Respira for WordPress
Features
Explore
Features See everything Respira can do Respira AER New See it in action Respira products WordPress plugin MCP Server Safe WordPress changes Vulnerability scanner Resonance Exhale: HTML to WordPress New Murmur New Art Direction New
Work with WordPress
Skills Marketplace WooCommerce Add-on ADA & WCAG Scanner Tools Catalog 350+ Agentic WordPress Prompt Book Earn with Respira White Label New
Build & extend
Claude Cowork plugin Respira CLI Respira SDK Playbooks WordPress Abilities What is MCP?

Free WordPress plugins

Inhale: MCP Abilities Respira ARC
Products
Plugin
The WordPress plugin + MCP server that runs the whole Respira stack.
Resonance · New
Persistent site memory for your AI, with enforced rules.
Respira Exhale · New
Drop an HTML file, get a page in your builder's own blocks. In seconds.
Murmur · New
Share a page, get client notes pinned to it. No login.
Art Direction · New
Your design direction, enforced at build time and verified on the rendered page. Free on every paid plan.
Earn · New
Bill clients from a position of knowledge. AI cost per site, per tool, with the multiplier on top.
Claude Cowork plugin · New
Edit live WordPress sites from inside Claude. 17 builders, snapshots, one-click rollback.
Inhale: MCP Abilities · Free
Free plugin. Decide which WordPress abilities your AI assistant can see.
Respira ARC · Free
Free WooCommerce plugin. Product feeds in six formats, a store llms.txt, and an AI-readiness score.
WooCommerce Add-on
104 tools for products, orders, feeds, and storefront design intelligence.
White Label · New
Your studio's name on the plugin in every client site. From €200/yr.
MCP Server
Model Context Protocol spec and 350+ tool catalog.
Tools Catalog
Every tool, all 350+, filterable by builder, license tier, and safety.
CLI · New
Modern WordPress CLI for AI coding agents. One npm install.
SDK · New
Build add-ons + agent integrations on top of the Respira platform.
Skills
53 open-source AI workflows and migration recipes.
Playbooks · New
Typed JSON workflows the agent crystallizes into reusable tools.
Abilities
The 350+ WordPress Abilities Respira registers, browsable and searchable.
ADA & WCAG Scanner
Accessibility compliance checks and automated fixes.
One WordPress connection · every supported AI assistant Explore all features
Works with
Explore
Integrations Every builder and AI Respira works with Figma to WordPress WooCommerce

Migration workflows

Divi 5 Migration Copilot
Page builders
Elementor MCP
Divi MCP
Bricks MCP
Oxygen MCP
Breakdance MCP
Flatsome MCP
Gutenberg MCP
WPBakery MCP
Beaver Builder MCP
AI assistants
Claude Claude Cowork Cursor ChatGPT Codex Hermes Agent OpenCode freecode
Same seatbelt · every assistant · every builder See all integrations
About
Explore
About Respira The story, founder, and reason it exists Manifesto Releases · full changelog Customer reviews Live product telemetry Community
Find your path
WordPress user AI curious Agency Developer Designer Vibe coder
Trust & progress
Trust Center Security model Support Roadmap Case studies Press kit Book a call
About Respira · choose your path or meet the team
Find your path
WordPress UserBuild without code fear AI CuriousGuided AI for WordPress AgencyScale multi-site operations Vibe CoderBuild at the speed of thought DeveloperAI co-pilot for complex stacks DesignerFigma → WordPress, direct
Trust & story
Roadmap LiveShipped, planned, and vote on what's next Meet the founderThe story behind Respira Case studiesReal production workflows ReleasesChangelog · every release Book a call Cal.comTalk with Mihai, the founder ManifestoBuild sites that breathe · sign it Press kitLogos, wordmark, release KVs
Built in Europe · for WordPress people everywhere Meet Respira
Pricing Docs

↑↓ move ↵ open esc close
Blog
Account
Dashboard Sites MCP Setup Skills Prompt Book
Earn with Respira Affiliate Billing Settings
Sign in Start free
Respira
Start free
U Account

Account

Dashboard Sites Earn with Respira Affiliate Billing Settings

Explore

Pricing Docs Blog
Features
Features overview Respira AER Exhale: HTML to WordPress See it in action WordPress plugin MCP server Safe WordPress changes Skills marketplace WooCommerce add-on All products, CLI and SDK Explore all features →
Works with
Integrations overview Claude, ChatGPT, Cursor and other AI Page builders
Elementor MCP
Divi MCP
Bricks MCP
Oxygen MCP
Breakdance MCP
Flatsome MCP
Gutenberg
WPBakery
Beaver Builder
Figma to WordPress WooCommerce Explore all integrations →
About
About Respira Customer reviews Live product telemetry Releases Community Support Trust Center Manifesto
Sign in

SECURITY

How Respira keeps your live site safe

Respira lets an AI edit your real WordPress site, so the safety has to be real too. A restore point on every content change, a copy-first workflow, a plan you read before anything runs, approvals for anything destructive, a plugin update that carries its own way back, switches that hold on every door into the site, scoped keys, and content that never leaves your server.

Last updated September 27, 2026
Scope The safety envelope around AI edits on your live site
Compliance EU data, encryption, GDPR on the Trust Center

Quick navigation

Snapshots & recovery Edit safety Approvals & governance Guarded updates What an agent cannot change Access & keys Connection Your content Audit log

A restore point on every content edit

Every content change Respira makes, to pages, posts, builder layouts, options and the site structure below, creates a restore point first. Snapshots are full fidelity: they capture the page builder's own data, not just rendered HTML, so a rollback brings back the real layout, not a flattened copy.

  • One-click rollback. Roll any change back to the state before it ran.
  • Cascade rollback. One call restores every object changed in a single edit session to its pre-session state, so a multi-step edit undoes cleanly.
  • Structure too. ACF field groups, custom post types, and taxonomies are snapshotted and restorable, not just pages and posts.
  • Deletes go to the trash, with a snapshot. A page, post, custom post or media item an agent deletes is moved to the trash after a snapshot is taken, and the answer carries the snapshot id. A restore brings it back with its old status and slug; media files come back byte for byte. A permanent delete happens only after a snapshot that can recreate the item under the same ID, and if that snapshot cannot be taken, nothing is deleted.
  • Theme files too. A theme file write stores the file's current bytes in a snapshot first. A restore puts the previous content back, or removes a file the write created.
  • What has no undo. WordPress core updates, creating, changing or deleting users, deleting menus or terms, and installing or removing plugins are not snapshotted, and neither is a plugin update outside the guarded update below. Your host's backup is the way back for those, and the destructive ones wait for your approval first.

Copy first, then swap

By default the AI works on a duplicate and you approve the swap. Editing the live original directly is off unless you turn it on.

  • Plan mode. Start a session with mode: plan and every write comes back as a step with its predicted effect, nothing written. You read the plan, and apply_plan runs the accepted steps in order through the same checks as a direct call, with one receipt at the end. It is only tool results, so it works in every MCP client (class-respira-plan-session.php).
  • Content-loss check. Before a swap goes live, Respira checks for unexpected content loss and blocks a risky replace unless you explicitly force it.
  • Stale-base detection. If the original changed since the copy was made, the swap is blocked, so the AI cannot clobber a newer edit you made by hand.
  • Render-checked, on every builder. After a write, Respira reads the saved content the way WordPress does and renders it in process, the block editor included. A broken block, an attribute that does not parse or a heading that renders as nothing is named in the result, next to the snapshot that undoes the write (class-respira-render-validator.php).

Destructive actions need approval

Deleting a page, post, media item, or user, installing or activating a plugin, and bulk operations all require an explicit approval step. Approval tokens expire after 10 minutes, and an approval is for a person: an agent that receives one shows it to you and asks.

Per-tool governance lets you turn any individual tool on or off for a site, so you decide exactly what an AI is allowed to do. Access profiles bundle those switches into one setting: Everything, Content or Observe. Both hold on every door into the site, the npm server, the REST API and the site's own MCP endpoint that Claude Desktop, ChatGPT and Respira AER use, with your per-tool choices stacking on top (class-respira-tool-governance.php).

Abilities from other plugins are off until you enable them by name. One setting, off by default, lets an agent run the ones their plugin declares read-only and not destructive; every such call still passes Respira's safety wrap, the activity log and the plugin's own permission check (class-respira-ability-reach.php).

A plugin update with its own way back

The guarded update brings one wordpress.org plugin to the exact version an advisory names, with a restore point before and a health check after. It runs from the Security page of your dashboard and from the /security card in Respira AER, on one site or a fleet, and every run ends in a receipt (class-respira-guarded-update.php).

  • Preflight. Before anything is written it checks the offer, that the previous version is archived on wordpress.org (a premium plugin is refused: no archive, no rollback), the new version's PHP and WordPress requirements, permission and governance, the backup plugin the site runs, and that the site answers from the server.
  • Restore point, by tier. Duplicator and BackWPup take a fresh backup through their own abilities and the run waits for it. UpdraftPlus is started the way its own command line does and the run reads the record it writes. Any other backup plugin, or none, is a finding, no backup detected, and the one-press path stays closed unless you say in so many words that no restore point is accepted.
  • Four health checks. After the update: the site answers, the front page and the most recently edited page answer, no new fatal in debug.log, and the builder still renders.
  • Rollback. When a check fails, the previous version comes back from wordpress.org.
  • Receipt. The versions, the advisory, every preflight answer, the four checks, the rollback if any and the duration go to the activity log and back to whoever pressed the button.

What an agent cannot change

The options that lock people out of a site are refused to every agent: siteurl, home, admin_email, who may register and with which role, the active plugins and theme, every WordPress key and salt, and Respira's own safety, governance, connection and licence settings. The refusal comes before the snapshot, so nothing is left behind. A filter can add names to the list; it cannot take any away.

  • Secrets stay redacted. Values that look like keys, salts, tokens or passwords read back as [redacted], inside settings arrays too, and WordPress's salts and Respira's own licence key are never returned.
  • Every SVG is cleaned first. An SVG an agent uploads is sanitised before it is stored: scripts, event handlers, foreign objects and every reference to outside content are removed, and one that cannot be parsed, or still carries anything dangerous, is refused. Respira never changes which file types a site accepts (class-respira-svg-sanitizer.php).
  • Site rules are final. A refusal from a site rule ends the attempt. The agent is told to say so, never to work around it, in the rules every channel loads before the first tool call.

Scoped keys, standard WordPress auth

Connect with a WordPress Application Password or a scoped Respira token. Keys are not all-or-nothing.

  • Scopes. Keys carry scopes such as read-only, full-fidelity read, write, and force-approve, so a key only does what you grant it.
  • Encrypted at rest. API keys are encrypted with AES-256-GCM.
  • Rate limited. 1000 calls per key per hour by default, configurable.
  • License-gated. If a license lapses, its keys stop working.

A connection you can see into

Respira's clients send the credential a second time, in a header of Respira's own, and the plugin reads that copy when a request arrives with none, so a host that strips the Authorization header does not end the connection. The copy never overwrites a real Authorization header, is accepted only as a Respira key or access token, and can be switched off with one constant in wp-config.php (class-respira-auth-fallback.php).

  • Troubleshoot. Respira › Troubleshoot in wp-admin runs the connection checks from the site's own server and shows each as pass or fail, with the cause and one next step: the REST API, the Authorization header and Respira's backup header, the MCP address, sign-in discovery, a bot filter that refuses the user agents claude.ai's and ChatGPT's connectors send, the security plugins and CDNs in front of the site, and whether the site can reach respira.press.
  • A report for your host. One button produces a plain-text report: what failed, what to allow, and the id of every test request, with no passwords, cookies, keys or page contents.
  • Errors that say what to do. An error on the connection, sign-in or approval path names its cause (credential, capability, licence, security gate, approval, host environment, and the rest) and says whether sending the same call again can work.

Your content never leaves your server

Respira records operation outcomes only: which action ran, on which resource, how many lines changed, and which builders and plugins were detected. It does not collect, store, or transmit your page or post content, and it cannot see your site content from its dashboard or internal tools.

When you connect an AI tool such as Claude, ChatGPT, or Cursor, the prompts and content you send to that tool are handled under that tool's own terms, not Respira's.

Every action is logged

Each key action is recorded: who, when, what resource, the result, and which AI client and version made the call. The audit log lives on your site, under your control.

  • Write receipts. Every write response states whether stored content actually changed, with a fingerprint of storage before and after the write. A write that changed nothing says so instead of claiming an edit (class-respira-write-receipt.php).
  • Sealed entries. Each audit entry carries a sequence number and a keyed hash chained to the entry before it, so an altered or missing entry is detectable, not silent (class-respira-audit-seal.php).
  • Kept 180 days, by your choice. Entries older than the window are removed once a day, oldest first as one unbroken run, so the seal keeps verifying. The window is set in Respira, Settings, under Audit & approvals: 0 keeps everything, otherwise 7 to 3650 days. An agent cannot change it (class-respira-audit-retention.php).

Infrastructure and compliance, EU data residency, encryption in transit and at rest, Postgres row-level security, GDPR, and sub-processors, live on the Trust Center.

Summarize with Google AI Mode
Respira Respira for WordPress

The AI infrastructure layer for WordPress, open, neutral, ecosystem-friendly.

Start free

Product

  • Plugin
  • MCP server
  • Skills marketplace
  • WooCommerce add-on
  • Safe WordPress changes
  • Vulnerability scanner
  • All products, CLI and SDK
  • Pricing

Proof

  • Reviews
  • Live product telemetry Live
  • Releases
  • Roadmap
  • Case studies

Learn

  • Getting started
  • Prompt Book
  • Page builders
  • CLI docs
  • What is MCP?
  • Blog
  • Edit WordPress with AI, safely
  • AI WordPress for agencies

Builder MCPs

  • Gutenberg
  • Elementor
  • Divi
  • Bricks
  • WPBakery
  • Oxygen
  • Beaver Builder
  • Breakdance
  • Flatsome

Company

  • About Respira
  • Manifesto
  • Trust Center
  • Security model
  • Press kit
  • Affiliates and partners
  • Support ↗
  • Support centre

Community

  • Community
  • Discord ↗
  • Slack ↗
  • Reddit ↗
  • Facebook group ↗
  • GitHub ↗

Reading

  • Respira vs the official WooCommerce MCP
  • WordPress.com AI and Respira
  • Working with Elementor AI
  • Respira and CodeWP
▢ Respira Ecosystem
  • respira.cafe
  • itworks.now
  • centerstudio.io New
Latest from the blog
  • Sep 27
    Respira Exhale, the HTML to WordPress converter: drop an HTML file, get a page in your builder's own blocks Respira Exhale turns a finished HTML page, written by ChatGPT, Claude or a designer, into a page in your WordPress builder's own blocks, in seconds, with no AI in the middle and no tokens from your plan.
  • Sep 22
    WordPress vulnerabilities, September 2026: the ones on sites people actually run Thirty-five critical records in twenty-one days. The plugins with real install numbers behind them, the version that fixes each one, the core release nobody should miss, and the one that no version can fix.
  • Sep 22
    Click2Shell and the 17 September WordPress security release (CVE-2026-93485) The patched release for every WordPress branch back to 4.7, what the reported Click2Shell chain actually needs before it works, why the 9.6 in the headlines is not WordPress's own rating, and the one trace a forced theme install leaves behind.
  • Sep 22
    Admin Menu Editor Pro shipped a backdoor. How to tell whether your site took it. An attacker reached the vendor's update server and two builds went out with a web shell in them. The files, the directory and the database rows to look for, why the version number cannot clear you, and what to do if you find one.
  • Sep 22
    Elementor Pro 4.2.2 closed an unauthenticated file upload (CVE-2026-32475) A form with an upload field was enough for anyone to drop a PHP file into your uploads folder. What the flaw needed, which version fixes it, and the folder worth opening on any site that ran 4.2.1 or below.
  • Sep 18
    Jev in Respira AER: a second model that checks every change your AI makes Jev is a new kind of AI model from TypeSafe that answers typed questions with probabilities instead of writing text. What i found testing it, the one prompting lesson worth knowing, and how Respira AER 0.3 uses it to check every change to a WordPress site.

Independent AI infrastructure for WordPress. Not affiliated with Automattic or WordPress.org.

© 2026 Respira Privacy · Terms · Security · Trust Center · Fair Usage · Disclaimer · Made in Europe
Lines of code updated through Respira

19,013,139

Aggregate telemetry across 3,087 connected WordPress sites, counted from signed tool events and deduplicated by operation ID. Your content never leaves your server.

Progress → 19,500,000

486,861 lines to next milestone

Respira icon Respira for WordPress
Public live telemetry

The independent AI infrastructure layer for WordPress. Duplicate-first, audited, privacy-preserving.

v9.1.1 · shipped Sep 27, 2026
Pages

277,526

Created4,516 Edited277,526 +2,433 / 24h
Posts

42,408

Created13,256 Edited42,408 +385 / 24h
Sites connected

3,087

 
MCP events

710,650

Since Mar 7710,650 +24,484 / 24h

Usage trends

Last 45 days · pages · posts · lines (×100) · MCP events (×10)
Lines (×100) Pages Posts MCP events (×10)

AI tools editing WordPress

710,650 MCP events
Tracked since March 7, 2026 · 3,087 sites
Claude Code Claude Code
48%
197,600 events
Other clients and scripts
13%
52,548 events
Codex Codex
13%
51,783 events
Claude Cowork Claude Cowork
9%
36,226 events
Claude Desktop Claude Desktop
8%
34,556 events
Cursor Cursor
8%
33,524 events
Windsurf Windsurf
<1%
583 events
OpenCode OpenCode
<1%
456 events
Hermes Agent Hermes Agent
<1%
399 events

Page builders

Builder presence across sites
Elementor 975 30%
Divi 661 21%
Beaver Builder 417 13%
Gutenberg 243 8%
Bricks 172 5%
Breakdance 113 4%
Flatsome Ux Builder 91 3%
Oxygen 90 3%
WPBakery 90 3%
Kadence Blocks 41 1%
Spectra 24 1%
Seedprod 17 1%
Wpbakery Tagdiv 15 0%
Thrive Architect 10 0%
Brizy 9 0%
Generateblocks 7 0%
Greenshift 3 0%
Not detected 225 7%

Not detected = no recognized builder.

Global activity

Global activity, last 53 weeks.

Each cell = one day of MCP events across all connected sites · UTC

Streak—days
Best day—events
Today—events
MonWedFri
Less More See full telemetry →
Telemetry is counted from signed tool events and deduplicated by operation ID, refreshed every 60 seconds. Respira never reads or transmits your WordPress content. Only operation outcomes.
All systems normal If you read all the dots, i should probably say thank you. cal.com/mihai-love
cookies. the legal kind. one click and i'll get out of your way.
See What AI Says

LLM-ready prompts about Respira MCP + WebMCP

Ask your favorite AI

Opens in a new tab. These prompts are designed to teach LLMs what Respira can do.

Question copied. Paste it in Gemini