A panel of 22 WordPress plugin tiles sharing one PHP process is sorted into four piles: 9 built into EmDash, 5 available in the registry, 3 to rebuild as sandboxed plugins and 5 dropped. For this illustrative marketing site, 19 plugins leave the PHP process and 3 are rebuilt.

Is it time to leave WordPress? A 2026 guide to the WordPress to Cloudflare EmDash migration

Your plugins decide this, not the headlines. Count what they cost you in risk and upkeep, check which ones EmDash already covers, and the answer for your own site gets simple.

Is it time to leave WordPress for EmDash?#

For a content site whose plugins are its biggest risk and upkeep cost, EmDash 1.0 is now a credible move; for a store or a plugin-heavy site, not yet. Cloudflare's launch post of September 28, 2026 calls it "a stable, free, and open source CMS built on Astro". Its license is MIT.

That matters for trust. When Cloudflare first showed EmDash in April 2026, some people took it for a joke. However, Cloudflare's launch post says more than 175 people have now contributed across more than 1,800 commits. Also, Cloudflare moved its own blog onto EmDash in August 2026. In short, it is a real option now.

  1. April 2026

    Cloudflare first shows EmDash

    Some people took it for a joke.

  2. August 2026

    Cloudflare moves its own blog onto EmDash

    The blog runs about 75 requests per second, with spikes above 5,000.

  3. 28 September 2026

    EmDash 1.0: stable, free and open source, MIT license

    More than 175 people have contributed across more than 1,800 commits, per Cloudflare's launch post.

What is the WordPress plugin problem actually costing you?#

Patchstack counted 11,334 new WordPress vulnerabilities in 2025, and 1,966 of them carried a high risk of automated mass exploitation. That figure, from Patchstack's State of WordPress Security in 2026, is a 42% rise over 2024.

Show data table
New WordPress vulnerabilities in 2025, from Patchstack's State of WordPress Security in 2026
Item Value
New vulnerabilities found 11,334
Serious enough to need a protection rule 4,124
High risk of mass exploitation 1,966

About one new flaw in six carried a high risk of automated mass exploitation.

WordPress vulnerabilities, 2025 New WordPress vulnerabilities in 2025, from Patchstack's State of WordPress Security in 2026 Patchstack, State of WordPress Security in 2026

So about one new flaw in six is the kind attackers use at scale. Patchstack also says 4,124 of the 2025 flaws were serious enough to need a protection rule. For an owner, patching is therefore a weekly job, not a quarterly one. Meanwhile, every missed update is a door left open.

Is the risk in WordPress itself or in its plugins?#

In 2025, 91% of new WordPress vulnerabilities were found in plugins and 9% in themes, with only 6 reported in WordPress core. Those are Patchstack's 2026 figures, and they point at plugins, not WordPress itself.

Show data table
Share of new WordPress vulnerabilities by where they were found, 2025, from Patchstack
Segment Value (%) Share
Plugins 91 91%
Themes 9 9%

Nine in ten new WordPress flaws were in plugins, not WordPress itself.

Where the flaws were found, 2025 Share of new WordPress vulnerabilities by where they were found, 2025, from Patchstack Patchstack, State of WordPress Security in 2026

Cloudflare's launch post explains why one weak plugin can hurt the whole site. With WordPress, "plugins run inside the same PHP process as the rest of the application". Each plugin has direct access to the database, files and network. As a result, a contact form plugin could read unpublished posts or send data anywhere. That is why WordPress's own hardening guide tells owners to keep plugins updated. So the count of plugins you run, and what each can reach, is what matters.

Do premium plugins fix the problem?#

Patchstack rated 58.6% of the vulnerabilities it found in premium WordPress components as high priority, the kind used in automated mass attacks. In other words, paying for a plugin does not buy safety. A paid plugin runs with the same access as a free one.

Show data table
Premium WordPress component vulnerabilities by Patchstack priority, from Patchstack's State of WordPress Security in 2026
Item Value
Low 24.4
Medium 17
High 58.6

Paying for a plugin does not buy safety: most premium flaws were high priority.

Premium component flaws by priority Premium WordPress component vulnerabilities by Patchstack priority, from Patchstack's State of WordPress Security in 2026 Patchstack, State of WordPress Security in 2026

Also, fixes are slow. Patchstack's 2026 report says 46% of vulnerabilities got no fix from the developer in time for public disclosure. Therefore a paid vendor does not always patch first. What limits the damage is how much a plugin can reach, not what it cost.

What does EmDash change about plugin security?#

EmDash runs each sandboxed plugin in its own isolated runtime that cannot reach content, users, secrets or the network until an administrator approves it. Cloudflare's launch post says a plugin gains more access only when it declares the need and the admin approves.

How a sandboxed EmDash plugin gains accessHow a sandboxed EmDash plugin gains access, from Cloudflare's launch post of September 28, 2026. Read it top to bottom: nothing beyond private storage is granted until the administrator approves.Cloudflare, 28 September 2026

Cloudflare compares this to a phone app. In its words, "EmDash shows what the plugin wants to do before it runs." For example, a search plugin can read content and contact the search service, but it still cannot edit articles. Likewise, an image plugin can manage media, but it cannot read user content.

The EmDash docs for WordPress developers map each WordPress plugin to a "sandboxed or native EmDash plugin". So every plugin you keep gets one clear question: what would it need to be granted?

Will your site be faster on EmDash and Cloudflare Workers?#

Cloudflare's own blog, which runs about 75 requests per second with spikes above 5,000, moved to EmDash in August 2026 and kept a flat response profile under load. InfoQ reported both traffic numbers in its September 2026 story on the migration.

Cloudflare blog traffic on EmDashover 60x at peak

about 75

Typical load

above 5,000

Spikes

One site kept a flat response profile across both, but it is one site, not a benchmark.

Cloudflare blog traffic on EmDash (requests per second)
Optionrequests per second
Typical loadabout 75
Spikesabove 5,000

Source: Source: InfoQ, 2026

Cloudflare's team told InfoQ that the old platform had periodic latency spikes under load. The new setup, by contrast, keeps "a remarkably flat, consistent response profile." Meanwhile, the site runs on Cloudflare Workers, which the Astro Cloudflare adapter makes possible for any Astro site. However, this is one large site, tuned by the people who built the CMS. Your results depend on your own pages and cache.

What does hosting on Cloudflare Workers cost as traffic grows?#

On Cloudflare's published Workers Paid terms, request charges stay at the 5 dollar monthly minimum up to 10 million requests, then add 30 cents per million. Those terms come from Cloudflare's Workers pricing page, read in September 2026.

Show data table
Workers Paid subscription plus request charges, worked from Cloudflare's Workers pricing page, September 2026; CPU time, storage and database costs excluded
Stage US dollars a month, request charges only
1 million 5
10 million 5
25 million 9.5
50 million 17
100 million 32

The bill stays at the 5 dollar minimum up to 10 million requests, then rises by 30 cents a million.

Workers request charges by monthly traffic Workers Paid subscription plus request charges, worked from Cloudflare's Workers pricing page, September 2026; CPU time, storage and database costs excluded Arithmetic from Cloudflare's Workers pricing page, September 2026. Modelled, not measured

For example, 25 million requests a month is the 5 dollar minimum plus 15 extra millions at 30 cents. That comes to 9.50 dollars. That is only part of the bill, though. CPU time, storage and the database have their own terms, and the Workers limits page sets the runtime ceilings. Still, you can check this line against your own traffic before you move.

What does a WordPress to Cloudflare EmDash migration bring across, and what does it leave behind?#

EmDash's importer brings posts, pages, custom post types, taxonomies, authors and media across, but plugin-owned fields, shortcodes and page-builder layouts need a second pass. That split comes from EmDash's WordPress migration guide.

What the EmDash importer and Exporter plugin carry, and what needs a second pass, from EmDash's WordPress migration guide, September 2026

What you have on WordPressHow it moves
Posts, pages, custom post types, taxonomies, authors, mediaThe importer
Menus, site settings, Yoast or Rank Math SEO fieldsThe EmDash Exporter plugin
Advanced Custom Fields valuesThe Exporter plugin, when the fields match
Shortcodes, page-builder markup, plugin blocksInspect by hand
Scheduled postsArrive as drafts

The EmDash Exporter plugin goes further than a plain export file. It can carry menus, site settings and Yoast or Rank Math SEO fields. It can also copy Advanced Custom Fields values when the fields match. Meanwhile, the guide says to inspect shortcodes, page-builder markup and plugin blocks by hand. Also, scheduled posts arrive as drafts.

So the content moves by tool, and the slow work is whatever a plugin used to store or draw. The guide's own rule is simple: "Keep the WordPress site available until the imported site has passed verification."

What happens to the WordPress plugins EmDash does not have yet?#

Sort every active plugin into four piles: built into EmDash, available in the registry, worth rebuilding as a sandboxed plugin, or safe to drop. The size of the rebuild pile then decides whether the move pays.

EmDash's GitHub project lists first-party plugins for forms, embeds, SEO and an audit log. Also, its collections can turn on search, scheduling, revisions and comments. So that covers much of what small sites install plugins for.

Take an illustrative marketing site with 22 active plugins. Say 9 are covered by built-in features and 5 have a registry plugin. Then 3 need a rebuild, and 5 were never needed. So that site sheds 19 plugins from its PHP process and rebuilds 3, and the move pays.

Whether the move pays for your site#

Put in your active plugin count and how many fall in each pile; it returns the plugins you shed, the ones to rebuild and the margin between them.

Your plugins, sorted into four piles

an assumption, change it

Only plugins are counted. Content import, page-builder layouts and hosting are left out, because they differ for every site. The defaults are an illustrative marketing site.

Plugins leaving the PHP process

19

Plugins to rebuild
3
Plugins shed minus plugins rebuilt
16
Plugins not yet sorted
0

Above zero, the plugins you shed outweigh the ones you rebuild, and the move pays.

How do AI agents change day to day editing on EmDash?#

EmDash ships a built-in MCP server, so an AI agent can read, update and save content through the same permissions an editor has. Cloudflare's launch post says agents "can work through the API, CLI, or built-in MCP server".

Its example is a bakery owner who asks, in plain words, to change the opening hours. An agent then reads, updates and saves the content. According to Cloudflare's first EmDash post, the MCP server does the same set of things as the admin.

  1. The owner asks, in plain words, to change the opening hours

  2. An agent reads the content through the built-in MCP server

  3. It updates and saves the content, with the same permissions an editor has

In practice, this helps most with dull jobs, such as fixing a phrase across many pages. Still, it is a benefit of moving, not a reason to move.

When is EmDash the wrong fit, and when should you stay on WordPress?#

Stay on WordPress for now if you run a store, depend on a page builder, or would have to rebuild more plugins than you would retire. W3Techs reports, as of September 2026, that WordPress runs 40.2% of all websites, and that breadth still counts.

WordPress usage as surveyed by W3Techs4 in 10 websites

40.2%

Share of all websites

58.7%

Share of sites using a known CMS

That breadth still counts when you weigh staying on WordPress against a move.

WordPress usage as surveyed by W3Techs (share of websites)
Optionshare of websites
Share of all websites40.2%
Share of sites using a known CMS58.7%

Source: Source: W3Techs, accessed 29 September 2026

First, stores should wait, because Cloudflare's launch post says EmDash's first eCommerce plugin is only now arriving. Second, a page-builder site needs its layouts rebuilt, since the migration guide says to check that markup by hand. Third, if your rebuild pile is longer than the plugins you shed, the move costs more than it saves.

In those cases, the better tool is WordPress, hardened. Cut unused plugins, keep the rest updated, and follow WordPress's plugin guide. Then run the sort again once the registry has grown.

Where to go from here#

If you would rather hand the sort over, our headless CMS team runs a WordPress to EmDash Migration Readiness Audit. It also rebuilds the plugins you keep as sandboxed plugins. After the move, our Cloudflare development team can run and tune the site on Workers. That said, the EmDash docs and your own plugin list are enough to make the call yourself.

Questions this post answers

Is a WordPress to Cloudflare EmDash migration worth it in 2026?
It is worth moving to when the plugins you shed outweigh the ones you rebuild. For a content site, that is often true today. For a store or a page-builder site, a WordPress to Cloudflare EmDash migration can usually wait.
What does the EmDash importer bring across from WordPress?
EmDash's importer brings posts, pages, custom post types, taxonomies, authors and media across, but plugin-owned fields, shortcodes and page-builder layouts need a second pass. Also, scheduled posts arrive as drafts.
How are EmDash plugins safer than WordPress plugins?
EmDash runs each sandboxed plugin in its own isolated runtime that cannot reach content, users, secrets or the network until an administrator approves it. Cloudflare's launch post says a plugin gains more access only when it declares the need and the admin approves.

Keep reading