation of capabilities. ¹https://developers.cloudflare.com/directory/?product-group=Developer+platform https://developers.cloudflare.com/directory/?product-group=D...
- jesse_dot_id 6mo agoMe. I used to deploy everything via Docker swarm but recently migrated everything to workers because wrangler is awesome, it makes blue/green very simple, and it's a lot less of a headache for me to maintain in general. It's a great/flexible product. I also use R1/R2 pretty extensively.
- lioeters 6mo agoCloudflare Workers solves their "scaling the price to infinity" problem.
- aetherspawn 6mo agoAnything built in Svelte can be deployed to workers easily, and it’s a very good platform. Just missing compartmentalisation features between prod and dev environments.
- hacker161 6mo ago
- doright 6mo agoI dunno, with the constant firehose of debate and disdain for AI this is a joke I'm too burned out about to feel like laughing at.
- jdurban 6mo agothe plugin security problem in WordPress was never really a code quality problem - it was a trust model problem. any developer could publish a plugin and any site owner could install it with one click, with no vetting layer in between. TypeScript and serverless doesn't change that dynamic unless the trust model changes too. curious how EmDash handles third-party plugin permissions at the API boundary.
- ascorbic 6mo agoIt runs each sandboxed plugin inside its own dynamic worker, with a separate bridge worker to enforce permissions. The worker only has access to its permitted APIs.
- jdurban 6mo agothe bridge worker as permission enforcement is a solid pattern - the plugin can't escalate by calling APIs directly, everything goes through the bridge. the edge case I'd be curious about is plugin-to-plugin interaction. if two plugins share state through a permitted API, does the bridge enforce granular enough boundaries there, or does the trust model flatten at that layer?
- 0xbadcafebee 6mo agoSerious question: Why is everyone still using JavaScript to AI-code projects? You can vibe-code apps with real languages now. There's no reason to use an interpreted, bloated, weird language anymore. The only reason interpreted languages were a thing was so you could edit a file and re-run it immediately without a compile step. Compiling is now cheap, and you don't have to build expertise in a new language anymore. Ask AI to write your app in Go, it'll happily comply. Run it and it's faster with less memory use and disk space. The code is simpler and smaller making reviewing easier. Distribution is as easy as "copy the file". I'll grant you, interpreted languages skip the "portability" compiling/distributing step, and let you avoid the stupid MacOS code signing. But Go is stupid easy to cross-compile, and (afaik?) the user can un-quarantine a self-signed app pretty easily.
- nikcub 6mo agoa) llms are good at writing typescript b) typescript fixed a lot about javascript and is somewhat decent c) multiple fast and performant runtime engines d) deployment story is php levels of easy that's it.
- Yokohiii 6mo ago> d) deployment story is php levels of easy Yeah just invalidate the SSR cluster for your tiny footer update and let it prewarm until coffee break. Easy.
- boredtofears 6mo agoDo LLM's not benefit from the abstractions higher level languages like Javascript/node offer? Perhaps I'm speaking out of depth because I haven't done a lot of Golang, but I've always thought of it as a systems language first, which means by necessity you have you to handle lower level problems yourself. I'm sure there's plenty of libraries that paper over this - but the philosophy of the languages themselves is different. Javascript was designed to solve CRUD like interfaces/problems quite well. Maybe this is just an outdated argument though that isn't really relevant with modern golang/rust though.
- toolpipe_dev 6mo ago[dead]
- sergiotapia 6mo agoSpiritually bankrupt, that should just be considered marketing material.
- orliesaurus 6mo agodeployed it on vercel for lolz - it works!
- mrbonner 6mo agoI am not sure if this is an April fool joke anymore in the age of AI.
- hnismad 6mo agoEmDash on Apr 1 come on guys
- rafark 6mo agoWill you look at it. Another Wordpress “killer”. Wordpress has that market share because it can be easily installed in a wide variety of servers and because of its plugin ecosystem of dozens of thousands of plugins and huge flexibility/customizability. Wordpress is one of the most flexible pieces of software out there and none of the competition seem to get why Wordpress is so popular.
- sensitiveCal 6mo ago[dead]
- TheRealPomax 6mo agoFrom the people who brought you "we used AI to undercut a project we use rather than pay them fairly for the work we relied on" comes an exciting new lawsuit by Mullenweg for using Wordpress in their product description.
- sam345 6mo agoI for one am glad that WordPress has some competition. This sounds like a killer rewrite.
- delfinom 6mo agoIs this just literally turning plugins into microservices? Lol
- delbronski 6mo agoHa! Nice April Fools joke. Nothing will succeed WordPress. Not even AGI. Specially not something with the name EmDash. Good one Cloudflare.
- Jaco07 6mo agoSpiritually hollow; at this point, it reads more like marketing material than anything of genuine substance.
- tkel 6mo agoYeah, they are churning out these AI slop projects for blogpost hits about once a week now
- hackerbeat 6mo agoThanks, but I'll stick to WordPress.
- pixxel 6mo ago[dead]
- TheTaytay 6mo agoIt looks like I'm in the minority after reading this comments, but I'm quite happy to see this announcement. A "good" standard, free CMS with theming and plugin support without the issues of Wordpress is _welcome_. (And the issues are many: Licensing, trust, drama, security, and cost). I'm guessing that a lot of cynicism here is coming from this crowd not being the target market of Wordpress in the first place? What were you recommending to non-technical friends and family who wanted a good, open source, affordable CMS to back their website? Wordpress has all the right _ideas_, but the wrong implementation.
- voganmother42 6mo agoI think the cynicism is related to cloudflares recent previous releases that were considered to be slop that significantly overpromised on its capabilities/completeness. Trust can take a long time to rebuild.
- notahacker 6mo agoThrow in the the bragging about slop and cleanroom clones to avoid AGPL, the name and April 1st launch date, and maybe the high priority afforded to agent-friendly crypto payment infrastructure if anyone was paying attention. Maybe they prompted the marketing agent with "how can you get HN to loathe a product as innocuous as an open source headless CMS?" Other than that, it seems it might be a half decent headless CMS, if the bit of WordPress you want is its interface, and not the number of plugins and devs and not being tied to Cloudflare's infrastructure.
- 9dev 6mo agoThere are great standard CMSes that do everything technically better than Wordpress (not that it's harder to jump higher than a rock, but hey). That's not the hard part. Every developer should build a good CMS once. The hard part is displacing Wordpress market share; building a community of bloggers, marketeers, agencies, web designers, and so on; creating a huge ecosystem of paid and free plugins, allowing plugin devs to commit to your marketplace and lock customers in. Wordpress is awful. The only thing it's got going is its moat, but that's not an engineering problem, but a people problem instead.
- rednafi 6mo agoIt's great that they are recreating much of the fundamental software stack using LLMs. But if you're going to 'vibeslop,' at least do it in a language other than JavaScript. I struggle to understand why anyone would want to generate code in TypeScript - unless what you're building truly can't be done in Go, Rust, or Kotlin; anything but JS. I’m not sure how much of an improvement it really is to rewrite something from PHP to TypeScript while claiming security benefits.
- billyhoffman 6mo agoI mean it's cool your created a new CMS and all, but beyond the look of the admin interface and publishing flow, I don't see how this is a "Spirtual Successor" to WordPress at all. Its a CMS, designed from scratch, for a serverless world. It has a stricter, well defined API that plugins are forced to use instead of directly calling/overriding core functionality like in WP. But that benefit comes with a CMS that's built on top of, and seems to prefer, a ton of CF proprietary capabilities (D1 Databases, R2 for image/media storage, their workers for running things). The web need less consolidation on CF, not more.
- CharlesW 6mo ago> Its a CMS, designed from scratch… Maybe not scratch scratch: "And under the hood, EmDash is powered by Astro…" > It's built on top of, and seems to perfer you use CF proprietary capabilities (D1 Databases, R2 for image/media storage, their workers for running things. D1 is SQLite, R2 is S3, and there are other ways to securely run plugins. If it was designed to only be possible to deploy on Cloudflare, they didn't do a very good job.
- rationalist 6mo agoWhy would I want to publish my writing online when it can just be copied by an AI?
- layer8 6mo ago“EmDash” sounds like it will also generate the writing.
- hyperionultra 6mo agoWordpress is PHP, which has developer base insanely larger then typescript. Also, a lot cheaper. Compete with that.
- skybrian 6mo agoCoding agents make this much less important.
- jesse_dot_id 6mo agoYour first statement is wildly and verifiably untrue (see: https://survey.stackoverflow.co/2025/technology#most-popular-technologies https://survey.stackoverflow.co/2025/technology#most-popular...) and your second statement doesn't make sense. I've got like 8 sites on Pages/Workers with R1 + vectorize databases scattered around and I'm not paying a dime for any of that. What cost are you talking about?
- steveharing1 6mo agoLately Cloudflare is trying to create alternatives to big ones, like first Vercel & now Wordpress.
- ValveFan6969 6mo ago[dead]
- kelvinjps10 6mo agoI don't like that they see the main selling point that the license, is not GPL, and that plugins don't have to license it that way either. I understand that not all developers are comfortable with the GPL license, but it allows to the code continue to be open source and that most plugins are open source also
- benatkin 6mo agoA big issue with WordPress is the GPL. There hasn't been much clarity about it and the interpretations I've heard from Automattic in regard to which code is and is not covered by the GPL come from Automattic, not from the GPL. https://redsweater.com/blog/825/getting-pretty-lonely https://redsweater.com/blog/825/getting-pretty-lonely
- rasso 6mo agoFor what it's worth: they live up to their own standards. Here, for example, is the source code that powers their VIP platform product: https://github.com/Automattic/vip-go-mu-plugins https://github.com/Automattic/vip-go-mu-plugins It must be open sourced because it's based on WordPress. I still love that.
- camillomiller 6mo agoLol, build the same level of community first, then we’ll talk
- eis 6mo agoAfter all the AI slop from Cloudflare in recent months and the embarrassment that came with it, they dare to launch this vibe coded project with THAT name on April 1st? I'm really not sure what to think anymore. Reality became too absurd.
- devmor 6mo agoYou want a spiritual successor? We have Ghost. You want anything beyond ghost? Find a way to port the vast market of 100,000+ cheap and free themes and components that are available to enable tech-illiterate, low-budget users to basically build an entire business platform on a $5/mo shared hosting plan. A vibe coded CMS that's 3 months in the making is not capable of taking that place in the market, no matter how much VC funding you put behind it.
- bluewavescrash 6mo agoCurious about the architectural choice: Why not build it as a pure headless CMS separate from Astro, and then ship an Astro adapter alongside it?
- t1234s 6mo agoI think wordpress, woo commerce and elementor are in a Mexican standoff. Wordpress cant fork or change in a major way because the other two are so popular no one would use the new variant. woo commercere and elementor can't just walk away and make their own wordpress-less platform because they rely on each other and the other constellation of plugins that run on wordpress.
- chuckadams 6mo agoWooCommerce is owned by the same company as Wordpress. Elementor is just one page builder of many in the vast ecosystem you mention, but much of that ecosystem can be ported. As replacing the core CMS goes, Emdash might be able to conquer, but time will tell as to whether it's able to rule.
- bornfreddy 6mo ago> But for the past two months our agents have been working on an even more ambitious project: rebuilding the WordPress open source project from the ground up. > no WordPress code was used to create EmDash Hm. Do you think those agents were trained on WP code?
- foopod 6mo agoAs a (unfortunately) wordpress dev this seems to solve my single biggest painpoint with WP. Which isn't plugin security, but the overall plugin architecture. WP treats plugins as content, literally in the same top level `wp-content` directory as uploaded images. This makes CI/CD among other things, a nightmare. But EmDash plugins are just TS modules, which has got to make things easier even if plugin configuration does end up in the db somewhere.
- bombcar 6mo agoWordpress has no concept of a "staging site" and no way to make changed and then "export" them from dev to production; you basically have to either restore it as a backup or just replay the changes by hand.
- donohoe 6mo agoHuh? That’s not how i think you should be approaching that. I always run local, staging, and production sites. It’s easy to setup and deploy across.
- bombcar 6mo agoHow do you deploy menu changes from staging to production?
- Y-bar 6mo agoI’m not the one you asked, but when I did WP work a few years ago I would solve it via a hook that was triggered on Jenkins deploy. The hook would always fire and listeners to that hook would execute migration scripts and similar callbacks. For example used it to migrate some tags to categories and vice versa. https://developer.wordpress.org/plugins/hooks/custom-hooks/ https://developer.wordpress.org/plugins/hooks/custom-hooks/
- donohoe 6mo agoAh. I understand your circumstances better. Short answer - I wouldn’t deploy menu changes. That’s usually low-lift that I would do it manually. If I was doing it in a recurring basis I would investigate creating a process to export the menu data and import directly using a custom plugin. Or create (via plugin) and endpoint to sync both environments (a bit more work). I did this one time before for a subset of pages and admin users. There are likely plugins that do this already but you could likely roll your own just for menus in an hour imho.
- capitanazo77 6mo agoName it CloudPress
- ymolodtsov 6mo agoIn my view, Astro is the most reasonable choice for a blog-like website these days. All the simplicity and all the capabilities that you need. Excited to check this out and see what they have added on top of it.
- earthlingdavey 6mo agoWhy not a templating language, like Nunjucks EJS or JSX, with vanilla JS for interactivity?
- ymolodtsov 6mo agoYou can use JSX in Astro if you prefer, but a CMS is more than just templates (not a LOT more I'd agree considering it's still static).
- earthlingdavey 6mo agoI know you can, but do blog-like sites really Island architecture? IMO most sites like that would be better to pick no-framework, vanilla or jQuery for interactivity. I can't image average WP users would be happy to move to EmDash, only to have a constant stream of dependabot updates for Astro. It has 55 direct (non-dev) dependencies https://www.npmjs.com/package/astro?activeTab=dependencies https://www.npmjs.com/package/astro?activeTab=dependencies - while ejs has 0 and nunjucks has 3. I'm weary of updates, maybe it's just me, but I doubt it.
- ymolodtsov 6mo agoAfter all these cases like axios it's definitely reasonable. But many people already use Astro. And with static website there are far fewer attack surfaces compared to a full-on PHP running WordPress on a VPS.
- CodeWriter23 6mo agoThe lede everyone is burying: "Every EmDash site has x402 support built in — charge for access to content"
- earthlingdavey 6mo agoThis is very interesting. I've worked with WordPress on and off for 10 years, and I'm convinced that this project has got 2 things absolutely spot on. TypeScript and Worker plugins. I've given the security, or lack of, WP a lot of thought recently. In WP malicious plugin has access to the database, enfironment variables, rendering text on screen (think XSS). Luckily, a thoughtfully designed plugin system can mitigate all of those issues. I've been working on a headless CMS in my spare time that is eirily similar to EmDash in a few ways. It's in very early development, but I will share regardless. It's called HotsauceCMS - https://github.com/hotsauce-team/hotsauce https://github.com/hotsauce-team/hotsauce - I went with optional NodeJS or Deno Worker plugins, this means that first-party plugins can benefit from the speed of in-process, and other plugins can be run in Workers. For fine grained permission control, you can use Deno Workers. - I went with absolute minimal dependencies, I am so fed up with Dependabot alerts and npm supply chain hacks. My CMS has only 4 dependencies, 0 transistive dependencies. - It's Drizzle schema first, and headless. So you have full controll of the database structure, use cms hints in your schema for features like file upload. - It's database-agnostic, so it works with any Drizzle-supported database (Postgres, MySQL, SQLite) - Being headless, you can use any frontend, my preference is JSX w/o react, but anything goes. Feedback is absolutely welcomed on HotsauceCMS, did I miss a trick, am I on the right track? Anyway, congratulations on EmDash. I'll be following closely, excited to see how the next few months unfold.
- mi_lk 6mo ago> I'm convinced that this project has got 2 things absolutely spot on. TypeScript and Worker plugins. Can you explain why TS is spot on?
- earthlingdavey 6mo agoThe main thing is unified types. - I've been done GraphQL server with a build step to share types between languages. - I've used untyped JS client side code. Both are prone to bugs, and not much fun. TS for front and back end: sharing types means you'll have editor type hints, catch type errors at lint (or build), and you might even share validation logic between client and browser.
- gbibas 6mo ago[dead]
- lucasay 6mo agoCool idea, especially the plugin security angle, but WordPress’s real strength is its ecosystem. That’s going to be hard to replicate.
- jaredcwhite 6mo agoNo thanks, I hate it. (To be clear, I'm no fan of WordPress either, and its security hassles are a real issue. But some sloppified MegaCorp vibecoded fever dream will never be a suitable replacement, of that I guarantee.)
- sublinear 6mo agoWhy?! Half the websites on wordpress moved to shopify, squarespace, etc. a very long time ago. The remaining half were blogs, personal pages, wikis, etc. that moved to community/social platforms created in the past decade(s). In a few cases out of all this someone finally learned how to write/host a webpage themselves (imagine that)! It's even easier with AI now. I'm totally serious when I ask "why". Who actually uses a CMS or anything like that anymore? It's madness!
- dminik 6mo agoI can't believe as developers we were worried about AI training on licensed code. It turns out it didn't matter at all. You can just point an LLM at some source code and you're off scot-free.
- hessammehr 6mo agoIne thing no other CMS tends to get right (for my needs) is Gutenberg. Tiptap, mantine etc.are just no substitute and for someone like me with next to no frontend knowledge Gutenberg was the only option that provided the flexibility and good defaults to keep a decent looking website that my students could also post on with no training. A while ago I ran claude code in a custom loop (calling it autoclaude; this was last summer) to create a CMS with Gutenberg’s editor but a lean Python backend (github.com/hessammehr/nuCMS). This was in the Sonnet 3.7 days and even that model got quite far.
- TacticalCoder 6mo agoThis reminds me of Linus Torvalds about Git, criticizing that SVN did present itself as "CVS done right" for... "It's impossible to get CVS right". Which I found incredibly funny and witty. Is the second coming of Wordpress what we really need?
- inklesspen 6mo agoSo it’s a WordPress successor that doesn’t support any WordPress plugins (since they’re written in PHP and this is written in TypeScript) and has baked-in support for blockchain payments. and also it’s “AI Native”, because the internet definitely needs more AI slop blogs. This IS an April Fools joke, whether or not they intended it to be one.
- mmaunder 6mo agoThe generous take is that this is someone's pet project that marketing got too excited about, and that the leadership haven't applied their minds to. GPL provides a moat for the community, who are contributing their time and energy into a project. It ensures that, even if a commercial company grabs your software, extends it, and commercializes it, that you can fold those improvements back into your original distribution. While the commercial entity benefits from your free labor, you benefit back from theirs. Re-implementing WordPress (their words, not mine) as MIT licensed, while legally questionable, breaks that virtuous cycle and removes the community's moat. They've taken WordPress's roles and menus and borrowed its Gutenberg code (which is GPL), and launched it as an MIT licensed product, which breaks that virtuous cycle. It means e.g. a hosting company can take the product closed source if they want to, and never have to contribute any of what they build on top of the community's work, back to the community. https://github.com/emdash-cms/emdash/tree/main/packages/core/README.md https://github.com/emdash-cms/emdash/tree/main/packages/core... says "The core EmDash CMS package - an Astro-native, agent-portable reimplementation of WordPress." Emdash uses WP's RBAC roles. Also uses their menus. Also depends on @wordpress/block-serialization-default-parser which I think might (??) be able to be used by an MIT project even though WordPress is GPL. They used Claude Code it seems because the first commit has a CLAUDE.md file which became an AGENTS.md.
- jeremie_strand 6mo ago[dead]
- midtake 6mo agoEmDash is a stupid name
- amanzi 6mo agoSo this is just a "similar" CMS to WordPress in that it has themes and plugins, and you can publish pages, posts, tags, categories, etc. But there are lots of similar CMS out there, and this one isn't "compatible" with WordPress since you obviously can't just take a WordPress theme or plugin and install it in your EmDash site. So I don't even know why the focus on WordPress here - this is just yet another CMS that offers similar features.
- alluro2 6mo agoWordPress is the most popular CMS, and, at any moment in time, especially lately, there are a lot of people looking for a "WP alternative". I agree that it's not actually compatible, but it seems they tried to make it similar just enough to be able to use the word without 100% lying and attract people that way.
- lupu 6mo agoNobody is looking for wp alternatives, if they were they would have moved long ago, as there are tens of similar CMS's that were supposed to be much "better" on paper yet never took of like octobercms,gravcms,ghost,netlify,wagtails,etc
- gnz11 6mo agoWagtail is fantastic. Pretty much the go to Python-based CMS to use these days.
- ajbourg 6mo agoI have long wanted a static blog with a backend content manager that runs serverless. Love seeing this, but we will see if Cloudflare maintains it in the long run.
- dirkc 6mo agoThe thing that has always stood out to me about WordPress, is that you can get a site up without any of the usual technical steps I associate with creating a site, but still have access to the innards of the site. Does it often go wrong, sure, but it is a lot more approachable for less technical users. In contrast, typical web frameworks (even static sites) require a code change, build, deploy, etc to update many aspects of a site.
- Venn1 6mo agoIf I could smash a button and get a 1:1 copy of my existing site, I’d do it in a heartbeat. I don’t see that happening just yet due to the integrated forum software and its own plugins. With Cloudflare behind it, hopefully plugin vendors will start paying attention.
- mmaunder 6mo agoIf creating OSS is this low effort, the right question is: What high effort assets, that are valuable to other builders, should open communities be working on? And I think the answer is open source models with open training and open training data.
- aetherspawn 6mo agoThis is really buggy and janky… try it in mobile, the navigation doesn’t even work. UX elements move around the place when you hover or click them.
- deleted 6mo ago[deleted]
- crabmusket 6mo agoDoes it bother anyone else that the capability tags in their example seem to follow different noun:verb conventions? capabilities: ["read:content", "email:send"],
- lioeters 6mo agoNow that you mention it.. List of capabilities: read:content write:content read:media write:media network:fetch read:users email:send email:provide email:intercept Also: > ### Trusted Mode > Trusted plugins are npm packages or local files added in `astro.config.mjs`. They run in-process with your Astro site. > - *Capabilities are documentation only.* Declaring `["read:content"]` documents intent but isn't enforced — the plugin has full process access. > - Only install from sources you trust. A malicious trusted plugin has the same access as your application code.
- rcarr 6mo agoIn my opinion, Cloudflare are coming at this from the wrong angle. WordPress is so popular because back in the day it was the easiest way to get a website built. So it got a network effect of engineers behind it which is why it persists at 40% of websites today. Same thing happened with React - majority of Typescript sites are written in React and NextJS because of the network effect around it. Yeah the security aspect is important, but how many of those Wordpress engineers are going to jump ship to this because of security when they've been fine with the risk so far? My money is not a lot. If someone is a WordPress dev in 2026, they're probably not the type of dev that likes to upskill and learn new tech. Similarly, if you're looking to target the average joe looking to build a fresh website, would that consumer really choose this over Wix or Squarespace? It doesn't look easier to use so I wouldn't count on it. So where is the network effect going to come from to make this the new WordPress? I could see Vinext being successful if they keep at it— I think there are a sizeable amount of people who would like to move away from Vercel (and who will probably migrate to Tanstack when the ecosystem is more stable). But I'm not sure people on WordPress really want to leave. If they really want to make this successful I think they need a better angle which in my opinion would be making it easier, quicker, cheaper and more flexible than Squarespace/Wix/Shopify etc
- donohoe 6mo agoWordpress has an amazing talent pool of experienced people. EmDash is starting from zero - but you have to start somewhere! I’m very happy with WP, but I’ll be cheering on EmDash if it gets momentum.
- ValentineC 6mo agoWordPress lost a lot of "experienced people" in the last two years, after Matt Mullenweg decided to wage war on WP Engine.
- donohoe 6mo agoI really do not know how true that is - or to what extent it matters.
- jeremie_strand 6mo ago[dead]
- dzonga 6mo agothis won't go far base platform used - typescript - means for the average Joe out there - deploying is difficult - compared to php. if they really wanted to be revolutionary - they would've made a single PHP script either on FrankenPHP backed by sqlite - single file deploy - with yeah a permission model Ala denojs for the security aspects. end of day this is vibeslop.
- wei03288 6mo ago[dead]
- momojo 6mo agoA quote from their nextjs writeup but I like: > Most abstractions in software exist because humans need help...It's not clear yet which abstractions are truly foundational and which ones were just crutches for human cognition... We took an API contract, a build tool, and an AI model, and the AI wrote everything in between.
- deleted 6mo ago[deleted]
- bengt_trustpay 6mo ago[flagged]
- smetannik 6mo agoIMO unlike WP, EmDash can he harder to host. With WP you can find a plethora of cheap PHP hostings that offer WP preinstalled. If you need to tweak a theme - just download a .php file via FTP, tweak it and upload back. No server management or restart is required. One big potential benefit that EmDash has - every WP deployment is basically a honeypot.
- deleted 6mo ago[deleted]
- ValidateKorea 6mo agoThe plugin security model in WordPress has been the elephant in the room for years. Any plugin can execute arbitrary PHP — there's no sandboxing, no permission system, nothing. It's wild that we accepted this for so long. The Cloudflare Workers approach (V8 isolates) is fundamentally better because it enforces boundaries at the runtime level rather than relying on developer goodwill. Curious to see how they handle the migration path for existing WP sites though — that's where projects like this usually die.
- j45 6mo agoThis looks nice. Can a successor for Wordpres shave some amount or type of import, conversion, or backwards compatibility? Can there. ba way to tie in wordpress plugins or their functionality through a secure interface/translation layer? Adoption for new projects is one thing, migration is another. There's some cms that pretty much build in some core amount of main plugins right into the core cms.
- cloudfixer_dev 6mo ago[dead]
- jeremie_strand 6mo ago[dead]
- ahhhhnoooo 6mo agoDo you think the Wordpress guy is going to have more public meltdowns on this post?
- mgkimsal 6mo agoTangential rant about WP. Having got back in to some WP in the last year, the big thing that struck me compared to other framework/environments is... no... build step, or even plugin/module install step. Files are just there in the document root, accessible by default - the logic files are invokable and the asset files are reachable. Most other php frameworks will install a plugin/module outside the document root then have some sort of publish/install step that will copy assets to be publicly accessible as needed. No plugin logic files would be invokable directly from a URL. That one change would make a big difference, imo, but seeing so much of the last 15-20 years of WP involves helper functions to assumed paths, and default assumptions about assets and logic living in the same paths... I'm not sure the ecosystem could adapt or support an alternative approach at this stage. Might be wrong. It's taken me a while to put my finger on why the current situation encourages less-secure-by-default systems, and this is probably the biggest thing I've landed on. There are other issues, but these issues all help contribute to WP popularity in the first place...
- cutler 6mo agoDefault EmDash size: 483Mb. Default WordPress size: 70Mb. That's progress?
- timedude 6mo agoIt is in the present AI climate
- SoftTalker 6mo agoThey say it was developed by AI agents but they still claim copyright in the LICENSE file. Doesn't seem right.
- thedevilslawyer 6mo agoI mean the creator of the commit takes authorship, just like the auto-complete in old style IDE. Using agents requires a skill, that varies from vibe to advanced. Why do you feel it's not right?
- SoftTalker 6mo agoThe output of LLMs doesn't qualify for copyright protection. There is no human author here.
- bzmrgonz 6mo agoWelp, it looks like if you selfhost, the sandboxing of plugins benefit goes out thr window from what I'm reading. What kind of open source is that? Opencore? More like openinsecure, for thr security version, pay the Piper. I might still give it a try, but I sure hope we can put monthly monetary ceiling, had ceilings on our accounts. Anyone knows if cost-caps are possible on CLOUDFLARE??
- bzmrgonz 6mo agoAlso, it looks like there are egress charges to download R2 object storage. So he day we choose to exit stage left, we will be taxed. Wanna setup independent backups for compliance, we will get taxed on egress. Am I reading this right guys??
- psz 6mo agoYou read it wrong. Egress from R2 is free. https://developers.cloudflare.com/r2/pricing/ https://developers.cloudflare.com/r2/pricing/
- Tepix 6mo agoUnless someone adds this feature, this is completely uninteresting to me, as well as dishonestly presented by Cloudflare.
- mpeg 6mo agoHonestly, you'll struggle to find a cloud platform cheaper than cloudflare. The $5/mo gets you 10 million dynamic requests (static assets are not included in this limit, so often a single pageview will be 1 dynamic request) and that would be across the whole workers product for your account, no extra pricing for extra websites, domains, or anything else like you'd see in most "wordpress hosting" I run all my personal sites and client sites (one of them for a fortune 500 company) in the $5/mo plan, and the only time I went over that was when a client got hammered with malicious requests (and it was like $100) Disclaimer: I have no relationship to cloudflare, I'm just a happy customer
- 6mo ago
- tim-projects 6mo agoI predict that almost no existing WordPress installs will be ported to this
- born-jre 6mo agoi have been a admirer of wordpress plugin system and had been shouting for modern alternative with explicit capability model for sometime. I also have been building own composable app platform (not cms) and this looks kinda great actually. https://github.com/blue-monads/potatoverse https://github.com/blue-monads/potatoverse
- jenadine 6mo agoWouldn't a spiritual successor use the same kind of license? (GPL)
- Nick_Finney 6mo ago[flagged]
- ori_b 6mo ago> no WordPress code was used to create EmDash. Oh, neat. Which model wasn't trained on WordPress?
- cutler 6mo agoTypescript, isolates, Cloudflare dynamic workers, serverless. You've already lost the market WordPress serves.
- p4cmanus3r 6mo agoThis is naive thinking you can just rewrite WordPress and think it's going to solve any problems that exist with WordPress. The entire community of WordPress has been built over decades including its successes and failures, but people are not going to just stop using WordPress as I have seen people attempt this over and over in the last 20 years with little success.
- sixhobbits 6mo agoIsn't it kinda bad taste to call your thing a "spiritual successor" to something that is very much alive? I'd usually expect this to be used about something like Google Reader, not something you are actively competing with.
- lupu 6mo agoSo this product has nothing to do with wordpress, it's just another CMS that mentioned WP only bcz they created a migration plugin that won't work on 90% of existing wp sites and won't work on 100% of woocommerce sites. This is no successor, it's not even in the same universe. - vendor lock-in, losing gpl, losing access to plugins source code, loosing ownership.
- slotted-dotted 6mo agoIt's licensed under MIT. It's more permissive than wordpress.
- epse 6mo agoThat is not a pure upgrade, GPL may well be the "better" / safer / trusted /... option for some
- manacit 6mo agoYou're welcome to take an MIT-licensed project, fork it, and relicense it as GPL. The inverse? not so much. Hard to sell it as anything but an upgrade if you care about open source.
- georgyo 6mo agoThe thread here doesn't explain why GPL might be better. So I'll try. You're correct, with MIT there are a lot less restrictions. I can make GPL or pretty much any other license. Including one that I sell and never have to release the source of. The latter option means if you make a product off of it, you have no obligation to share or even fund upstream development. This kind of situation has strangled other products. Consider if Linux was released under MIT. Then companies like Oracle and RedHat (now owned by IBM) who have strong incentives to keep improvements to themselves and fund a lot of development would never share those improvements. Linux is the most used operating system in the world because of _everyone_ contributing back. But a MBA would want to privitize the profits. If you care about the long term openness of a product, then GPL is hard to beat.
- p0w3n3d 6mo agoI used to host a wordpress on my server for some people who configured it. However, when some bots got there, I was unable to keep them at bay. I upgraded WP's version, but the Wordpress had some vulnerable plugin, and I was unable to find out what path did the attack go. I only could find that the malicious files were uploaded into images/ directory and run from there. That's something I blame PHP for (and of course my lousy LAMP configuration skill, but the directory was not allowed to run the code from, I must impress). I tried also to block IPs attacking my server, but this was like cutting one of the hydra's heads. So, long story short I ended up removing write permission to all the folders, thus disabling upload, and later they went to another server. They host it fine there, I still maintain redirection from the main domain to their host. However I failed, but really this is sad the WP is so vulnerable just by the plugins installation. Since then I am looking for WP replacement that would not mix up the code and the images from the upload directory (presumably in rust or golang), but this would need to be opensource anyways.
- karel-3d 6mo agoI am not fluent in Cloudflare-lingo. What is "Dynamic Worker" and how can I run it outside Cloudflare? The repo says "depends on Dynamic Workers ... Dynamic Workers are currently only available on paid accounts" but the article says "but you can run it on your own hardware".
- VerifiedReports 6mo agoplug-in security
- aservus 6mo agoSecurity by reducing attack surface is underrated as a design philosophy. We took a similar approach for a PDF tool — moved processing client-side entirely so there's no server to compromise in the first place.
- whh 6mo agoAn edge-first CMS is cool. I've wanted something that works well alongside Astro for ages. That said, WordPress is a weird paradigm to be replicating in 2026. WP won on extensibility, but the actual legacy of that ecosystem is bloat, security disasters and dogshit performance. What I think makes more sense is this kind of edge backend paired with a proper modern authoring experience with visual control like Framer/Webflow with Notion-style database primitives underneath. And given how fast AI is getting at generating bespoke business logic, building another monolithic plugin ecosystem feels like solving the wrong problem. Plugins were a workaround for the fact that most people couldn't write code. That's increasingly not true.
- JoostBoer 6mo ago[dead]
- JoostBoer 6mo agoI run a handful of WordPress sites. The plugin problem is real. I've spent more time managing plugin updates, conflicts, and security patches than actually building content for the sites. But the reason I'm still on WordPress isn't loyalty. It's that my clients can maintain their own sites without me. A small business owner updates their own pages, adds blog posts, changes a phone number. No developer needed. That's not a feature of WordPress. That IS the product. EmDash solves a developer problem (sandboxed plugins, TypeScript, Workers) by building a developer product. Nothing wrong with that. But calling it a WordPress successor misses why WordPress won in the first place. It wasn't the code quality. It was the guy who runs a bakery being able to edit his own website on a Sunday morning.
- ulrischa 6mo agoIt is written in typescript not php - so not a successor of WordPress. Typescript is a complete other Story. With compile step and build Pipeline. All not necessary in php
- progx 6mo agoCompile step? Your knowledge is outdated.
- Growtika 6mo agoI have a love/hate relationship with WordPress. I prefer it over any other CMS for reasons I can't fully explain. Probably nostalgia. I love the editor, the sidebar, the ability to find niche plugins in an endless marketplace, and how easy it is to get a site running. What I don't love is how insecure it is. You're entirely dependent on plugins (if you're not a developer), and if WordPress updates and a plugin goes inactive, you're sitting on a vulnerability. It adds real stress for something that's just supposed to be a fun personal site. I stopped building on it two years ago, even though I still like it more than Webflow and most alternatives I've tried. It's a bit sad.
- _davidchambers 6mo agoFrom the readme on GitHub: > A full-stack TypeScript CMS built on Astro and Cloudflare. EmDash takes the ideas that made WordPress dominant -- extensibility, admin UX, a plugin ecosystem -- and rebuilds them on serverless, type-safe foundations. Someone should introduce the authors to the lovely em dash character. It's perfect for such sentences!
- brvn 6mo agothis is how they used to teach people to type on typewriters — don't see it that often these days
- CodeCompost 6mo agoThe cost of building software has drastically decreased. The arrogance of this statement is staggering.
- znpy 6mo agoIt is true though. We have a cursor subscription and work and i now see many non-technical people building their own internal tooling. People that had essentially never written a line of code before this new revolution. The cost of building software has really drastically decreased.
- DevCrate 6mo ago[dead]
- aiedwardyi 6mo ago[dead]
- petterroea 6mo agoI can't help but sense a level of arrogance when they launch their product by writing an obituary for a competitor. Is this what people feel when they make fun of the "(product here) killer"?
- QuantumNomad_ 6mo agoThe Deploy to Cloudflare button in the article is not working for me. It takes me to the expected Cloudflare dashboard page, with title “Clone a repository” and with the GitHub repository URL field filled with https://github.com/emdash-cms/templates/tree/main/blog-cloudflare https://github.com/emdash-cms/templates/tree/main/blog-cloud... but when I click Continue, the Continue button changes to “…” and animates indicating it’s thinking, but then nothing happens. No error messages shown, nothing. The Continue button switches back to having the Continue text and being clickable. I tried deleting a couple of old applications I had in the Workers & Pages page of the Cloudflare dashboard thinking that maybe I had exhausted the number of such applications I can have on a free Cloudflare account. The number of applications I have is now down to 7, after deleting a couple of old ones. Still, attempting to deploy EmDash to my Cloudflare account fails in the same way as before without any error messages shown. I was using Safari on iOS 18.7.1. I will try on a desktop browser, in case the problem is only happening in Safari on iOS.
- radicalriddler 6mo agoYeah, I had this happen the other day with their Moltworker. Another one of their products which was “just an experiment” Cloudflare annoys me as a company.
- vishalmeenaa 6mo agoSounds great. How developers can publish their plugins on EmDash?
- vishalmeenaa 6mo agoSounds great. How can developers publish their plugins on EmDash plugin marketplace? Where we can see guidelines for that?
- znpy 6mo agoWhat if I want to run EmDash on my own infrastructure? Is there a way to run EmDash plugins outside cloudflare's Dynamic Workers ?
- grougnax 6mo agoThis has nothing to do with Wordpress
- _cenw 6mo agoAfter the last time Cloudflare released some vibecoded crap that wasn't what they said it was (this happened more than once, but the last one was Matrix), my interest to engage with this was near zero. The name did the rest. Fuck this entire fucking industry.
- jeninho 6mo ago[dead]
- codewithveek 6mo ago[dead]
- kunley 6mo ago"..aims to be compatible with WordPress functionality" What does it mean, to be "compatible with functionality"? At a first glance this statement promises a lot, but does it really mean anything technically?
- jacton81 6mo agoI like the where this is going. The plugins are always the biggest threat. The biggest hurdle will be adoption with all other platforms. One reason WP is still the most used is because all other services you'd ever want to integrate with offer some sort of plugin or integration with WP. Also, so many people use it you know there will always be someone to assist if needed.
- intensifier 6mo agoDoesn't even render properly in not-so-old browsers where WordPress renders fine.
- gloosx 6mo agoAt least the cost of building slopware has drastically decreased.
- Nick_Finney 6mo ago[flagged]
- k3vinw 6mo agoThanks for sharing this on GitHub. Nice to see how others are using AI in their projects.
- wiradikusuma 6mo ago"We think of it as the spiritual successor to WordPress. It’s written entirely in TypeScript" — A major reason why WP is popular is that it's PHP-based and works with shared hosting. Will EmDash work with shared hosting?
- pettycashstash2 6mo agoPlayed with this for 30 minutes. looks promising, and of course its rough around the edges. im sure you're working on it, but could not figure out how to add section to page.
- kmeisthax 6mo agoI like the idea of sandboxing plugins, but I don't like the move away from GPL, and I would rather not junk PHP just to get isolates. PHP is one of WordPress's advantages: it runs on basically any web host, you have no edit-compile-debug loop to worry about, and all state is temporary by default. Switching to JavaScript means we have a persistent process that has to be rebooted, and we're now married to single-threaded event loops and async/await syntax, which leaks[0] into everything. Additionally, as others have already mentioned, the best security would be no dynamic code at all, just static pages generated by Jekyll. This should have been a Jekyll frontend, IMO. >And because WordPress plugins run in the same execution context as WordPress itself and are so deeply intertwined with WordPress code, some argue they must carry forward WordPress’ GPL license. That is a feature, not a bug. I already have to debug broken or poorly-documented WordPress plugins as-is, my job would be 100x harder if those plugins were proprietary and forbade inspection of the code. Furthermore, while the GPL forbids locking down plugins to charge a licensing premium, it does not forbid charging money in general. While in theory you can legally pirate paid WordPress plugins (it's called "nulling"), in practice few do this because it's an obvious and blatant security risk[1]. Paid plugin authors are selling support and software assurance that has real value. Also, I must take umbrage with the legal hedging. "Some argue"? Like, the GPL is strategically ambiguous with regards to the definition of a "Program"[2], but it'd be very hard to write a useful WordPress plugin that does not become part of the same Program. [0] This is predominantly a fault of JavaScript, which has no threading story and is designed to fit in a foreign event loop. In Rust, async code can spawn and await real threads to hold blocking code, and sequential code can host its own event loop to run async in. [1] Especially if you were to, say, name your nulled version "Secure Custom Fields". Nobody would EVER do that, right? [2] No, proprietary Linux modules don't count. Linux has a userspace syscall exception that defangs the GPL, so it's perfectly possible to write kernel-mode code that only touches syscall equivalents.
- deleted 6mo ago[deleted]
- givan 6mo agoMost WordPress plugin vulnerabilities would not exist if Wordpress would expose only a public folder to the web without including `wp-content/plugins/`. This would avoid plugin scanning and direct plugin code execution. For the CMS I'm developing, Vvveb CMS, no plugin code is exposed, everything passes through the only exposed php file `public/index.php`
- tonymet 6mo agoReminds me of smartphone vendors declaring “iPhone killer” only to fade away. Premature to declare EmDash the successor . A competitor , maybe. Like SVN , and Perl 6, a better version of something popular is still bad . They fix many of the hosting concerns , but it’s way too complex, and lacks wordpresses biggest selling points. People will be vibecoding Wordpress templates and sites for another 15 years
- joeyoungblood 6mo agoWithout a theme marketplace and possibly a plugin marketplace, this is just another open source CMS. However, since it is MIT licensed perhaps someone out there will build upon this and make an actual spiritual success to WordPress.
- jeninho 6mo ago[dead]
- ksec 6mo agoWordpress powers 40%+ of the web, the second largest CMS is Shopify. [1] I have been on and off in the past 6 - 7 years trying to get DHH / 37Signals to release a CMS / simply blog system that compete with Wordpress. May be Shopify should do it instead, and name it Pressify. [1] https://w3techs.com/technologies/overview/content_management https://w3techs.com/technologies/overview/content_management
- milliephanillie 6mo agoAll i heard in this article is that PHP is bad and yeah you can run Emdash anywhere but really you can't because we are so good.
- mikey_l3verage 6mo agoLmao. Well played. Typical Cloudflare. That said - I think you can ostensibly run it on any backend API. Idk what a "dynamic" worker is. But I know Astro handles routing and all the 'workers" really have to do is connected backend to DB.
- deleted 6mo ago[deleted]