Cloudflare has released EmDash 1.0, a free and open-source content management system designed to contain the security risk of third-party plugins. Each plugin runs in its own sandbox and starts with only private storage. To touch site content, media, users, secrets, the filesystem, or the network, it must first request those abilities and receive approval from a site administrator. The model is deliberately unlike WordPress, where plugins execute inside the main PHP process and can reach the database and filesystem directly.
EmDash treats plugin installation like installing a phone app: the runtime shows what the plugin wants and enforces that list. Permissions are granular, so a search plugin might read published articles and contact its search service without being able to edit content or reach arbitrary hosts. The design has an obvious weak spot: the runtime enforces whatever an administrator approved, including approvals granted without a glance.
The plugin registry is built on AT Protocol, the same decentralized network used by Bluesky. Publishers sign releases with their own Atmosphere accounts, and EmDash verifies the signature, checksum, package name, version, requested access, and build provenance before installation. A signature confirms who published a release, but not whether the publisher's account was compromised. The registry also has no central off switch; moderation can hide a listing in Cloudflare's catalog, but the release itself remains published.