Cloudflare releases EmDash 1.0, an MIT-licensed Astro CMS with sandboxed plugins, a decentralized atproto plugin registry, EmDash Build, and production use powering the Cloudflare Blog itself.
When we introduced EmDash on April 1 as the “spiritual successor to WordPress”, the buzz was hard to ignore. But alongside the excitement was a seed of doubt: Was this just an April Fools’ joke?
It was not. Today, we are releasing EmDash 1.0: a stable, free, and open source CMS built on Astro, ready to power a production website, your agency’s vibe-coding platform, or your hosting company’s site-building experience.
Developers build with Astro, editors manage content through the EmDash admin, and agents can work through the API, CLI, or built-in MCP server. EmDash 1.0 brings those pieces together with production-tested editorial, media, localization, migration, and deployment workflows.
We are also launching a decentralized plugin registry that lets developers publish without handing ownership of their identity or releases to a central marketplace, while site owners can discover and install plugins from inside EmDash.
The road to 1.0
Since EmDash's first beta, developers have launched real websites with it. EmDash 1.0 is our answer to teams who wanted confidence that upgrades would protect their content and that we are committed to maintaining it.
In August, we migrated the Cloudflare Blog to EmDash as part of our “Customer Zero” approach. Comfortably handling millions of pageviews per week and spikes up to 5,000 RPS shaped optional KV object caching, the Hyperdrive database adapter, and Workers Cache compatibility—now available to all customers.
Built in public, open to everyone
EmDash is completely free and open source under the MIT license. More than 175 people have contributed across more than 1,800 commits. Contributors have translated EmDash into 25 languages. Particular recognition is due to Noah Pham, who joined as an intern and became EmDash’s second maintainer alongside Matt.
A plugin registry that does not own the ecosystem
Traditional plugin registries usually combine three roles: publisher account, authoritative package record, and discovery catalog. EmDash separates the plugin from the catalog. Publishers retain control of packages and release history.
The registry is built on AT Protocol (atproto). Plugin authors publish with an Atmosphere account; package and release records are signed by the publisher and stored in the publisher's own account. EmDash can verify records independently via signed Merkle Search Trees, then check checksum, package name, version, requested access, and build provenance.
Plugins with clear boundaries
Sandboxed EmDash plugins run in an isolated runtime with access to their own private storage only. They gain additional abilities only when declared by the plugin and approved by the site administrator. On Cloudflare, each plugin runs as a Dynamic Worker through the Worker Loader; on Node.js, EmDash starts workerd as a separate process.
EmDash Build
We are also releasing an alpha of EmDash Build, an open-source AI site builder that hosting providers can run themselves. Try the demo at build.emdashcms.com.
Get started
npm create emdash@latest
Join the EmDash community on Discord, or explore the plugin development docs.