---
title: "EmDash 1.0: the stable CMS with a secure plugin registry"
slug: emdash-1-0-the-stable-cms-with-a-secure-plugin-registry
url: https://listedarticles.com/articles/emdash-1-0-the-stable-cms-with-a-secure-plugin-registry
canonical_url: https://blog.cloudflare.com/emdash-cms-plugin-registry/
content_type: announcement
language: en
published_at: 2026-09-28T12:00:00.000Z
updated_at: 2026-09-29T00:09:50.630Z
author: "Scott Buscemi, Matt Kane, and Noah Pham"
authored_by: human
publisher: "Cloudflare"
publisher_url: https://blog.cloudflare.com/
topics: ["Open Source", "Web Development", "Developer Tools", "AI Agents", "Infrastructure"]
license: all-rights-reserved
word_count: 479
reading_minutes: 2
citation: "Scott Buscemi, Matt Kane, and Noah Pham, Cloudflare. \"EmDash 1.0: the stable CMS with a secure plugin registry.\" 28 Sept 2026. https://blog.cloudflare.com/emdash-cms-plugin-registry/ (all-rights-reserved)"
# The full text follows. The web page shows an extract and sends readers
# to the source above; quote the citation and link the canonical URL.
---

# EmDash 1.0: the stable CMS with a secure plugin registry

> Cloudflare releases EmDash 1.0, an MIT-licensed Astro CMS with sandboxed plugins, a decentralized atproto plugin registry, EmDash Build, and production use powering the Cloudflare Blog itself.

When we introduced EmDash on April 1 as the “spiritual successor to WordPress”, the buzz was hard to ignore. But alongside the excitement was a seed of doubt: Was this just an April Fools’ joke?

It was not. Today, we are releasing **EmDash 1.0**: a stable, free, and open source CMS built on Astro, ready to power a production website, your agency’s vibe-coding platform, or your hosting company’s site-building experience.

Developers build with Astro, editors manage content through the EmDash admin, and agents can work through the API, CLI, or built-in MCP server. EmDash 1.0 brings those pieces together with production-tested editorial, media, localization, migration, and deployment workflows.

We are also launching a **decentralized plugin registry** that lets developers publish without handing ownership of their identity or releases to a central marketplace, while site owners can discover and install plugins from inside EmDash.

## The road to 1.0

Since EmDash's first beta, developers have launched real websites with it. EmDash 1.0 is our answer to teams who wanted confidence that upgrades would protect their content and that we are committed to maintaining it.

In August, we migrated the Cloudflare Blog to EmDash as part of our “Customer Zero” approach. Comfortably handling millions of pageviews per week and spikes up to 5,000 RPS shaped optional KV object caching, the Hyperdrive database adapter, and Workers Cache compatibility—now available to all customers.

## Built in public, open to everyone

EmDash is completely free and open source under the MIT license. More than 175 people have contributed across more than 1,800 commits. Contributors have translated EmDash into 25 languages. Particular recognition is due to Noah Pham, who joined as an intern and became EmDash’s second maintainer alongside Matt.

## A plugin registry that does not own the ecosystem

Traditional plugin registries usually combine three roles: publisher account, authoritative package record, and discovery catalog. EmDash separates the plugin from the catalog. Publishers retain control of packages and release history.

The registry is built on **AT Protocol (atproto)**. Plugin authors publish with an Atmosphere account; package and release records are signed by the publisher and stored in the publisher's own account. EmDash can verify records independently via signed Merkle Search Trees, then check checksum, package name, version, requested access, and build provenance.

## Plugins with clear boundaries

Sandboxed EmDash plugins run in an isolated runtime with access to their own private storage only. They gain additional abilities only when declared by the plugin and approved by the site administrator. On Cloudflare, each plugin runs as a Dynamic Worker through the Worker Loader; on Node.js, EmDash starts workerd as a separate process.

## EmDash Build

We are also releasing an alpha of **EmDash Build**, an open-source AI site builder that hosting providers can run themselves. Try the demo at build.emdashcms.com.

## Get started

```
npm create emdash@latest
```

Join the EmDash community on Discord, or explore the plugin development docs.
