EmDash 1.0 released this week - so we built an app and ran it through our JS vulnerability tool 🥷 One simple to-do app, 744 dependencies, 1 exploitable XSS vulnerability. 🚨 We are releasing our mitigation features for vibecoded apps soon. Apply for early access in comments:
EmDash hit 1.0 this week. Cloudflare's open source CMS for Astro. It's a lovely bit of work. Congrats Matt Kane and Matt Taylor They launched it as "the spiritual successor to WordPress that solves plugin security," citing our research twice to make the case. 96% of WordPress security issues start in plugins. They're right. Every plugin runs in its own sandbox and can only do what it declared it needs, which is exactly how it should have worked all along. So I built something with Em. One prompt. "Create a simple todo list site with em dash" 744 packages. One reachable, exploitable vulnerability sat there on day one. An XSS in dompurify, disclosed back in March. Zero plugins installed. Plugin security: solved. The other door was never locked. Thats not a dig at EmDash. Its the whole point. Sandboxing shuts the plugin vector and npm strolls in through the dependency tree, and no framework, CMS or AI builder on earth opts out of that. Same 6 month old advisory, brand new stack. And the industrys answer is still shift left. Scan the repo, raise a pull request, feel productive. Meanwhile the thing actually exposed is in production and time to exploit is down to hours. Patchstack for JavaScript starts where the danger is. Build with EmDash, build with Lovable, build with whatever launches next month. You stay protected on the live app while the vulnerable package is still sat there, and you update when youre ready rather than when the shit hits the fan. Safe the same way you when using Patchstack for WordPress Early access is open. Works just as well on EmDash as anything else in this new wave. 🔗 https://lnkd.in/ebsXcXtz