EmDash 1.0 vs WordPress vs Grav: three CMSs, measured on one small VPS

cms wordpress grav emdash flat-file

Cloudflare shipped EmDash 1.0 on 28 September and called it the spiritual successor to WordPress. Search Engine Journal answered the same day with the counter-argument that actually matters: the features that make EmDash interesting are features of Cloudflare’s infrastructure, not of the CMS itself. Both pieces are worth reading, and both are argument. This post is the part neither of them has: numbers.

We run all three. This blog is Grav — 33 pages, 32 posts, 14 plugins, flat files on a VPS with one vCPU and 1.9 GB of RAM. Our agency blog is WordPress — 459 posts and 648 tags on shared hosting we do not administer. And on the day EmDash 1.0 was released we installed it on that same small VPS, to see what the claim that it can run anywhere Node runs costs in practice. Everything below is either a documented fact with a link, or something we measured ourselves. Where a number is a single sample, I say so.

The three in one sentence each

WordPress — PHP and MySQL; used by 58.7 percent of all websites whose CMS is known; the reason an agency can promise a client that any freelancer on earth can take the site over tomorrow.

Grav — a flat-file CMS in PHP: no database, content as Markdown files in folders, Twig templates. The whole site is a directory you can copy, diff and put into Git.

EmDash — Astro plus Node, with an admin that is a React application, MIT licensed, an API, a CLI and a built-in MCP server, and a plugin registry built on the AT Protocol.

What we measured: how much machine a CMS needs

Install footprints, on the same box, measured rather than quoted:

  • EmDash 1.0, a fresh install with seven demo images: roughly 783 MB on disk. Its admin bundle contains a single 8.1 MB JavaScript chunk (the plugin registry), a 642 KB shared library, and a 226 KB stylesheet for the blog.
  • Grav, our live site with 33 pages and 14 plugins: 123 MB in total — 35 MB of plugins, 6.4 MB of pages, 6.4 MB of cache.
  • WordPress: we cannot give you a number, and that is the point. It runs on shared hosting we never touch. We know its content scale, 459 posts, but not its disk footprint. Managed hosting makes the footprint somebody else’s problem, which is a feature people pay for.

Runtime: what has to be running for a page to load

WordPress and Grav need PHP-FPM behind a web server. That stack was already on our server before either was installed, and one pool serves several sites.

EmDash needs Node.js 22.16 or higher, with odd-numbered releases unsupported, and it needs a production build: npm run build took about 37 seconds on our single vCPU. Then a long-running Node process has to stay up. Nothing ships a systemd unit for you, so we wrote one, environment file included, because the documentation states plainly that a standalone Node server does not load .env by itself. On a 1.9 GB machine we capped the process at 800 MB so it could not evict everything else. Sandboxed plugins need one more runtime: a workerd child process. Database migrations run on the first request after a deploy.

None of that is a defect. It is the honest price of a server application built on Node, and Cloudflare’s documentation is unusually clear about it: use SQLite with local storage for a single server, and the docs warn that an ephemeral filesystem will lose the database on restart; scale out and you want PostgreSQL or libSQL plus S3-compatible storage. That is a normal, modern architecture. It is also three decisions that WordPress and Grav never ask you to make.

Where the content lives, and what that buys you

This is the difference we feel daily, not the one that shows up in a benchmark.

In Grav a post is a folder with a Markdown file in it. This article is a Markdown file. It went into Git next to its cover image, and the diff shows exactly what changed. A backup is a copy of 123 MB of files, with one catch worth knowing: two configuration files are mode-600, so a plain rsync as a non-root user skips them and leaves you a backup that cannot restore a complete tree. We learned that by inspecting a backup rather than by needing one, which is the good order to learn it in.

In WordPress, posts live in MySQL. You back up a database dump plus the uploads directory, and you edit content through an admin panel or the REST API. It is a mature, well-understood model, and for a blog with 459 posts and an editor who is not a developer, it is the right one.

In EmDash both halves are yours: SQLite plus local files by default. The same shape as WordPress, except the database file sits next to the site and the documentation tells you when to graduate to a real database.

Grav is the only one of the three where backup and version control are the same operation, and for a documentation site that is most of the value.

Lock-in: the licence is not the architecture

EmDash is MIT licensed, and Cloudflare says explicitly that a CMS at the heart of a company’s web presence should not come with vendor lock-in. Take that at face value, because it is real: the licence is free, the plugin registry is deliberately separated from the catalogue so that no single company can hold a plugin hostage, and plugins run sandboxed. Those are genuine improvements on the WordPress status quo, and they read like a direct answer to the WP Engine conflict of autumn 2024, when WordPress.org cut a large host off from its resources. Anyone who tells you WordPress carries no governance risk is selling something.

A licence, though, does not determine where your site runs. Search Engine Journal put it precisely: EmDash can be hosted without Cloudflare on any Node environment, yet most of what version 1.0 adds depends on Cloudflare — EmDash Build with its external model and sandboxed containers, the Hyperdrive database adapter, Workers cache compatibility, and Git history through Cloudflare Artifacts. Choose EmDash for those features and you have chosen Cloudflare, whatever the licence says. That is not a scandal. It is simply worth saying out loud, because the phrase open source is doing more work in the launch copy than the architecture supports.

The other two are boring here, which is their strength. Grav is MIT licensed and runs anywhere PHP runs; a Grav site is a folder, and moving it means copying the folder. WordPress is GPL, runs on the cheapest hosting on the market, and even Cloudflare, when you want it, is a layer you can add and remove.

Publishing: what an agent can actually do

This is where EmDash earns the agent-native label honestly. It ships an API, a CLI and a built-in MCP server, and its documentation treats automated clients as first-class users. Credit where it is due: that is ahead of both of the others out of the box.

In practice the gap is narrower than the marketing suggests, because both older CMSs already provide the one thing an agent needs — a documented HTTP API.

  • This post was published to Grav by our agent through the REST API with an API key: create the page, upload two cover formats, patch content and header, clear the cache, verify. One command, no browser, no sudo. The same pipeline placed every link you are reading.
  • The WordPress article we published earlier today — a comparison of EmDash and WordPress, ironically — went live the same way, through the WordPress REST API with an application password.

What we could not do was log into EmDash over its public URL. The admin is a single-page React application, and the documentation is explicit that if React is not wired into the Astro integrations the admin page simply sits on Loading EmDash. In our run we got in through the development bypass, which is a localhost convenience, and never through the front door a client would use. That, more than anything technical, is why the experiment ended: we could not hand a client a working login.

Speed: a small snapshot, with the caveats attached

We measured our two live sites today, three requests each, from the same client:

  • Grav listing page: 0.086 to 0.110 seconds to first byte.
  • WordPress listing page: 0.141 to 0.197 seconds to first byte.

Grav is roughly twice as fast in this sample. Now the caveats, because this is not a benchmark: different hosts (a single-vCPU VPS with Caddy and PHP-FPM against managed shared hosting), different page weights, one client, no CDN, and three samples. Treat the direction as a hint, not a result.

The more useful Grav number comes from today’s 2.2.3 release: theme and plugin templates now compile without the Twig sandbox checks, which Grav measures as about half the Twig time on a busy listing template. Twig inside page content is still checked exactly as before, so the security posture does not move. On a site whose listing pages are theme templates, that is a free improvement — and it is the sort of thing a flat-file CMS with a template layer can do without disturbing the content model.

Ecosystem, and the humans who have to use it

WordPress is used by 58.7 percent of websites whose CMS is known, which is 40.2 percent of all websites. Grav is used by less than 0.1 percent. That is not a rounding error in this argument; it is the argument.

The consequences, in the order we hit them while running Grav for real: breadcrumbs that never rendered, a sidebar partial that assumed a variable item pages do not have, OpenGraph metadata that the admin panel corrupted on write, and a theme partial frozen from an older core that silently suppressed a newer feature. None of it was hard. All of it was ours to find, because there is no crowd of Grav developers who have already answered it.

With WordPress, that crowd exists. With EmDash it is a year old and small: more than 175 contributors and 1,800-plus commits by Cloudflare’s own count, 800 people in the community chat, 44 themes from a single vendor, and an eCommerce plugin still in progress. Promising, and not yet a labour market.

What we would choose, and why

Three honest answers, because the right CMS depends on who maintains the site after you:

  1. Client marketing sites: WordPress. Not because it is elegant, but because freedom of hosting, a hireable skill pool and cheap maintenance beat elegance whenever somebody else pays the bill. Its openness is also its risk surface, and we say both things in the same breath.
  2. Documentation, knowledge bases and technical blogs: Grav. Markdown in Git, no database, 123 MB for the entire site, fast without a CDN, and backups you can read with your own eyes. The price is a smaller ecosystem and nobody to call.
  3. Agent-first greenfield projects on Cloudflare: EmDash is genuinely interesting. If your site already lives on Workers and you want an AI builder, sandboxed plugins and a registry with no gatekeeper, it was designed for you. If you are a small team on a VPS, the deployment is a project rather than an install, and the parts that excite you most are the parts that keep you on one vendor.

The short version

  • EmDash 1.0 is a real CMS with real ideas; the lock-in is architectural, not legal, and it is fair to say that out loud.
  • WordPress remains unbeatable for client work: hosting freedom, one-command agent publishing, and an ecosystem measured in tens of millions of sites.
  • Grav trades ecosystem size for content you can read, diff and move: 123 MB, no database, Markdown in Git.
  • What we measured: a fresh EmDash install is 783 MB and needs a Node build plus a process to look after; Grav is 123 MB and needs the PHP-FPM that was already running.
  • The cheapest long-term decision is usually the one that leaves your content in a format you can read without the CMS.

If you are choosing a CMS for a project and want the maintenance cost modelled before the first line of a brief, that is part of what we do — start with agenteum.top. Related reading from this blog: how we measured real reading behaviour on the WordPress side in AnGo Scroll Analytics, the storage migration that cut our agent state database by 58 percent in the compact FTS layout, and a debugging story from the same stack in the auxiliary title generation 400. Everything else is in the blog archive.

Sources: EmDash 1.0 Challenges WordPress Freedom With Cloudflare Lock-In (Search Engine Journal, 28 September 2026); EmDash 1.0: the stable CMS with a secure plugin registry (Cloudflare, 28 September 2026); Deploy to Node.js (EmDash documentation); Usage statistics of WordPress and usage statistics of Grav (W3Techs, September 2026).