Word & Press · 24 publishing platforms profiled Updated 11 October 2026

Guide

Best self-hosted CMS for publishers: four open-source options

How to shortlist a self-hosted CMS for a news site, with four open-source options compared on licence, stack, roles and approval workflow.

By Word & Press Published 11 October 2026 Facts verified 10 October 2026 Read 4 min

The short answer

There is no single best self-hosted CMS for publishers. Ghost suits memberships on a Node.js and MySQL stack, Drupal suits complex editorial workflows, Wagtail suits Django teams, and WordPress suits sites that want the widest extension choice. Choose by team skills, approval needs and who will patch the server.

SELF-HOSTED CMS SHORTLIST

Word & Press is an independent publication. It is not affiliated with, endorsed by or connected to WordPress, the WordPress Foundation or Automattic. This profile describes the open-source WordPress software as a third party.

Self-hosting means you run the CMS on a server you control, and you answer for its updates, backups and uptime. In return you keep the data, avoid a per-seat subscription and can change almost anything. For a newsroom, the question is whether the team can carry that load.

This guide gives a method for shortlisting, then four open-source options. It rests on vendor documentation. We have not installed any of them, so nothing here is a test result.

How should you shortlist a self-hosted CMS?

Start with four questions, in this order:

  1. Who maintains the server? If nobody, price a hosted plan instead.
  2. What approval does your newsroom need? A single editor, or draft, review and publish stages with separate roles.
  3. What do your developers already know? PHP, Node.js and Python stacks each have a natural CMS.
  4. Do readers pay you? Membership and newsletters are built into some systems and added by extensions in others.

Then check the licence, the supported stack and the update path for each candidate. Our features checklist turns this into a list you can score against, and how to trial a CMS covers testing before you commit.

How do the four options compare?

Ghost Drupal Wagtail WordPress
Licence MIT GPL 2 or later BSD-3-Clause GPL 2 or later
Documented stack Ubuntu LTS, Node.js 22, MySQL 8.0 or 8.4, NGINX Linux recommended; MariaDB, MySQL, PostgreSQL or SQLite; Apache, Nginx or others; Composer A Django application (see the profile) PHP 8.3 or greater recommended; MariaDB 10.11+ or MySQL 8.0+; Apache or Nginx
Editorial roles Five staff roles Roles and Content Moderation workflows Page permissions and moderation See the profile
Approval before publishing Contributors cannot publish Workflow states and transitions Submit for moderation without publish permission See the profile
Headless Not covered here Not covered here Content API described in the repository Not covered here
Managed option from the maker Ghost(Pro) Not covered here Not covered here Not covered here

“Not covered here” means we did not read a source for it today, not that the feature is absent. For fuller detail see the profiles for Ghost, Drupal, Wagtail and WordPress.

When does Ghost fit?

Ghost documents a narrow production stack: Ubuntu 22.04, 24.04 or 26.04 LTS, Node.js 22 LTS, MySQL 8.0 or 8.4, NGINX, at least 1 GB of memory, systemd and a non-root user. It says other set-ups are not officially supported. That makes it predictable to host and awkward on a server standard that differs.

Its five roles are simple: Contributor, Author, Editor, Administrator and Owner. A Contributor can write but not publish, which gives a basic approval step. The trade-off is that you do not get custom multi-stage workflows from what we read. Ghost also sells a managed service, Ghost(Pro), so you can compare self-hosting against it. See WordPress vs Ghost.

When does Drupal fit?

Drupal suits newsrooms that need structured workflow. Its Content Moderation module keeps a published version live while a separate working copy is reviewed, using states and transitions you define. The default Editorial workflow exists only if you installed from the standard profile, so check how your site was built.

The cost is complexity. Drupal says Composer is needed for installation and updates, and it recommends Linux for hosting. Expect to need a developer. See WordPress vs Drupal and Wagtail vs Drupal.

When does Wagtail fit?

Wagtail suits teams that already work in Django and Python. Its page permissions include add, edit and publish, and users without publish permission must submit changes for moderation. Publish permission is independent of edit permission, so you can separate who writes from who releases.

The repository also describes a Content API for headless use. Wagtail is a framework-based system, so it assumes developers build and maintain the site.

When does WordPress fit?

WordPress is released under GPLv2 or later, and the project’s position is that plugins and themes must also be GPL. Its requirements page recommends PHP 8.3 or greater, MariaDB 10.11 or greater or MySQL 8.0 or greater, Apache or Nginx, and HTTPS. It warns that old PHP and MySQL versions may expose a site to security vulnerabilities.

Its main draw is extension choice, which also means you vet plugins and keep them updated. Many features that other systems ship in core arrive as plugins here. See how plugins work.

Which should you choose?

  • Readers pay you and you want a small, predictable stack: Ghost.
  • You need defined review states and have developers: Drupal.
  • Your developers work in Python and Django: Wagtail.
  • You want the widest extension choice and can vet plugins: WordPress.
  • Nobody can maintain a server: look at hosted plans in the cost guide.

If you later outgrow your choice, the migration guide covers moving without losing search traffic.

Questions people ask

What is the best self-hosted CMS for a news website?

There is no single answer. The documentation lets us compare licence, stack and roles, but we have not installed any of them. Shortlist by your developers' skills, whether you need staged approval, and who will apply security updates.

Is self-hosting cheaper than a hosted CMS?

The licence can be free, but hosting, backups, updates and developer time are yours. Ghost, for example, offers both self-hosting with its CLI and the managed Ghost(Pro) service, so you can price the two against each other.

Which self-hosted CMS has an approval workflow built in?

Drupal's Content Moderation module keeps a published version live while a working copy is reviewed. Wagtail makes users without publish permission submit changes for moderation. Ghost's Contributor role can write but not publish.

Do I need a developer to self-host a CMS?

Usually someone with server skills. Ghost documents a production stack with a non-root user and NGINX, and Drupal says Composer is needed for installation and updates. Without that person, a hosted plan is a safer choice.

Can a self-hosted CMS be used headless?

Some can. The Wagtail repository describes a Content API for headless use. A headless set-up adds a separate front end, so check the [headless guide](/headless/) before choosing it for a small team.

Sources

  1. The Ghost repository states the licence as MIT, with copyright 2013-2026 Ghost Foundation, and says Ghost can be self-hosted using its CLI tool or run as the managed Ghost(Pro) service. — source, checked 10 October 2026.
  2. Ghost's documented supported production stack is Ubuntu 22.04, 24.04 or 26.04 LTS, Node.js 22 LTS, MySQL 8.0 or 8.4, NGINX, at least 1 GB of server memory, systemd and a non-root user for running ghost commands; other configurations are not officially supported. — source, checked 10 October 2026.
  3. Ghost has five staff roles: Contributors can write posts but not publish; Authors can create and publish new posts and tags; Editors can invite, manage and edit authors and contributors; Administrators have full permissions to edit all data and settings; the Owner is an admin who cannot be deleted and has access to billing details. — source, checked 10 October 2026.
  4. Drupal, and all contributed files that are derivative works of Drupal hosted on Drupal.org, are licensed under the GNU General Public License, version 2 or later. — source, checked 10 October 2026.
  5. Drupal's system requirements page lists MariaDB, MySQL, PostgreSQL and SQLite as database servers, says Drupal works with Apache, Nginx and other web servers, recommends Linux or a similar operating system for hosting with Windows supported only for development, and says Composer is required for installing and updating. — source, checked 10 October 2026.
  6. Drupal's Content Moderation module lets a published version stay live while a separate working copy is reviewed, using workflows of states and transitions; the default workflow is called Editorial and is only created if the site was installed from the standard installation profile. — source, checked 10 October 2026.
  7. The Wagtail repository describes Wagtail as a Django-based content management system emphasising flexibility and user experience, lists the BSD-3-Clause licence, and describes a Content API for headless use. — source, checked 10 October 2026.
  8. Wagtail's page permissions are add, edit and publish among others; users without publish permission must submit their changes for moderation, and publish permission is independent of edit permission. — source, checked 10 October 2026.
  9. The WordPress software is released under the GPLv2 (or later) from the Free Software Foundation, and the project's position is that plugins and themes are derivative works that must also adopt the GPL. — source, checked 10 October 2026.
  10. The WordPress requirements page recommends PHP 8.3 or greater, MariaDB 10.11 or greater or MySQL 8.0 or greater, Apache or Nginx, and HTTPS support, and says older versions such as PHP 7.4 and MySQL 5.5.5 are no longer officially supported and may expose a site to security vulnerabilities. — source, checked 10 October 2026.