ShootCal Social Feed
ShootCal Social Feed

ShootCal Social Feed

0/5 (0 ratings) — active installs Updated Sep 19, 2026

ShootCal Social Feed displays recent posts from one connected Instagram Business or Creator account on your WordPress website. Connect with Facebook, choose your linked account, and add a shortcode. The plugin refreshes posts on a schedule and serves visitors the last successful WordPress cache without visitor-triggered Instagram API requests.

ShootCal also provides website building, scheduling, booking, contracts, invoices, client galleries, and a print store for photographers.

Features:

  • Feed assets load only on pages containing a feed.
  • Responsive image grid with no jQuery or heavy libraries. Static embeds need no JavaScript; dynamic embeds use one small deferred script.
  • Images, video thumbnails, Reels, and carousel cover images.
  • Exact, case-insensitive caption hashtag filtering with a single tag, any-of lists, and optional exclusions.
  • Saved feeds: name a filter set once in ShootCal Apps > Social Feed, paste [shootcal_instagram_feed feed="1"] anywhere, and later edits apply everywhere.
  • Shortcode-specific hashtags and display limits.
  • Optional five-desktop/four-mobile layout and account follow button.
  • Optional post-load refresh that bypasses full-page caches while reading only WordPress’s saved feed.
  • Scheduled cache refresh with a last-known-good fallback.
  • One-click Facebook authorization through ShootCal, plus manual-token fallback.
  • Manual refresh and connection status in ShootCal Apps > Social Feed.
  • Preview saved Smash Balloon feed imports, map existing shortcode IDs, and explicitly switch with an undo option.

Requirements: a WordPress site using HTTPS and an Instagram Business or Creator account linked to a Facebook Page that you can manage. The Connect with Facebook flow uses ShootCal’s Meta app, so you do not need to create your own developer app. Advanced users can enter their own numeric Instagram account ID and Page access token instead. The plugin uses the official Instagram API with Facebook Login. It does not scrape Instagram or support Personal accounts.

External services

The plugin contacts ShootCal only when an administrator starts or completes Connect with Facebook. During one-click connection, the plugin sends this site’s WordPress admin callback URL, WordPress Address, plugin version, and a one-time cryptographic challenge to the ShootCal OAuth broker at api.shootcal.com. ShootCal redirects the administrator to Meta, temporarily handles the resulting Page-token candidate, and releases it only to this WordPress server after the server proves possession of the one-time verifier. Tokens are never placed in browser URLs. The broker attempt expires after ten minutes.

After connection, this plugin connects to Meta’s Graph API at graph.facebook.com during a scheduled or administrator-requested refresh. It sends the configured Instagram business account ID and Page access token to request the account username, captions, media type, media URLs, post links, timestamps, and carousel cover data. The token is decrypted only for these server-to-server requests and is never included in front-end HTML.

Feed images are served from the remote Meta/Facebook CDN URLs returned by the API. A visitor’s browser therefore connects directly to Meta to load each visible image, which can disclose ordinary request information such as the visitor’s IP address and browser user agent to Meta. The plugin applies a no-referrer policy to image requests.

Service terms and privacy policies:

  • ShootCal Terms of Service: https://shootcal.com/terms/
  • ShootCal Privacy Policy: https://shootcal.com/privacy/
  • ShootCal data-deletion instructions: https://shootcal.com/data-deletion/
  • Meta Platform Terms: https://developers.facebook.com/terms/
  • Meta Privacy Policy: https://www.facebook.com/privacy/policy/

Support

For help with connection or feed display, contact [email protected]. Include your WordPress and plugin versions and a description of the issue. Never send your access token or Facebook password.