EmDash 1.0: an open source CMS for Astro
Announcing EmDash 1.0, a stable, free and open source CMS built on Astro.
Today we are releasing EmDash 1.0, a stable, free and open source CMS built on Astro. Proven in production, it is ready for everything from your personal blog to the biggest production sites. It is delightful for human editors and developers, and is also the best CMS for AI agents.
Why we built EmDash
EmDash started with a question: what would WordPress look like if it were built today. In some ways it would feel similar, but in others it would be unrecognisable.
WordPress powers over 40% of the web. It has been a publishing powerhouse for over 20 years because it does several things really well. It is super easy to get started, and almost anyone can edit a WordPress site. It also has an incredible ecosystem of plugins and themes. These are things that most newer CMSs don’t handle, but EmDash took as its top priority from day one.
Web hosting has changed almost beyond recognition in the two decades since WordPress launched. When it was born, AWS EC2 didn’t exist. In the intervening years, that task has gone from renting virtual private servers, to uploading a bundle bundle to a globally distributed network at virtually no cost. EmDash brings easy, cost-effective and massively scalable hosting support to CMS developers. EmDash can be deployed for free to Cloudflare, and scales to massive traffic without needing to deploy new servers. There is no lock-in, because all features work anywhere that you can deploy Node.js apps.
We chose to build EmDash on top of Astro, because it is the best framework for content-driven sites. It is rated the most loved framework by developers every year because it is both pwoerful and delightful to use.
The best CMS for humans and agents
The way people build sites has changed dramatically in the past year alone. Most developers are using agentic coding tools to build their sites, and while humans are still the best at writing, editors are increasingly using ChatGPT or Claude to manage the boring and fiddly parts of their job. Most CMSs are having to adapt to this new world with hastily-added features or plugins, but EmDash was built from the ground up to be great for both humans and AI agents.
EmDash includes first-class, built-in MCP server, APIs and CLI. Like WordPress, the admin is built-in to the site (it’s just an Astro integration!), so there’s no separate backend to manage. But unlike most CMSs, anything that a human can do can also be done by an agent. The built-in MCP server includes OAuth with granular access controls, and a first class API and CLI.
Every default EmDash template ships with built-in agent skills, meaning your AI tools will have no trouble understanding how to build the best EmDash site. Or scaffold a new plugin – or port one from WordPress – and the skills to do that are right there. It even gives a helpful guide on mapping WordPress concepts to their EmDash and Astro equivalents.
Building a CMS is no joke
We first announced EmDash on 1st April, so we have only ourselves to blame when a lot of people thought it wasn’t real! But it was very real, and EmDash 1.0 is the proof. We have been working hard for the past six months, landing thousands of PRs fixing bugs and making improvements across every part of the editor and user experience. Our goal for EmDash 1.0 was not not about features (though we’ve added loads!) – it was about building a CMS that users can trust with their most important sites. We would not launch until EmDash was stable, secure and tested at scale.
Shaped by real sites
You can run all the tests and benchmarks you want, there will always be issues that only show up in production, and the more demanding the site the more edge cases it is likely to find. The same applies to the user experience: we might spend our days building the admin pages, but it will be the editors who are writing the posts who will notice the annoying papercuts and bugs. For this reason, the real people building real sites have been invaluable over the past six months.
Cloudflare has a principle of “customer zero”, where we are the first users of all of our products. This helps us find the problems first, and feel the users’ pain before they do. We were always going to do this for EmDash too, but it was still a bit daunting when we were told that the Cloudflare Blog was not only going to switch to EmDash, but it was going to do it before 1.0, in time for Agents Week in July. These launch weeks always generate massive amounts of traffic to the Cloudflare Blog, so it was vital that it was fast and stable. There are also dozens of posts written by loads of different users that need to be managed and timed to the minute. Inevitably they were always going to be our most demanding users! It was hard work, but with they managed to ship the new EmDash site in time for the launch, and it served millions of real page views, plus handling many more requests from the inevitable DDoS attacks that always try to spoil the party. The blog team wrote a great post going into all the details.
All of this work, plus feedback and contributions from dozens of other users deploying EmDash in production has helped make it stable, fast and great to use.
Built in public, by the community
We are huge believers in open source software, and my hot take is that you shouldn’t ever trust your site to a proprietary CMS. The risk of getting locked-in or left stranded is too high. For that reason we always knew that EmDash would be open source. WordPress has always been open too, using the GPL license. We decided against using that, because we wanted to give our users more freedom and flexibility. For that reason we chose the MIT license, which has become the de facto standard for web tools and frameworks. This lets you use EmDash for whatever you want, including distributing private themes or plugins if you want.
But open source is about more than the license. The part that is most important to me is the community. Slapping an OSI-compliant license on a project and then locking it down to external contributors may be technically open source, but it missed the point for me. As a core maintainer of Astro, and previously of Gatsby, I’ve come to appreciate the real value of a vibrant open source community. I hoped we may one day build a community around EmDash too. We succeeeded more than I could have ever imagined. Within days we had a buzzing Discord with hundreds of members, and we’ve had nearly 200 external contributors to the project.
When I started working on EmDash, it was just me (and loads of Claude credits) but the maintainer team has grown, with Cloudflare employees in the minority! The majority of commits to the project have been from external contributors.
First to step up was Noah Pham, who joined Cloudflare as an engineering intern over the summer. He has worked on all areas of EmDash, but his internship project was a complete rebuild of the media and image library. After text, images are the most important part of a CMS, and Noah has helped build a best-in-class experience. The best news is that his internship has been extended and he’ll be at Cloudflare for another six months.
While we have had hundreds of external contributors, a core group has returned again and again to help out most. In July we created a triage team, where a small group were able to help out more with the firehose of issues and PRs, while continuing to contribute to the 1.0 release. I’m now excited to announce the next stage in the EmDash open source project, where three of them have agreed to join as maintainers. We’re hoping to grow that number.
Plugins without handing over the whole site
The plugin ecosystem around WordPress is probably its greatest strength, but it’s also its greatest weakness. The PHP model where the plugins have full access to everything means that plugins are the source of 96% of security issues for WordPress sites. There hardly seems to be a week that goes by without a major issue that originates in a malicious or compromised plugin. For EmDash we wanted to keep the power and flexibility of plugins, but without the security nightmares. For this we looked to inspiration from mobile apps. Two decades ago it seemed like half the software you installed on your computer came with a side of malware, whether that was stealing or destroying your data.
The mobile app stores showed there was another model: a secure sandbox, with limited permissions that meant that one dodgy app couldn’t take over your whole device and steal or destroy all your stuff. We have chosen the same model for sandboxed plugins in EmDash. Each plugin is run inside an isolated sandbox, with no direct access to the rest of the site. An evil plugin can’t read anything from any other plugin, and you decide when you install it exactly what it can access and whether it can connect to the internet. When running on Cloudflare this uses Dynamic Workers, but this is also available in Node.js, where it runs plugins in a separate process in the open source workerd runtime.
A registry with no landlord
The downside to app stores, which also affects CMS plugin marketplaces, is centralised control. If the organisation running the store decides that they don’t like you or your software then you have no choice but to accept it. We wanted a different model for EmDash. We have built a plugin registry that is secure, but not controlled by a central authority. To do this we built it on top of AT Protocol (atproto). This is the protocol that powers Bluesky, but it’s not just for microblogging. It is designed as a general purpose system for distributed, decentralised apps and has a growing community of cool new projects. Dan Abramov (best known as a member of the React core team) has a great primer on atproto that gives some indication of its power. It’s perfect for a case like this, where we want anybody to be able to publish plugins, but without needing lots of different stores with different plugins available. We provide a default plugin store, but anybody else can create one that is compatible and can provide all the plugins in the network. Likewise while we provide a labeler that moderates plugins that appear in the store, you can choose to not use it, or build your own. We expect hosting companies or third-party directories to build their own. Our implementations are all open source, so you don’t need to start from scratch.
Of course, WordPress has the best ecosystem of any CMS, with thousands of free and paid plugins. With a registry that launches this week it will be a long time before EmDash is anywhere close. However we have made it super easy to create really powerful plugins, and if you have something you want it’s easy to just ask your agent to build you one. I’ve found they can usually create something in just a few minutes! In a few minutes more you can have it live in the registry for anyone to install. Developers will soon discover how easy and fun it is to create them.
We are planning a plugin hackathon soon, and all existing plugins will be eligible. There’s no need to wait: you can get a head start by building your plugin today.
What’s next
While we have been working hard for months to make EmDash stable and ready for production use, we are just getting started. We have big plans for making it even better, and are eager for your feedback. Come join us in Discord to see how you can get involved in shaping the future of EmDash.
Get started
Start building using the site creator:
npm create emdash@latest…or just ask your agent:
Look at https://docs.emdashcms.com/llms.txt and help me build a site