A single timeline. Every version Respira has shipped, with the stories behind the ones that mattered. Click into any release tagged story for the full write-up.
Murmur's element outline stays on the element after scrolling
fixMurmur's element outline stays on the element after scrolling. The review overlay is fixed to the viewport, but its hover outline was positioned with document coordinates. After a reviewer scrolled, the green border move
Respira AER is the agent workspace in the Respira dashboard. Respira for WordPress 9.0 is the runtime installed on each site: it gives AER secure access to the site's builders, memory, approvals, snapshots and receipts without putting another chat inside wp-admin. Across 8.x the plugin learned five things one release at a time. It remembers a site and enforces its rules. It knows the site's art direction and checks work against it. It lets clients talk back through Murmur. It lands a designed page as native builder output. And it proves what change runs did. Version 9.0 brings those parts together and adds an Open in Respira AER button plus a Ready for Respira AER checklist. Murmur links and client notes, spoken ones included, show up where you work. Site memory and Art Direction are on screen next to the pages they govern. The security audit gives the same answer whether you or your agent run it from an app connected over MCP, from Respira AER or from the site's own endpoint: the known vulnerabilities that match its plugins, themes and WordPress version, checked against Wordfence Intelligence, each with the version that fixes it, and never a clean report when that database cannot be reached. Change runs leave receipts, and reversible content work keeps its snapshot or undo.
fixapply_builder_patch accepts find_element's identifier shapes. The tool now
September 11, 2026
Hosts that turn PUT, PATCH and DELETE into reads
fixHosts that turn PUT, PATCH and DELETE into reads. Some hosts pass those requests to
fixA site URL that redirects is named as the problem. When the configured URL redirects
fixSite template operations take type and operation as well as op. The three
changeThe HTML conversion tool describes fidelity mode, the default in plugin 8.8.34 when the
September 11, 2026
wordpress_create_share_link
addwordpress_create_share_link. Mints a share-grade preview link for any page, post,
addttl_days on wordpress_mint_design_preview. The same token, minted for days instead
changeBoth tool descriptions now say what the link is for: put it in the reply with its expiry
September 10, 2026
An HTML page converted to Divi keeps its stylesheet and its classes
fixAn HTML page converted to Divi keeps its stylesheet and its classes. The converter
fixAn upload that fails says why. When WordPress could not move an uploaded file, the
fixThe update page tool takes a template and reports what it stored. A template
September 10, 2026
A refused connect now says why
fixA refused connect now says why. Connect returns you to the Overview screen, which hides
fixA second edit on an Elementor page built with sections no longer blanks it. Adding an
fixDuplicated Divi modules no longer block every edit. Divi 5 keeps a module's internal id
fixOne edit on a multilingual Bricks site no longer rewrites query filters across the site
fixFlex layouts converted from HTML now render on Bricks. Direction, alignment, wrapping and
fixSigned-out visitors can see a site's public tools again. With public discovery switched
September 9, 2026
The public key check was an oracle, and an amplifier
secThe public key check was an oracle, and an amplifier. POST /respira/v1/auth/validate-key
secAny key could destroy any other key. DELETE /respira/v1/auth/revoke-key/{id} checked
fixChatGPT could only see two of the tools your site offers. Tool names for the built-in
September 9, 2026
A Respira outage was reported as a fault on your site
secA lapsed trial could leave a valid key refused on your own site, and 8.8.27 made it
fixA Respira outage was reported as a fault on your site. When the account service
fixDivi 4 writes could silently drop part of the page. A targeted edit rebuilt the
fixA Divi 4 patch could report content loss that had not happened, and roll back
fixDivi presets applied through the API were not recognised by the Visual Builder
fixBeaver: removing a setting reported success and wrote the word "unset" instead
September 9, 2026
The connection diagnostic now reports why your tools are missing
fixThe connection diagnostic now reports why your tools are missing. When an
September 9, 2026
One failed handshake made a site look broken for the rest of the session
fixOne failed handshake made a site look broken for the rest of the session. A
fixA Respira outage was described as a fault on the customer's site. When the
fixEditing a menu item failed on hosts that block PUT. Those hosts already had a
fixRedeeming an install token discarded local per-site settings. The redeemed entry
fixA password-protected site was reported as one with Respira uninstalled. The check
fixFiled issue reports lost the builder they came from. The report tool read the
September 8, 2026
Revoking an API key did not reliably revoke it
secRevoking an API key did not reliably revoke it. A customer revoked the same
secThe cloud-side token revoke almost never found the right site. It selected an
September 8, 2026
Respira could adopt another vendor's AI agent as the user it writes as
fixRespira could adopt another vendor's AI agent as the user it writes as
September 8, 2026
Text a stranger typed into your checkout no longer reaches your AI as-is
secText a stranger typed into your checkout no longer reaches your AI as-is
fixThe remote transport decided one thing by reading a value that meant two
September 7, 2026
Settings told almost everyone that white-label does not exist yet
fixSettings told almost everyone that white-label does not exist yet. The
changeThe white-label card now says what it is and where to get it. Studios who
September 6, 2026
Divi 5 button text colour was written somewhere Divi never reads
fixDivi 5 button text colour was written somewhere Divi never reads. A button has
fixDivi presets created through Respira never appeared in the Visual Builder. They
fixDesign-direction colours did not reach five of Divi's colour slots. Divi removes
fixcreate_menu_item failed with "the link you followed has expired". Menu plugins
fixA duplicate could come back with an empty builder payload, and approving it would
fixDestructive bulk edits and batch removes were unguarded. The bulk path wrote
September 5, 2026
updates.unset did nothing on Divi 4 and said it worked
fixupdates.unset did nothing on Divi 4 and said it worked. The Divi 4 writer had
fixA scoped Divi 4 patch rewrote separators across the whole page. An unset
fixThe 8.8.21 Elementor subtree fix only covered half its input. It rescued children
fixinclude=meta.all was unreachable. It is gated on the read_meta_all scope, and
fixActivating a plugin reported failure on sites with a canonical redirect. The
September 4, 2026
Elementor atomic writes deleted the element's children
fixElementor atomic writes deleted the element's children. Any write touching an
fixupdate_element reported changed: true on every call ever made. The
fixDivi 5 heading and text writes could nest the value inside itself. Where an
fixFlatsome dropped content it could not model. The shortcode parser had no tag
fixFlatsome moved content between columns. Column boundaries were discarded on
fixFlatsome refused edits it should have allowed. The write guard compared against
September 4, 2026
Creating a translation rewrote the other translations in German
fixCreating a translation rewrote the other translations in German. On a
fixElementor edits on a translated page were refused, and the page kept
fixEditing any element on a WPBakery page was refused as content loss. The
fixTurning on an ability from another plugin failed with no reason given
September 4, 2026
Uploading a JPEG never worked
fixUploading a JPEG never worked. upload_media decided whether the file
fixA failed upload hung for minutes instead of retrying. The multipart body was a
fixThe ?rest_route= upload fallback had never worked. It inherited the same
fixOne bad upload could take the whole server down. Error responses skipped the
fixThe tool description advertised a 120 second upload timeout; the actual default has
changemcp-bundle/build.sh now packs the local mcp-server when its version matches the
September 3, 2026
The advice for editing one of two identical elements did not work
fixA WPBakery page lost two headings when an unrelated element was
fixBulk find and replace stripped <style> and <script> out of Divi 4
fixThe advice for editing one of two identical elements did not work
housekeereadme.txt still advertised 8.8.17 as the stable version after 8.8.18
September 3, 2026
A save could arrive at WordPress as a read, and answer as one
fixA save could arrive at WordPress as a read, and answer as one. If a site
September 2, 2026
A plain anchor no longer converts into a button
fixA plain anchor no longer converts into a button. Rebuilding a page from
September 2, 2026
Editing any element on a Flatsome page was refused
fixEditing any element on a Flatsome page was refused. On a page
fixThe same shortcodes were missing when reading a page
September 2, 2026
The accessibility scan was inventing findings
fixThe accessibility scan was inventing findings. In cloud and hybrid
fixSaving a setting could report success without saving it. If something
September 2, 2026
The check that would have told that site owner why he got
addA deep scan now tests whether PHP dropped into your uploads folder
September 2, 2026
A hidden administrator that hides its own age is now found
addA hidden administrator that hides its own age is now found. Malware
addRespira now tells you if anyone can list your usernames. Reading the
September 1, 2026
Modules from third-party builders answer for their own settings
fixAn option holding a plugin's own object can no longer be overwritten
fixModules from third-party builders answer for their own settings
September 1, 2026
Respira checks what a write did to the rest of the page
addRespira checks what a write did to the rest of the page. Three times
September 1, 2026
Specialty sections keep their layout
fixSpecialty sections keep their layout. Appending a section to a Divi 5
fixThe page keeps its outer wrapper. The same write dropped the wrapper
August 31, 2026
A ::selection rule no longer paints the whole page
fixA ::selection rule no longer paints the whole page. A selector
fixDivi's default section padding steps aside on convert. Converted
August 31, 2026
An approval-gated tool asked for an argument it never advertised
fixAn approval-gated tool asked for an argument it never advertised
August 31, 2026
build_page wrote attribute names Flatsome does not read
fixbuild_page wrote attribute names Flatsome does not read. Building a
fixA two-column row no longer collapses into one, with a stray [/col] on
fixA block nested inside another of the same kind is now refused instead of
August 31, 2026
Scoped design tokens resolve per element
fixScoped design tokens resolve per element. CSS custom properties
fixColumn widths reach the page. The converted row's fraction list was
fixColumn backgrounds, corner radius and padding render. Their silence
fixInternal layout-detection markers no longer persist as junk attributes
August 31, 2026
The other half of the Kadence
fixSending new content and new settings in one edit no longer loses the
August 31, 2026
Kadence blocks keep their content when you edit something else
fixKadence blocks keep their content when you edit something else
August 31, 2026
Shorthand CSS now maps
fixShorthand CSS now maps. Real pages say background: #101418 and
fixGrids become real columns. Every converted row defaulted to one
fixIcons render. Two bugs: data-respira-module="icon" serialized the
fixAn un-annotated nav inside an annotated section no longer kills the
fixAn anchor wrapping only an image becomes an image with a link, not
fixInline span runs keep all their text. Two sibling spans in a plain
August 30, 2026
Editing one block no longer empties the headings, lists and images around it
fixEditing one block no longer empties the headings, lists and images around it. A change i made in 8.7.4 cleared the saved markup of any block WordPress reports as rendering from its settings. That reasoning was wrong. Hea
fixA page can use the site's own saved patterns again. Security validation refused to write a saved pattern into a post when the pattern contained a script, because the script was not yet in that post. It is a block the sit
August 30, 2026
The data-respira annotation vocabulary
addThe data-respira annotation vocabulary. Five attributes for authors who write their own source HTML, designed with Bronko from his empirical import test. data-respira-section makes an element a top-level section no matte
fixGrids survive without annotations too. The converter used to survive exactly one div level: every additional div became a row, never a column, so any page with a grid or card group produced an invalid tree and the whole
fixEvery string appeared twice. Text modules were emitted once correctly and once again as a nested child with the same content; button text duplicated inside the link. Leaf modules no longer re-emit their markup as extra m
fixDropped styling confesses. Unmapped CSS properties were tracked internally and reported to nobody while the fidelity report claimed zero warnings. Every dropped property is now a named warning in the report and the respo
fixValidation failures are readable. A failed import used to return up to 158KB of duplicated tree-index messages. Distinct errors now come deduplicated with counts and the section each first occurred in
fixSame-page anchors stay relative. #kontakt no longer becomes an absolute link to the site root, wrong on every subpage
August 30, 2026
The Divi Library, as tools
addThe Divi Library, as tools. Save a page, a single section of it, or a supplied structure as a real Divi Library item, and apply it to any page as a live-linked global reference. The page stores only a reference; Divi exp
fixA page receiving its first Divi content through a raw write now renders it. Writing native Divi 5 markup to a plain page flipped it into Divi 5 mode but never builder-enabled it, so Divi ignored the content entirely: a g
August 30, 2026
wordpress_save_divi_library_item and wordpress_apply_divi_library_item
addwordpress_save_divi_library_item and wordpress_apply_divi_library_item. Save a page, one section of it, or a supplied structure as a real Divi Library item, then apply it to any page as a live-linked global reference: th
change10 skills brought to catalog parity, plus Figma to Elementor, page-template-library, prime-the-agent, stale-content-detector. 41 skills total.
changeMigration skills rewritten to be snapshot-safe with surgical find/update/batch.
changeconnect-site no longer assumes it can write to ~/.respira; it hands you the move command instead.
changeInstall docs corrected. The page claimed Cowork installs Node for you and would prompt if it was missing. Neither is true, and a Windows customer lost an evening to it. The prerequisite now says to install Node yourself,
changeTwo stale counts fixed against their sources: 41 skills (was thirty), 17 page builders (was 16).
August 29, 2026
A Divi 5 page built by Respira can finally use Divi's own styling engine
fixA Divi 5 page built by Respira can finally use Divi's own styling engine. Divi generates CSS from module attributes and presets only for pages carrying a marker that says "saved from the Visual Builder", and no Respira w
fixOne payload vocabulary across all Divi 5 write paths. Building a page and updating an element accepted different shapes for the same styling: what update_element wrote verbatim, build_page dropped with "styling dropped".
fixContact forms can be built inside a page. A contact form with fields used to fail the whole write with a baffling "section must be top-level" error, because underscore spellings like contact_form missed the module lookup
fixThe module list tells the truth about the live site. It used to be a bundled catalogue: Divi 4 names on a Divi 5 site, WooCommerce modules on sites with no WooCommerce, and third-party module suites invisible even when i
fixA preset reference means the same thing everywhere. _presetId was honored by one write path, silently discarded by another, and stored as an inert string by a third. All paths now apply the preset's attributes and keep t
fixA JSON-encoded structure can no longer be stored as visible text. Passing a node array as a JSON string to the theme-builder tools used to store the raw JSON as page content, quotes curled and all, with no error. It now
August 29, 2026
Divi 5 presets are first-class tools
addDivi 5 presets are first-class tools. wordpress_list_divi_presets, wordpress_upsert_divi_presets (bulk, idempotent by name so a brand-profile installer can re-run safely), wordpress_delete_divi_preset, and wordpress_reso
August 29, 2026
The phantom "4KB limit" is gone
fixThe phantom "4KB limit" is gone. Nested Divi 5 payloads over roughly 4KB appeared to arrive truncated, failing with a generic validation error that forced batches to be split and pushed one build toward literal hex color
fixfind_builder_targets works on Divi 5. Agents pass the generation string the builder info reports (divi5), which resolved no adapter, so the tool walked nothing and answered "this page is empty" with a success flag. The g
fixget_page_outline accepts id. Every sibling read tool calls it id; this one demanded page_id and rejected the rest. Both work now
fixbatch_update stops advertising a duplicate action the server rejects. The schema promised it, the server 400ed the entire batch. The schema now tells the truth and points at duplicate_element
fixEvery add_* shortcut states its contract up front. They append at the end of the page, always. That used to be revealed only after a positioning parameter was silently ignored; the tool descriptions now say it before you
August 27, 2026
A post's publish date can be corrected after the fact
fixA post's publish date can be corrected after the fact. Migrating posts in from another site stamps every one of them with the migration date, and there was no way to put the real dates back: creating a post has accepted
fixDivi 5 CSS classes actually reach the page. Setting a class or an ID on a Divi 5 element reported success while nothing was written, and adding the same class by hand in Divi worked, which made it look like Respira was w
fixA dynamic block stops carrying the answer it had before you changed it. Updating a block that renders from its settings, a Rank Math FAQ among them, changed the settings and the visible output and left the previous text
August 27, 2026
Respira's REST responses are no longer printed twice
fixRespira's REST responses are no longer printed twice. Every response on one store came back as two JSON objects with nothing between them, including 404s and OPTIONS, which never reach a route callback. Tolerant parsers
fixA server that removes the Authorization header no longer looks like a broken login. Apache running PHP as CGI or FastCGI drops that header unless CGIPassAuth is on, and Claude only ever sends its token there. Every call
fixRestricting a site's tools now actually restricts what the agent is sent. The per-site tool allowlist was only consulted when a tool ran, never when the catalogue was listed, so a credential limited to a handful of tools
fixA repeated write no longer reports that it did the work again. Sending the same write twice returns the stored result rather than doing it twice, which is right for a retry. But it said so only in an HTTP header, and an
fixA duplicate Respira cannot read back is no longer reported as an id. Creating a duplicate returned an id for a post that was not there, while the real duplicate had a different one. A successful insert means the row was
fixSecurity validation stops refusing a page its own content. A draft-only update was blocked because the page used the site's own saved pattern, and that pattern carries an inline script that was already live on the page.
August 26, 2026
A Bricks append no longer reports that it duplicated your page
fixA Bricks append no longer reports that it duplicated your page. Appending one container to a 161 element page said 319 elements total, which reads as the whole tree having been copied. The page was correct the entire tim
fixEditing one Bricks setting no longer looks like it edited several. Changing a heading's text also listed that element's typography as changed, which made a strict review step refuse to approve a write that had done exact
fixA builder without modules now tells you which tool does work. update_module on a Gutenberg table answered that module level updates are not supported and stopped there, which is true and a dead end. Eleven of the sixteen
fixA page Respira could not read is no longer reported as a write that failed. This one shipped in 8.7.1 and missed its changelog entry, so here it is properly. After editing a live Elementor page, Respira fetched the publi
August 26, 2026
WebMCP site tools work now
fixWebMCP site tools work now. The bundled browser bridge never could: tool discovery sent cookies without the nonce WordPress requires, so it ran as an anonymous visitor, got told to authenticate, and registered nothing; a
fixDivi 5.10 presets resolve again. Divi 5.10 renamed the preset option to et_divi_builder_global_presets_ng and changed it from an array to an object; the reader looked only at the old name and shape, so _presetId returned
fixRespira no longer runs schema checks on every page load of every visitor. Since 6.10.5 the upgrader self-healed missing tables and columns on every request, anonymous front-end traffic included: up to eleven SHOW TABLES
fixApproving a duplicate into a draft no longer moves the draft's authored date. WordPress keeps a draft's date floating and resets it on every save, so a content-only approval silently advanced the original draft's post_da
fixThe two connection diagnostic tools now declare complete MCP annotations. respira_diagnose_connection and respira_get_job_status omitted destructiveHint, which blocked directory listings that require every annotation on
fixbuild_page produced unstyled pages because it never told the agent how to style them. The structure parameter's entire documentation was the phrase "Declarative page structure", so an agent had to guess the settings voca
August 26, 2026
The openWorldHint allowlist shipped yesterday matched nothing
fixThe openWorldHint allowlist shipped yesterday matched nothing. 8.6.48 replaced a hardcoded "every tool reaches the open internet" with an allowlist of the thirteen tools that genuinely do, but the list was written with u
fixreport_issue said it was read-only while filing a bug report. It posts a structured report upstream, so it is a write that reaches outside your site, and each call files another one. Reclassified, and report joined the a
fixThe approval link opened a screen that stopped being the product in 7.1. Every approval_url the tools emit pointed at the pre-7.1 Approvals template, while the redesigned queue has lived in the Activity screen's pending,
changeA tool result is no longer a place to sell a plan. Five error strings urged upgrading or linked pricing from inside tool responses, words an assistant would repeat to the person it is helping. Each now states what is tru
August 25, 2026
The native connector told every client that all 300-odd tools reach outside your site
fixThe native connector told every client that all 300-odd tools reach outside your site. openWorldHint was hardcoded true, so update_page, which writes one row in your own database, was advertised exactly like a call out t
fixidempotentHint was missing from every tool. A client had no way to tell whether repeating an interrupted call would create a second thing or land on the same state, which is exactly the question worth answering after a t
August 25, 2026
Every tool's read-only and destructive hints were delivered to nobody
fixEvery tool's read-only and destructive hints were delivered to nobody. The catalog carried readOnlyHint as a top-level property of the tool object, sitting next to name and description. MCP puts those hints inside annota
August 19, 2026
A site connected as read-only was not read-only
fixA site connected as read-only was not read-only. Choosing that scope when connecting a site stored it, and the API keys screen in wp-admin showed the key as read-only, but nothing enforced it: the introspection that deci
addA tool policy per site: full access, agency-safe, or read-only. Set it from the dashboard against a site, and it travels with that site's credential and is applied on the site itself, at the same checks that already gove
addThe stricter of the two settings always wins. A site's own governance profile and the policy on the credential are merged into one blocked set rather than one overriding the other, so a policy cannot widen what a site ad
changeSetting a policy no longer discards a site's approval overrides. Both live in the same stored object, and writing one replaced the whole thing. It merges now
August 19, 2026
A site that was connected and working was told it had no API key
fixA site that was connected and working was told it had no API key. The status badge counted keys minted inside that WordPress install, and a site connected from the dashboard's MCP setup authenticates with a scoped token
August 19, 2026
A row nested inside a column was deleted by any write that rebuilt the page
fixA row nested inside a column was deleted by any write that rebuilt the page. The shortcode parser found a module's closing tag with a non-greedy match on the same tag name, so an outer [et_pb_row] ended where the first i
fixA page that never carried _builder_version had one written onto every module the first time any tool touched it. Divi stamps that attribute itself, so a page authored in the visual builder always has it, but a page assem
fixA specialty section's column widths came back as full width when they were halves. column_structure="1_2,1_2" was rewritten to "4_4,4_4", silently, with the call reporting success. The widths were being inferred from the
fixRespira's internal bookkeeping could end up written into the page. On a module carrying an attribute with no value, the attribute run ends early, the module never enters the tree, its parent row flattens to no children,
addA write that would leave a Divi 4 page with fewer modules than it started with now says so, and for a settings-only edit refuses before writing anything. The existing dropped-children check compared the extracted tree ag
knownA Divi 4 attribute written with no value, such as sticky rather than sticky="on", still ends the attribute run, so that module does not appear in the tree and cannot be addressed by find_element or update_element. Its co
August 19, 2026
One edit to one heading on an Oxygen page deleted the body copy of every rich text element on that page
fixOne edit to one heading on an Oxygen page deleted the body copy of every rich text element on that page. Oxygen Classic writes by re-serialising the whole page tree, and the step that turns a tree node back into an Oxyge
fixapply_builder_patch said it had applied a change it had dropped. The same page, a patch on a rich text element by id: success: true, applied: 1, changed: true, and the text byte-identical afterwards. Two separate problem
fixThe patch response reported the element's type from before the write. operations[].target.type was read off the pre-write tree, so on the write above it cheerfully said oxy_rich_text about an element that had just been t
fixA one-attribute patch on a Divi 4 page quietly removed sixteen others. apply_builder_patch did not patch the document, it parsed the whole thing into a tree and wrote a new document back out. That round trip is lossy on
fixdelete_post returned an empty response and deleted nothing. The tool is approval-gated, and the gate answers with a token and HTTP 202. 202 is a success code, so the connector treated it as a normal reply, and the code p
fixCreating a Theme Builder template without saying where it applied took over every page on the site. Divi records a site-wide template as an empty include list and an empty exclude list, which is byte-identical to a calle
August 19, 2026
An HTML document with a list in it could not be converted to Breakdance at all
fixAn HTML document with a list in it could not be converted to Breakdance at all. The converter mapped a list to EssentialElements\Checkmark_List, and Breakdance does not register that name. Its declared identifier is Chec
fixThe list text was never going to arrive either, so fixing the name alone would have shipped an empty list. The section mapper leaves the <li> elements as children of the list node rather than as its content, and the conv
fixLists now convert to BasicList rather than CheckmarkList. The adapter's own shortcut map already sent the generic list type to BasicList and reserved CheckmarkList for markup that actually asks for checkmarks, so the con
changeThe bundled skills catalog was five releases behind. The Skills screen ships a snapshot of the catalog so it renders on a site with no outbound network, and that snapshot still listed 42 skills while 47 exist. Refreshed,
August 19, 2026
A write receipt said nothing had changed while the Yoast title it had just saved sat in the database
fixA write receipt said nothing had changed while the Yoast title it had just saved sat in the database. The receipt fingerprinted three things: the post content, the builder slug, and the builder payload. Post meta was nev
fixApproving an SEO-only duplicate moved the live page's modified date. The merge called wp_update_post() on every approval, including one where the only difference between the duplicate and the live post was a meta value.
fixA Divi 4 page on a Divi 5 site came back as one opaque block that no targeted edit could reach. Every Divi routing decision asked the site's runtime rather than the page in front of it. On a site where Divi 5 is enabled,
fixcheck_structured_data and analyze_aeo reported no schema on a page whose schema was fine. Both share one detector, and it read the stored post content rather than the page a visitor gets. Rank Math prints its @graph on w
fixAn Elementor widget with no type could still pass the render check. 8.6.28 stopped the emitter writing an untyped widget, which was the corruption itself. It did not teach the validator to see that shape, so the parser c
addAn uninstaller, with the destructive half switched off by default. Deleting the plugin left six tables, about a hundred options, five scheduled jobs and their transients behind, with no documented cleanup list. It now cl
August 19, 2026
delete_post answered with an empty response and deleted nothing
fixdelete_post answered with an empty response and deleted nothing. The tool is approval-gated on the site, and the gate replies with a token and HTTP 202. 202 is a success, so the request resolved normally rather than rais
fixupdate_element and remove_element rejected the two things the ambiguity error told you to use. When several elements matched, the site refused to guess and suggested addressing the element by path or narrowing with match
fixbulk_pages_operation documented a rate limit six times stricter than the real one. It said three runs an hour; the limit is twenty, and dry runs have never counted. Agents plan their work around that number. Corrected, a
changecreate_theme_builder_template no longer assigns anything by default. Omitting assignments used to mean site-wide, which on a body template replaced the content of every page. It now creates the template unassigned, and s
August 19, 2026
html-to-breakdance
addhtml-to-breakdance. The Breakdance counterpart to html-to-bricks, for bringing a Webflow, Framer or CodePen export into a Breakdance site. Breakdance keeps nothing in post_content: the page lives entirely in the _breakda
August 19, 2026
An update to a host that silently drops PUT now completes instead of hanging forever
fixAn update to a host that silently drops PUT now completes instead of hanging forever. 8.1.5 taught the client to retry a write as POST when a host *rejects* PUT, which fires on a status code. This host does not reject it
fixThe fallback cannot execute a write twice. The plugin's idempotency cache keys on the HTTP method, so a PUT that reached PHP and executed, and whose response was then dropped, would not have deduplicated against the retr
fixdiagnose_connection no longer reports a dropped request as "not blocked". It probed with OPTIONS and scored the result by status code, and a probe that times out has no status, so the comparison came out false and the ve
addforceWriteMethod: "post" per site, alongside forceRestRoute, so a host that blocks PUT can be worked around in one line of config without waiting for a release
addpurge_cache. Purges one page or the whole site and reports which caching layers it found and exactly what it called, which it looked for and did not find, and what it skipped and why. Requires plugin 8.6.31
addWooCommerce order reads carry customer_ip_address, customer_user_agent and meta_data, with credential-looking meta keys withheld, counted and named. Requires the WooCommerce add-on 4.0.4
August 15, 2026
Every add_* tool wrote straight to the live published page on sites that had turned direct editing off
fixEvery add_* tool wrote straight to the live published page on sites that had turned direct editing off. add_accordion, add_heading, add_image and the other 24 widget shortcuts went from parameters to the builder's inject
fixApproving a duplicate could merge a customer's edits into an unrelated published page. The merge-target walk followed _respira_original_id off any post carrying it, including a page that had itself been a duplicate once
fixA duplicate's base snapshot recorded an empty page, so rollback had nothing to roll back to. The baseline snapshot was captured before the post meta was copied onto the new duplicate, so builder detection looked at a pos
fixElementor widgets were stored with no type, which took the whole page down with a critical error. A tree that mixed simplified containers at the top with Elementor's native widgetType spelling underneath passed validatio
fixImage alt text and Rank Math FAQ questions reported success and changed nothing. The shared update path treated attributes as a key that was already in the right place, which is true for the builders whose attribute buck
fixA paragraph added to a Gutenberg page was written into a different builder entirely. On a page whose last block had just been removed, the content is empty, so the per-page builder check correctly reported nothing, and t
August 15, 2026
wordpress_deactivate_design_direction reaches npm
addwordpress_deactivate_design_direction reaches npm. The tool was written and dispatching, but was never documented in the public tool list, and the parity check that guards every release refused to publish anything until
fixA tool call with no site_id answered from the default site and said nothing about it. On a connection carrying more than one site, get_site_context, list_pages, list_posts and get_active_site now report which site answer
fixTwo MCP connections on the same machine shared one active-site pointer. The active site was persisted to ~/.respira/state.json under a single key with nothing identifying which connection wrote it, so switching sites in
fixadd_image advertised src as the only way to name an image. Passing a media library image_id was refused with a missing-parameter error. The schema now says either works, and add_testimonial gained the same for its author
August 13, 2026
The reset for a wrongly-inherited connection was locked behind the state it fixes
fixThe reset for a wrongly-inherited connection was locked behind the state it fixes. Respira_License::deactivate_license() already deleted exactly the options that make a cloned site believe it is connected, but it is reac
August 13, 2026
A cloned staging site inherited production's connection and hid its own setup screen
fixA cloned staging site inherited production's connection and hid its own setup screen. WordPress keeps plugin options through deactivate, delete and reinstall, so a staging site cloned from a connected production site cam
August 13, 2026
Two Art Direction companions
addTwo Art Direction companions. wordpress_mint_design_preview returns a short lived signed link that lets the respira.press dashboard frame the real rendered page, drafts included, without changing caching, passwords or vi
August 13, 2026
wordpress_check_design gains rendered mode
addwordpress_check_design gains rendered mode. rendered: true (with Respira for WordPress 8.6.20+) renders the real page at desktop and mobile widths through the respira.press render service and turns the five previously-un
changeThe npm listing tells the truth about the numbers, and a test now keeps it that way. The README carried a 303-tool badge, a 16-builder heading over a table that was missing GreenShift entirely, a 103-tool WooCommerce hea
Respira spoke sixteen page builders. As of 8.0 it also speaks WordPress's own Site Editor: block templates, synced patterns, block navigation and design tokens, readable and writable on the same safety contract as everything else. A navigation link changes by exact block path, not by rewriting the menu. A pattern is created, read back through WordPress, render-checked, then placed by reference. Structural edits can wait for your approval, and every write leaves a snapshot, a normalised diff and a server-render result. The WooCommerce add-on goes to 4.0 alongside it, and its storefront tools now try the native block path first, so a shop built in the Site Editor stops being a place where the store tools quietly go dark. Building all of that meant auditing the safety layer itself, which turned up two places where the safety mechanism was the thing doing the damage: a Divi serialiser rule written for brand-new pages was firing on every write path, and undoing a Theme Builder create could trash a template the agent never created. Both fixed, both pinned by permanent tests.
addNative FSE structure service for templates and template parts with hierarchy/source discovery, exact block-path operations, stale-write fingerprints, structural proposals, snapshots, normalized diffs, cache invalidation,
addNative user-pattern and block-navigation editing on the same structural contract: registered theme/plugin patterns remain read-only; editable user patterns support synced/unsynced state; navigation responses include comp
addFirst-class Site Editor and Gutenberg design-token MCP surfaces.
addAgent-facing activity list/detail endpoints linking audit entries to snapshots, proposals, approvals, and rollbacks.
addShared mutation-result contract for dry runs, pending approvals, verified writes, stored-but-unverified writes, rollbacks, and failures.
addAbility discovery now labels results as Respira-native, inhaled, unavailable, or replaced by a safer Respira workflow and returns the preferred next tool.
changeRewriting a Divi Theme Builder global layout now requires explicit confirmation. update_theme_builder_template refuses the first call with respira_tb_live_edit_confirmation_required, naming the layout and stating that th
July 16, 2026
Released 2026-07-16.
changeReleased 2026-07-16.
addProduct configurator tools (STAGGS). 8 tools: configurator status, per-product enable/disable, attribute-group listing, option-items read and write (through the STAGGS/Carbon Fields helpers, so storage stays consistent), and an allow-listed
add"What an agent could do here" card on the Respira ARC screen: eight copyable real prompts covering catalog fixes, pricing previews, cart links, agent-order reporting and storefront design.
July 16, 2026
Released 2026-07-16.
changeReleased 2026-07-16.
changethe Respira ARC screen is light-only and matches the standard wp-admin chrome (the dark variant read as a foreign app and had contrast problems).
addofficial platform logos (Google, OpenAI, Meta, Pinterest, TikTok) on the format chips and submit links.
changethe fix-prompt button is smaller ("Fix with AI") with a tooltip explaining what the prompt does and what Respira is.
July 16, 2026
Released 2026-07-16.
changeReleased 2026-07-16.
addSubmit links on the feed table. Each feed row links to the right platform dashboard (Merchant Center, OpenAI merchants, Meta Commerce Manager, Pinterest, TikTok) with a one-line where-to-paste instruction on hover.
addA quiet footer with credits and links (add-on, ARC, docs, support), and the agent-tools panel links to the full tool list.
July 16, 2026
Released 2026-07-16.
changeReleased 2026-07-16.
addFix prompts on the quality card. Every failing readiness check now carries a copy-ready prompt for your AI assistant (Claude, ChatGPT, Cursor). Paste it into an assistant connected through Respira and the agent fixes what the check flags, s
addProduct picker for cart links. Choose products by name (variations grouped under their parent, prices shown) instead of typing product IDs. Large catalogs show the first 200 by name.
addThe page title now carries the Respira ARC wordmark, set in Alan Sans (bundled, no external font requests).
July 16, 2026
Released 2026-07-16.
changeReleased 2026-07-16.
adda small provenance line under the Respira ARC page title, so a screenshot instantly shows whether the screen is rendered by this add-on or by the free Respira ARC plugin.
July 16, 2026
Released 2026-07-16. Agent-Ready Commerce: AI assistants can now find, read, and sell from your store. 79 MCP tools (up from 56).
changeReleased 2026-07-16. Agent-Ready Commerce: AI assistants can now find, read, and sell from your store. 79 MCP tools (up from 56).
addProduct feeds in six formats. Google Shopping XML (Merchant Center scheduled fetch; Bing accepts the same file), OpenAI/ChatGPT JSONL, Meta CSV, Pinterest CSV, TikTok CSV, and generic CSV, plus a store llms.txt at the site root. Built in th
addReadiness becomes a fix loop. readiness_fixlist turns the AI-readiness scan into an ordered work queue mapping every failing check to the tool that fixes it; set_image_alt writes the alt text that fails most; update_product gains global_uni
addAssisted checkout with attribution. create_cart_link builds signed multi-item cart URLs: the shopper's cart fills server-side and lands on your own checkout; tampered signatures are rejected. Orders are attributed via WooCommerce native att
addSubscriptions, Bookings, Memberships write tools (14). Tested against the real extensions. Status transitions validated against what each extension allows, booking reschedules include a conflict scan, everything is dry-run by default with s
addRespira ARC admin screen under WooCommerce → Respira ARC: feed URLs with copy buttons, catalog quality score, cart link generator, agent-origin orders, in light and dark admin schemes.
July 16, 2026
Released 2026-07-16.
changeReleased 2026-07-16.
fixrevert_pricing works end to end for the first time. Two defects, both present since the pricing tools shipped in v2.0: the tool passed a numeric snapshot id to the UUID-keyed snapshot store (so the lookup could never match, and the error ob
July 16, 2026
Released 2026-07-16. The full commerce surface: 56 MCP tools (up from 21). Completes the v3.0 rollout that began in June: the release was built and published then, but the update was never offered to customer sites, which kept stores on the
changeReleased 2026-07-16. The full commerce surface: 56 MCP tools (up from 21). Completes the v3.0 rollout that began in June: the release was built and published then, but the update was never offered to customer sites, which kept stores on the
add15 commerce tools now reachable over MCP. The catalog, pricing, inventory, and storefront endpoints (advanced product listing, natural-language product search, catalog health, bulk product/price/stock updates, sale scheduling, pricing rollb
addBrand tools. list/get/create/update/delete-brand REST routes and MCP tools (the abilities existed since 2.2.0; now they're reachable everywhere).
addVariations and attributes. set_product_attributes (global or custom, creates missing terms), generate_variations (cartesian product, skips existing, capped at 100/call), create_variation, set_variation_gallery (variation image + gallery whe
addCoupons and customers. list/create/update_coupon (discount types, expiry, usage limits, product/email restrictions) and create/update_customer (billing and shipping addresses; passwords auto-generate and are never returned).
addOrder notes and refunds. add_order_note (private by default), get_order_refunds, and create_order_refund which is DRY-RUN BY DEFAULT: it previews the refund until you pass dry_run: false, and never touches the payment gateway unless refund_
The plugin now tells the same story as your dashboard
The setup and connection screens were rebuilt around one source of truth. You link a site once, then watch the moment your first agent reaches it: the screen updates on its own and names what just happened, for example "connected. Claude just ran update_page on page #42". The plugin, the dashboard and your agent now read the same connection state, so they always agree on whether a site is connected and what access it has. One-click installs (the Desktop app, Cursor, Cowork) lead the way in, with browser sign-in still there for ChatGPT and claude.ai. Sites also arrive in the dashboard with their real WordPress title instead of a bare URL, which matters the moment you run more than one. And seven builder fixes land across Bricks, Divi, Elementor 4.x and Gutenberg.
addThe setup and connection screens now show your site coming alive. They tell the same story as your respira.press dashboard: link the site once, then watch the moment an agent first reaches it. When an app connects, the s
addYour site now arrives in the dashboard with its real name. The plugin sends your WordPress site title when it activates and when it checks in, so a site shows up by name instead of a bare URL when you manage more than on
fixBricks: moving or nesting an element no longer drops its siblings. Reordering or re-parenting an element on an existing Bricks page used a nested-tree move against Bricks' flat element tree, which could leave other eleme
fixBricks: a link set to open in the same tab now does. Bricks decides whether to open a new tab based on whether the setting is present at all, so switching the toggle off still opened a new tab. The setting is now removed
fixDivi: editing a single module now refreshes the cached CSS. A single-module or update-page edit on Divi did not clear Divi's static CSS cache, so a change could look like it had not applied until the next full save. The
fixDivi: custom post types are no longer corrupted by certain color settings. A color setting that contained square brackets could end the shortcode early and spill raw text into the page. Those characters are now encoded s
What the agent writes is what actually lands on the page
A deep pass through every supported builder, closing the gaps where a write reported success but the page stayed stale or blank. Styling now lands on Oxygen, Beaver Builder, Elementor v4 Atomic, Bricks, Divi 4 and Divi 5. Brizy and Visual Composer move from read to write, with their caveats stated. Recovery gets deeper: custom CSS and page settings are captured, and globals are versioned, so deleting a Bricks global class, a Divi preset, or an Elementor kit color leaves a recovery point. And when something cannot be persisted in a way the builder reads, Respira says exactly what did not land instead of reporting success. Every fix verified on a real site by loading the actual rendered page.
addBrizy moved from read to write. Respira can now write Brizy pages that Brizy's own editor opens and the front end renders. Writes are labeled with their caveats in the docs (front-end compile depends on Brizy's compiler
addVisual Composer moved from read to write. Respira now writes in VC's canonical storage format, so the editor loads the page and the front end renders. Labeled with its caveats (VC recompiles on the next editor save)
addGlobals are now versioned. Deleting a Bricks global class, a Divi preset, or an Elementor kit color now leaves a recovery point. "The agent deleted my global class" used to be unrecoverable; now you can roll it back. Res
addYour own custom CSS and page settings are now captured in snapshots, so the edits Respira makes to things like custom CSS are recoverable, not just the main content
addLoud-drop behaviour across builders. When a value cannot be persisted in a way the builder reads, Respira names exactly what did not land and tells the agent not to retry blindly. This is the systemic version of the per-
addAn internal check now runs across the test fleet to confirm that every builder function Respira calls actually exists in that builder. It would have caught several of the silent failures below the day they were written,
fixOxygen: generated CSS was being written without the selectors it needed, so styles never reached the page. Element styling now renders, and dynamic content resolves correctly. Code blocks that contained quotes could corr
Redesigned admin, public add-on SDK, generate_activity_report
A React-first plugin admin built around live telemetry: a bridge view of agent ↔ Respira ↔ site, real cards driven by eleven new REST endpoints, and a personalised greeting. A public add-on SDK ships so third-party plugin authors can register their own MCP abilities. And a new MCP tool, generate_activity_report, turns this site's audit log into a structured report your own agent shapes into prose — six framings cover the use cases customers actually have, time-saved math is calibrated to conservative per-tool baselines, and Respira never writes a single line of prose itself.
addCode signatures (Respira_Bricks_Signatures). Bricks refuses to render code / svg / queryEditor elements on the frontend unless they carry a signature minted by Bricks with the site secret. Elements pushed through the RES
addStructural autofix (Respira_Bricks_Autofix). Pre-validation repair pass on the build / inject path: strips bare px (skipping raw-CSS / text / url keys), renames div → block, regenerates invalid or duplicate IDs and rewri
addQuirks coercion + warnings (Respira_Bricks_Quirks). Centralises Bricks settings footguns with a clear split: silently coerce the safe ones (link.postId / _link.postId int → string so the href actually emits; harvest imag
addResponsive inference — builder-agnostic. Explicit, idempotent, non-destructive action that generates tablet + mobile breakpoint overrides for a desktop-only page. The scaling tables + fluid clamp() math live in a builder
addDesign-token import (Respira_Design_Token_Import). Bring a Tailwind theme object, a Figma Tokens Studio export, or a Style Dictionary / DTCG file into Bricks. Colours land as palette swatches plus --color-* CSS variables
addSection presets (Respira_Bricks_Section_Presets). A curated library of production-ready Bricks sections (hero, features, CTA, testimonials, pricing, stats, FAQ) an agent drops onto a page. Each flattens to Bricks' native
May 27, 2026
Released 2026-05-27.
changeReleased 2026-05-27.
addProduct brand support (product_brand taxonomy). The update-product and create-product abilities now accept brand_ids so an AI can assign or clear brands on a product the same way it already assigns categories and tags. Full CRUD endpoints l
addFeatured-image removal. The update-product ability now accepts image_id. Pass an attachment ID to set; pass 0 or null to remove the featured image. Previously the only image-related field on the response was a read-only URL; agents had no w
schemaProduct response shape gains brand_ids, brands, and image_id. image is unchanged.
May 19, 2026
wp.org review fixes
changeDisplay name updated to "Inhale: MCP Abilities by Respira" so the author attribution is visible in wp-admin plugin lists. Slug inhale-mcp-abilities is unchanged.
changeContributors field in readme.txt now lists urbankidro (the wp.org username that owns the plugin) instead of the brand string. The Author header still reads "Respira" so the visible attribution on the directory page is un
changeuninstall.php updated to remove the new primary key, the v0.4.0 migration flag, the canonical compat key, and every legacy key from v0.1.x and v0.2.x. Single-site and multisite sweep.
May 18, 2026
WordPress.org Plugin Directory submission
changeCanonical option key. v0.2.0+ stores the opted-in list under mcp_adapter_public_abilities — the same key proposed first-party in [WordPress/mcp-adapter#184](https://github.com/WordPress/mcp-adapter/pull/184). A one-shot
changeBrand-aligned chrome. Header with "by respira.press" Baskervville italic subtitle and a tiny version pill in the right-side toolbar. Light and dark themes both render with AA contrast
changeiOS-style toggle in the Status column for fast per-row inhale / exhale, on top of the standard wp-admin bulk-actions pattern
changeForeign admin notices suppressed on the Inhale settings page only, so the screen stays focused on the one decision it exists to support
changeHardened uninstall. Removes every option the plugin has ever written, single-site and multisite
changePlugin Directory readiness pass. ABSPATH guards on every shipped PHP file. Every output escaped. Every state-changing request nonce-verified and capability-gated. No remote calls, no tracking, no obfuscation, no bundled
May 17, 2026
hardening pass
changewp_die response code 403 + back link on the settings page permission denial path. Access logs and automated clients now see an authorization failure instead of a generic error
changeRow class escaping normalised: the abilities table's <tr class="…"> attribute is always rendered through esc_attr() instead of conditionally injecting the attribute fragment. No behavioral change, but conforms more stric
May 17, 2026
first public release
changeDiscovers every ability registered via the WordPress Abilities API and lists them in a wp-admin native list table.
changeStandard wp-admin selection + bulk-action UX: row checkboxes are selection; Bulk Actions dropdown plus Apply commits Inhale or Exhale immediately. No save-changes step.
changeRow-hover quick actions for single-ability inhale or exhale.
changeAnnotation badges on each ability (read-only, destructive, idempotent) sourced from the ability's declared meta; falls back to heuristic inference from the ability name when the registering plugin didn't tag it.
changeFilter views (All, Inhaled, Read-only, Destructive, Unannotated), a search box that matches across name / source / description, sortable columns, multi-select source filter, client-side pagination (20/50/100/All).
changeSources summary card above the table listing every plugin or theme that registers abilities, with the count per source and deep-links to each source's wp-admin home.
May 10, 2026
Zero-touch Cowork onboarding (Open in Cowork)
change.mcp.json sets RESPIRA_BOOTSTRAP_OK=1 so the npx server boots even without a config file present.
changeExisting RESPIRA_CONFIG_FILE, RESPIRA_AGENT_CLIENT, RESPIRA_AGENT_TRANSPORT env vars unchanged.
changeVersion label bumped in plugin.json and README.md.
changeThe skill-documented config shape ({url, apiKey}) crashed the MCP server silently on startup because the server required four fields (id, name, url, apiKey). User saw "MCP server still connecting…" forever.
changeThe Cowork form echoed pasted API keys into the chat transcript, contradicting the skill's own privacy promise.
change.mcp.json points RESPIRA_CONFIG_FILE at ~/.respira/config.json.
changenpm dependency pinned to @respira/wordpress-mcp-server@latest so the server schema fix lands immediately.
change/respira:connect-site skill rewritten: check for ~/.respira/config.json, point user at the dashboard to download it if missing, restart Cowork, test. Includes a "if startup fails" branch that reads ~/.respira/last-startu
changeREADME.md and INSTALL.md updated to describe the unified flow.
May 9, 2026
audience-first README rewrite
changeEdit a page without opening WP admin ("Update the headline on my client's homepage to say 'spring collection arriving'", about thirty seconds end to end)
changeMigrate a client site between page builders (sixteen supported paths, week of work into an afternoon)
changeAudit a site before a client meeting (SEO, AI search visibility, accessibility, mobile, technical debt, WooCommerce, with one-click fixes)
changeClean up a media library in one pass (alt text, compression, dimensions)
changeManage ten client sites from one conversation (multi-site context follows the conversation naturally)
changeNo code changes.
May 9, 2026
README accuracy pass: 30 skills
change8 slash commands for the most common workflows
change30 auto activating skills, broken down as:
change1 visual reviewer sub agent that shows what changed after every edit
changeFull access to all 180+ Respira MCP tools through the bundled @respira/wordpress-mcp-server
Every page-builder adapter promoted to deeper-intelligence parity
The biggest release since v5. Every builder adapter promoted in lockstep. Five cross-cutting Phase A invariants every adapter now inherits — render-validation gate, universal write-trace, Variables CRUD shape, source-driven catalog auto-scan, per-property typed validators — plus Phase B slices per builder that close the family-bug arcs surfaced across v6.10.x. 1076 standalone test assertions across 27 alpha cycles, zero failures.
phaseA.1 Render-validation gate. Post-write check: HEAD-fetch the preview URL plus parser-walk the persisted blob using the parser the adapter declares. 9 parser slugs ship. Either failing surfaces partial_write: true with st
Closes 14 customer bugs across 5 named trials and 7 GitHub issues
The release I should have shipped weeks ago. Closes 14 customer-reported bugs across 5 named trial threads and all 7 open public GitHub issues, plus 5 cross-cutting audits — JSON post-meta unicode safety across every adapter, MCP server tool-schema audit, duplicator kses bypass, schema endpoints anon-readable, render-trace fields on every write. New respira_diagnose_connection tool surfaces edge-layer interception so REST returning homepage HTML instead of JSON stops being opaque.
Self-updater fatal on every WP cron tick. class-updater.php:104 called \Respira_License::get_license_key() which has never existed on the core License class — every site that activated the add-on threw Uncaught Error: Call to undefined meth
fixSelf-updater fatal on every WP cron tick. class-updater.php:104 called \Respira_License::get_license_key() which has never existed on the core License class — every site that activated the add-on threw Uncaught Error: Call to undefined meth
April 20, 2026
drop keytar, fix whoami after login, unstick terminal, warm welcome
54 ACF tools covering field reads and writes, field-group management, ACF Pro repeaters, flexible content, galleries, options pages, relationships, and bulk updates. Every write snapshot-backed and dry-run previewable. Works on approximately 2 million WordPress sites that use ACF today.
add54 Advanced Custom Fields tools under respira_acf_*. ACF powers flexible content models on approximately 2 million WordPress sites. Before v6.6.0, Respira could only read ACF values through generic post-meta calls, which
addEvery write tool creates before_edit and after_edit snapshots via Respira_Snapshots::capture_snapshot(), audit-logs through Respira_Auth::log_action(), and supports dry_run=true to preview the change without executing. E
addLicense tier gating follows the existing scope model. Reads (get_*, list_*, search_*) require any valid API key and are available on Lite. Writes (update_*, delete_*, create_*) require the write scope and are available o
addACF presence detection in site context. Respira_Context::get_addons_context() now exposes addons.acf.{installed, pro, version, licensed}. MCP server uses this to register ACF tools only on sites where ACF is active and t
tested17/17 direct-handler assertions via mu-plugin probe.
tested54/54 HTTP assertions against the full endpoint surface using a real encrypted API key (wp-now + ACF 6.8.0): 28 free ACF tools return 200 with the expected payload shape, 26 Pro-gated tools correctly return 412 respira_a
changeSix-phase execution cycle: LoadContext -> PreHooks -> Resolve -> Execute -> PostHooks -> Return. Deterministic. Traceable. Every command runs through every phase
changeFive framework hook contracts, frozen for v0.1: before_resolve, filter_plan, before_execute, filter_result, after_execute. In v0.1 no callbacks register. v0.2 populates them. NullHookRegistry swaps for ManifestBackedHook
changeTyped ToolChainFunction<T> abstraction for all 34 commands. Each function declares capability (read | write | destructive), domain tags, and prerequisites
changeFile-organization convention: one BaseCommand subclass per file, one ToolChainFunction per file, always co-located. Named export <camelCasePath>Function
changeStructured JSON tracing via --verbose, written to ~/.respira/traces/{invocationId}.json. Hard cap 10,000 entries per invocation
addOxygen Deep Intelligence: Full intelligence package for Oxygen Builder — 49 components cataloged with properties, types, defaults, and nesting rules. Component registry with dynamic detection and 24-hour caching. JSON Sc
addOxygen Settings Validator: Validates component properties and data types before injection — colors, URLs, emails, numeric values, booleans, and arrays all checked with detailed error messages
Flatsome UX Builder joins as builder #12. 15 new WooCommerce Commerce tools with storefront design intelligence. Context-aware MCP tool filtering reduces tools in context by ~40. Three coordinated releases.
addFlatsome UX Builder as Builder #12: Full support for the most popular WooCommerce theme on ThemeForest (200K+ sales). Extract, inject, element ops, build_page, and snapshots all work. Detection by active theme. Shortcode
addShortcodeParser utility: Shared shortcode parsing and reconstruction for Divi 4 and Flatsome. Parameterized by tag prefix, column format, and detection patterns. Strict tag allowlists prevent cross-builder content confus
addBundled WooCommerce entitlement: Studio and Founder plans now include the WooCommerce add-on at no extra cost. Maker and Builder customers continue to purchase it separately
addContext-aware tool filtering (MCP server v6.0.0): The MCP server now filters the tool list based on detected builder and active plugins. Bricks tools hidden when Bricks is not active, WooCommerce tools hidden when WooCom
addWooCommerce snapshot safety: All existing WooCommerce write tools (create_product, update_product, update_stock) now create before/after snapshots and log to the audit trail. Previously these operations were invisible an
addFlatsome Intelligence package: 55 element definitions with attributes, types, defaults, nesting rules, and responsive patterns. 6 pre-built page patterns for AI agents
7 new Bricks-dedicated tools. Cross-site element search, page health diagnostics, Automatic.css integration, query loop discovery, style profiling, and design system export.
addCross-site element search (respira_search_bricks_elements): Search across ALL pages and templates for Bricks elements by type, global class name, or setting value. Find every instance of a specific element, audit class u
addPage health check (respira_bricks_health_check): Standalone diagnostic tool that detects orphaned elements, duplicate IDs, broken parent/child references, invalid global class references, empty containers, and heading hi
addACSS integration (respira_bricks_detect_acss, respira_bricks_import_acss): Auto-detect Automatic.css (ACSS) installation, read its color/spacing/typography variables, and import utility classes into the Bricks global cla
addQuery loop discovery (respira_bricks_query_loops): Find all Bricks elements that use query loops across the site. Filter by object type (post, term, user) or queried post type (product, page, etc.). Essential for auditin
addStyle profile learning (respira_bricks_style_profile): Analyze a page and extract its design patterns — colors used (with frequency), spacing values, typography (fonts, sizes, weights), and global class usage. Use to lea
addDesign system export (respira_bricks_design_system): Single-call export of the complete Bricks design system — global classes, color palette, theme styles, typography/variables, components, element types, and Bricks vers
65 new tools. Element-level editing across every supported builder, build_page declarative page creation, HTML-to-builder conversion, stock-image search, tool governance, and dynamic schemas for 12 builders.
addElement-level operations: find_element, update_element, move_element, duplicate_element, remove_element, batch_update (atomic), reorder_elements — works across all 11 builders via tree utility or native overrides
addbuild_page: Create complete pages from a declarative structure in a single API call. Returns preview URL
addStock images via Openverse: search_stock_images and sideload_image with CC attribution, domain allowlist, SSRF protection, and deduplication
addTool governance: Per-tool enable/disable with fail-open safety. Single chokepoint for REST + Abilities API. Audit logging
addElementor dynamic schemas: Reads control registry at runtime, maps to JSON Schema types. Settings validator with "did you mean?" suggestions
Every AI edit now has an undo button. New Changes page in wp-admin, storage management, merge-mode default for approvals, and WebMCP write-tool protection. Three months of "can you revert that?" tickets, gone.
Compact MCP responses, working-copy reuse, simpler multi-site setup, and a broad reliability pass driven by a single support ticket from a customer who asked for their money back. They stayed.
addAdded explicit live-edit preflight responses for original pages, posts, custom posts, builder module updates, and builder patch flows when direct editing is enabled. Clients must now choose editTarget: "live" or editTarg
addAdded rollback guidance for live edits, including the WordPress edit-screen URL for revisions and Respira pre-edit snapshot messaging.
addAdded support for dashboard-issued site tokens (respira_site_...) so hosted agency MCP exports can authenticate without per-site plugin-local keys.
addAdded a hosted-dashboard handoff card in wp-admin so agencies can open the dedicated account-wide MCP Setup page for all-sites exports, install commands, and AI setup prompts.
changeMulti-step write flows now reuse the current working duplicate when available and no longer create a duplicate during the confirmation-only preflight response.
changeGET /respira/v2/status now exposes whether direct editing of originals is enabled, so MCP clients can decide when to present live-edit confirmation.
Fixed: WordPress did not show an Enable/Disable auto-updates control for the WooCommerce add-on while it was already current. The updater supplied metadata only when a newer package existed; WordPress also needs an explicit current-version
changeFixed: WordPress did not show an Enable/Disable auto-updates control for the WooCommerce add-on while it was already current. The updater supplied metadata only when a newer package existed; WordPress also needs an explicit current-version
Fixed: nine write tools could not run on hosts that block the PUT method. Those hosts are common enough that Respira already retries such a write as a POST, but these routes were registered to accept PUT only, so the retry arrived at a rout
changeFixed: nine write tools could not run on hosts that block the PUT method. Those hosts are common enough that Respira already retries such a write as a POST, but these routes were registered to accept PUT only, so the retry arrived at a rout
Added: writes now say whether the AI actually looked at what it changed. A write names an id, and until now nothing checked where that id came from, so an assistant that read your catalogue and one that carried an id over from a different s
changeAdded: writes now say whether the AI actually looked at what it changed. A write names an id, and until now nothing checked where that id came from, so an assistant that read your catalogue and one that carried an id over from a different s
Added: size limits on price and stock writes. Every write tool already checked that the caller was allowed to make the change and that the batch was not enormous. None of them checked how far the change went, so "set every product in this c
changeAdded: size limits on price and stock writes. Every write tool already checked that the caller was allowed to make the change and that the batch was not enormous. None of them checked how far the change went, so "set every product in this c
Security: text a customer typed into your checkout no longer reaches your AI assistant as-is. Customer reads returned the name, company and address lines exactly as they were entered, and a tool result is not a document: whatever is in it l
changeSecurity: text a customer typed into your checkout no longer reaches your AI assistant as-is. Customer reads returned the name, company and address lines exactly as they were entered, and a tool result is not a document: whatever is in it l
Fixed: listing orders failed outright on any store that has ever issued a refund. WooCommerce's own order query returns refunds alongside orders by default, and a refund is not an order: it carries no order number, no customer and no billin
changeFixed: listing orders failed outright on any store that has ever issued a refund. WooCommerce's own order query returns refunds alongside orders by default, and a refund is not an order: it carries no order number, no customer and no billin
changeAdded: order lines. Order reads now return each line with its product, its variation and its quantity. Counting sales for one size of a variable product was not possible before: only a total item count came back, and the product report grou
changeFixed: the add-on's test runner only ever ran the tests inside its standalone folder, so two test files sitting next to it, including the one written for an earlier version of this exact refund bug, had never run once. That is why the same
Fixed: setting a category image did nothing and said it worked. update-category only ever read name, slug, description and parent, so image_id fell through untouched, the update ran with nothing to change, and the unchanged category came ba
changeFixed: setting a category image did nothing and said it worked. update-category only ever read name, slug, description and parent, so image_id fell through untouched, the update ran with nothing to change, and the unchanged category came ba
Added: order reads now return customer_ip_address, customer_user_agent and meta_data. Without the request fingerprint and the order meta, the order tools could not support payment-fraud triage at all, and the reporter kept a competing plugi
changeAdded: order reads now return customer_ip_address, customer_user_agent and meta_data. Without the request fingerprint and the order meta, the order tools could not support payment-fraud triage at all, and the reporter kept a competing plugi
changeFixed: the add-on's own test runner exited before printing its results, so a failing test could report success. Any test sorting before version-surfaces was swallowed and the suite still exited zero.
Fixed: the update notice for this add-on could never clear itself. 4.0.2 bumped the plugin header but not the version constant underneath it, and the constant is what the updater reports to the server as your installed version. So every sit
changeFixed: the update notice for this add-on could never clear itself. 4.0.2 bumped the plugin header but not the version constant underneath it, and the constant is what the updater reports to the server as your installed version. So every sit
Fixed: a site running both Respira and this add-on printed "Ability category respira-woocommerce is already registered" on every request. Both plugins registered the same category, so with the add-on installed the collision was guaranteed r
changeFixed: a site running both Respira and this add-on printed "Ability category respira-woocommerce is already registered" on every request. Both plugins registered the same category, so with the add-on installed the collision was guaranteed r
Fixed: an agent orders summary could 500 the whole site on hosts that answer plugin bootstrap before WooCommerce finishes waking up. It now waits for WooCommerce's own readiness signal before touching order data, and falls back to an honest
changeFixed: an agent orders summary could 500 the whole site on hosts that answer plugin bootstrap before WooCommerce finishes waking up. It now waits for WooCommerce's own readiness signal before touching order data, and falls back to an honest
changeFixed: the Observe governance profile closed only 42 of 277 tools despite its own description promising every write closed. It computed its blocked set from an eleven-family category registry, and a tool in no family was never considered; i
changeFixed: add_sale_badge and add_low_stock_badge were flagged read-only while actually writing, which meant a governance profile closing writes left them open and the transport withheld the retry fields that make an interrupted write safe to r
changeFixed: convert_html_to_builder with no builder specified threw a type error on any block-library site (GreenShift, Spectra, Kadence Blocks, GenerateBlocks) instead of converting, because auto-detection asked "is this Gutenberg" by name inst
changeFixed: all five WooCommerce card/checkout tools now declare edit_target and verification_marker in their schemas; the backend has always forwarded both, but no schema advertised them, so they were unreachable from any client.
Storefront intelligence is now FSE-first with page-builder fallback. On a block theme, analysing a shop page returns real structural analysis against the native archive-product template instead of "no page builder detected". The two badge t
changeStorefront intelligence is now FSE-first with page-builder fallback. On a block theme, analysing a shop page returns real structural analysis against the native archive-product template instead of "no page builder detected". The two badge t
changeSale and low-stock badges are POSITIONED: they anchor inside the product image, matching WooCommerce's own card structure, instead of being appended after the add-to-cart button. If a badge is already present the write is refused as a no-op
changeAdded product-card field addressing: discover the card's composition and set attributes on one named field, by canonical WooCommerce block name. Attributes are intersected with the installed block's registered attributes, so an unrecognised
changeupdate_checkout_layout no longer returns "no page builder detected" on a block theme. It returns the honest capability error its sibling tools already returned.
changeThe missing-changes error no longer advertises a parameter that does not exist. It names only the keys the handler reads.
changeThe legacy woocommerce/product-query block is recognised during discovery, so a store on an older card block is no longer told it has no product grid.
Fatal error on HPOS stores (PHP 8). The daily license check, which also gathers a small agent-orders summary for the dashboard, could run on the plugins_loaded hook before WooCommerce initialized its order data store. On stores using High-P
fixFatal error on HPOS stores (PHP 8). The daily license check, which also gathers a small agent-orders summary for the dashboard, could run on the plugins_loaded hook before WooCommerce initialized its order data store. On stores using High-P
Thrive Architect product pages — description edits didn't appear on the frontend — bulk_update_products with description / short_description wrote to post_content via WooCommerce setters, but Thrive Architect renders from its own wp_postmet
fixThrive Architect product pages — description edits didn't appear on the frontend — bulk_update_products with description / short_description wrote to post_content via WooCommerce setters, but Thrive Architect renders from its own wp_postmet
Product category CRUD endpoints and MCP tools (list/get/create/update/delete).
addProduct category CRUD endpoints and MCP tools (list/get/create/update/delete).
addProduct tag CRUD endpoints and MCP tools (list/get/create/update/delete).
changeProduct create/update now supports category and tag assignment payloads for safer taxonomy-aware catalog workflows.
cookies. the legal kind. one click and i'll get out of your way.
what you'd actually be saying yes to
tune your cookie preferences
essentials stay on regardless. the rest is opt-in. nothing fires until you tap save.
essentials
the cookies that make logging in work and remember which partner sent you. switching these off would just break the site, so the law does not let me make you opt out.
first-touch source on a /respira_acq cookie, plus a flag if an ai chatbot referred you. helps me figure out what is working without turning you into a tracking pixel statue.
messaging
customer.io for in-app notes, chatwoot when you click the support bubble. off by default. on means i can actually answer you in the app.