WordPress share of sites with a detected platform (Tranco top-10,000): 719 of 2,491 (28.9%) (Source: WebPulse scan of Tranco top-10,000 domains (September 2026))
The plugin question is changing shape
Every CMS plugin is code your organisation did not write, running next to content and customer data. The usual defence is trust: in the author, in the marketplace, in the next update. Cloudflare's EmDash offers sandboxed plugins built on a different premise. In Cloudflare's design, the question narrows from whether you trust the author to what you approved the code to do. Trust does not vanish, since approving access to content still means trusting the plugin with that content, but it becomes specific and reviewable.
Cloudflare released EmDash 1.0 on September 28, 2026, describing it as a stable, free, open source CMS built on Astro under the MIT license. It was introduced on April 1 as a "spiritual successor to WordPress." Alongside 1.0, Cloudflare is launching a decentralized plugin registry. Everything below is Cloudflare's description of its own design, not independent testing.
Two models of trust
Cloudflare's account of WordPress is that a plugin executes alongside the core application in a single PHP process. It can therefore reach whatever the core can reach: the database, the files on disk and outbound connections. Cloudflare's example is a contact-form plugin that could, in principle, read unpublished posts. Whether it does is left to the owner's confidence in the author, both today and after every later release.
EmDash offers sandboxed plugins instead. According to Cloudflare, a sandboxed plugin starts with a private storage area and nothing else. Anything beyond that, such as reading content or contacting outside services, requires the plugin to ask and the site administrator to agree. Before any code executes, the administrator is shown the list of abilities the plugin has requested. Cloudflare adds that each ability is granted separately, so approving media access does not open up users, and that the runtime enforces the limits, "not left to the plugin author's good intentions." On Node.js, Cloudflare says EmDash starts workerd as a separate process to hold each plugin.
Cloudflare draws its contrast with WordPress's plugin model. In WebPulse's sample, WordPress was detected on 719 of the 2,491 sites where any platform was identified. That shows how widely WordPress was detected, not how many of those sites run plugins or how they are configured. It does not measure EmDash adoption or how either model performs.
The registry moves the keys, not just the catalog
Cloudflare's critique of conventional registries is concentration. One operator holds the publisher's login, the official copy of each package and the shop window. If that operator suspends an account, delists a plugin or shuts down, Cloudflare says publishers cannot carry their identity and release history elsewhere. EmDash's registry is built on AT Protocol, and publishers sign their own package and release records, which live in the publisher's account rather than in the catalog.
Cloudflare says EmDash can verify a release record independently instead of relying on the catalog's copy. The installer then tests the downloaded bundle against that signed record. It looks at the checksum, the name and version, the access being requested, and build provenance where it is required. On moderation, Cloudflare says the catalog's controls affect only what the catalog displays. The release and the underlying publication stay as published.
For a budget-holder, this cuts two ways. By Cloudflare's account, publishers keep their identity and release history if a marketplace changes its rules. But Cloudflare also says no central controller can remove plugins on a whim. Our reading is that removing a plugin already installed on your site then becomes a decision for whoever administers it. That is a governance choice, and it needs a named owner.
Why agents raise the stakes on the approval step
Cloudflare's point about agents is that a plugin packages the effort of building, testing and maintaining an integration, so a second agent can adopt the finished result rather than repeat the work. If agents increasingly assemble sites this way, the approval screen becomes the control point. A permission prompt reviewed by a person is a safeguard. One approved by habit is not. This is our reading, not a finding from the announcement.
Cloudflare's own example shows the human side. Avulux moved a custom microsite from WordPress, and Greg Barbosa, its Director of Innovation and Systems, said the site had to be "fast to use and simple for our team to update." Cloudflare says the move took less than a day using EmDash Agent Skills. Editors carry the daily cost of a CMS, and they are also the people affected when an extension misbehaves.
What the release does not settle
This is a single vendor release with self-reported design claims. Cloudflare's description covers sandboxed plugins specifically, and this piece does not assume every EmDash plugin uses that model. A permission model is only as strong as the review at the approval step. Cloudflare says the registry supports free plugins today and that paid plugins are an aim, not a shipped feature.
On project maturity, Cloudflare reports the following contributor activity. It is the vendor's own count of participation, not a measure of security or of the sandbox's effectiveness.
Treat EmDash as one data point on where plugin trust could go, not as evidence that the industry has moved.
Questions to put to your team
1. For each plugin on our CMS today, can it read unpublished content, users or secrets, and who decided that?
2. Whatever extension model we use, does the administrator see requested access before install, and who signs off?
3. If an update changes what a plugin requests, does anyone review it before it runs?
4. Who can remove or pin a plugin that is already installed, and how fast?
5. If agents will install extensions for us, which approvals stay with a named person?
A plugin permission is only a control if someone reads it.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Cloudflare.





