EmDash, the open-source content management system Cloudflare introduced in April as a "spiritual successor to WordPress," reached version 1.0 on September 28, 2026. Cloudflare is calling it stable and ready for production sites.

Disclosure: AEO Sherpa is built on EmDash and hosted on Cloudflare.

What EmDash is

EmDash is a full CMS that runs inside an Astro website. Developers build pages in Astro, editors work in the EmDash admin, and AI agents can work through its API, command-line tool, or built-in MCP server. It is free and MIT-licensed. Cloudflare says more than 175 people have contributed across more than 1,800 commits, and the admin has been translated into 25 languages.

In August, Cloudflare moved its own blog onto EmDash. The company says that migration required handling millions of pageviews a week and spikes of up to 5,000 requests per second, and it produced several features now available to everyone, including KV object caching and compatibility with Workers Cache.

A plugin registry built on AT Protocol

The biggest change in 1.0 is the plugin registry. Traditional registries combine three roles in one company: publisher accounts, the official package record, and the catalog. If the company changes its rules or suspends an account, the developer has nowhere to take their identity or release history.

EmDash's registry runs on AT Protocol, the decentralized network behind Bluesky. Plugin authors publish from their own account, sign their releases, and keep them in their own repository. EmDash runs a default catalog that indexes those releases and applies moderation to what it displays, but moderation cannot rewrite a release or take ownership of a plugin. Anyone can run another catalog, and Cloudflare has open-sourced its aggregator and labeler services.

Plugins with permissions, like mobile apps

The security model is the practical news for site owners. In WordPress, a plugin runs in the same process as everything else and can read the database, files, and network. In EmDash, each sandboxed plugin runs in isolation and can access only its own storage until the site owner approves specific abilities, such as reading published content or contacting one named service.

On Cloudflare, each plugin runs as a Dynamic Worker. On Node.js, EmDash runs plugins inside workerd, the open-source Workers runtime, so the same permissions apply on either platform.

Why it matters for AI search

Publishing tools shape how content reaches answer engines. Three features in EmDash are aimed squarely at that:

  • Agent access is built in. A site's content model is available to agents through MCP, so an assistant can draft, update, and schedule content with the same permissions as a human editor.
  • Structured content by default. Content is stored as structured data rather than HTML, which makes it easier to render clean pages, feeds, and machine-readable files.
  • Search plugins with narrow access. A plugin that indexes articles for AI search can be given read access to published content and one outbound host, and nothing else.

Cloudflare also released an alpha of EmDash Build, an open-source AI site builder that creates a full EmDash site from a prompt.

Free newsletter

The Sherpa Brief

One email a week on what changed in AI search, what it means, and what to do about it. Written for marketers, SEOs, and publishers.

Free. Unsubscribe in one click.