https://www.youtube.com/watch?v=9xkrJ2rJ8DM
Inhale: MCP Abilities Manager shows you, on one screen, every action your WordPress site offers to AI agents through the Model Context Protocol (MCP), and lets you decide which of them an AI client may use.
Why this matters now. Since WordPress 6.9, plugins register "abilities": small, named actions such as "get site info", "create a post" or "update a product". The WordPress MCP Adapter turns those abilities into tools that Claude, ChatGPT, Cursor and other AI clients can call. Since adapter 0.6 and WordPress 7.1, a plugin that marks its ability as public makes it reachable by AI clients without the site owner choosing. And you may already run the adapter without knowing it: several popular SEO, page builder, form and store plugins load their own copy.
Inhale puts that decision back with you. Nothing changes until you choose.
What Inhale does
- Lists every registered ability on the site, from every plugin and theme, with what it does and which plugin registered it.
- Lets you switch each one on or off for MCP with a checkbox, or in bulk.
- Shows the safety hints each ability carries: read-only, destructive, idempotent. Filter to read-only abilities in one click. Turning on a destructive ability asks you to confirm.
- Shows your MCP setup at a glance: whether an MCP Adapter is running, its version and which plugin loads it, your endpoint URL, and whether Application Passwords work on this site.
- Gives copy-paste connection steps for Claude Desktop, Claude Code, Cursor, VS Code and WP-CLI.
- Keeps your choice when a plugin author marks an ability public. On WordPress 7.1, every ability gets an explicit decision from you, so "not selected" really means not exposed.
What Inhale does not do
- It does not run an MCP server or handle sign-in. The WordPress MCP Adapter does that, whichever plugin loads it.
- It does not register abilities of its own or change what an ability does. Every ability still runs its own permission checks for the signed-in user.
- It does not phone home, collect telemetry or load anything from outside your site. Nothing is sent anywhere unless you connect a free Respira account for the site check below.
Free with a Respira account: a weekly vulnerability check
Connect a free respira.press account from the Inhale screen, and Inhale checks WordPress core, every installed plugin and every installed theme against more than 40,000 known vulnerabilities from the Wordfence Intelligence database, once a week and whenever you click Check now.
- The Inhale screen shows which plugins or themes have known vulnerabilities, how severe the worst one is, and the version that fixes them.
- Your free Respira dashboard lists every record with its CVE and a link to Wordfence, for every site you connect.
- The same free account includes an accessibility scan of any page on the site.
No card and no trial. Inhale works the same whether you connect or not, and Disconnect removes the connection on both ends. What is sent, and when, is listed under External services below.
Requirements
- WordPress 6.8 or later. The Abilities API is in core from 6.9; on 6.8 it needs the Abilities API plugin.
- PHP 7.4 or later.
- A WordPress MCP Adapter, for AI clients to connect: the MCP Adapter plugin or a copy loaded by another plugin. Inhale shows which one is running. You can make your choices before an adapter is installed; they apply once one runs.
Browse the abilities directory
Respira keeps a public directory of WordPress plugins that register abilities. Browse it at
respira.press/abilities to see what a plugin exposes before you install it.
About MCP
Model Context Protocol (MCP) is an open specification originally developed by Anthropic. Inhale is a third-party plugin and is not affiliated with, endorsed by, or sponsored by Anthropic or OpenAI.
About Respira
Inhale is built and maintained by Respira. Respira's main product, Respira for WordPress, lets AI apps edit WordPress sites in the page builder each site already uses, with a snapshot before every write and one-click rollback, and signs in from
claude.ai and ChatGPT in the browser. Inhale is free and works on its own. Learn more at
respira.press/inhale.
0.7.0
- Added: a free site check. Connect a free Respira account and Inhale checks WordPress, your plugins and your themes against 40,000+ known vulnerabilities from Wordfence Intelligence, every week, and shows what to update. Opt in, off until you connect, listed under External services.
- Added: a link to the free accessibility scan that comes with the same account.
- Changed: uninstalling Inhale also removes the site check connection, unless Respira ARC is still installed and uses it.
0.6.0
- Added: a "Your MCP setup" card at the top of the settings page: whether an MCP Adapter is running, its version and which plugin loads it, the endpoint, whether Application Passwords work on this site, and how many abilities are exposed.
- Changed: Inhale no longer says it needs the MCP Adapter plugin specifically. It works with any copy of the adapter, including the ones other plugins load, and your choices apply as soon as one runs.
- Fixed: the Connection steps showed a config format no client reads and described Application Passwords as "four groups of six" characters. They now show working setups for Claude Desktop, Cursor and VS Code (through @automattic/mcp-wordpress-remote) and for Claude Code (a single command with a one-line Basic header).
- Added: one rating request, a week after you first save a choice, on this page only, with a "No thanks" that is permanent.
0.5.1
- Fixed: activating Inhale on a site already running Respira for WordPress could end in a fatal error. Inhale now steps aside with a notice when Respira has already loaded it.
0.5.0
- Changed: WordPress 7.1 compatibility. 7.1 adds a unified meta.public flag for abilities; every ability now carries an explicit decision from you on the MCP channel, so an ability you did not select stays unexposed even if its author marked it public.
0.4.5
- Added: "Connect with Respira for WordPress" as an option in the Connection section. Links only, no runtime calls.
Earlier versions
The full history is on
GitHub.