
ShootCal Social Feed displays recent posts from one connected Instagram Business or Creator account on your WordPress website. Connect with Facebook, choose your linked account, and add a shortcode. The plugin refreshes posts on a schedule and serves visitors the last successful WordPress cache without visitor-triggered Instagram API requests.
ShootCal also provides website building, scheduling, booking, contracts, invoices, client galleries, and a print store for photographers.
Features:
[shootcal_instagram_feed feed="1"] anywhere, and later edits apply everywhere.Requirements: a WordPress site using HTTPS and an Instagram Business or Creator account linked to a Facebook Page that you can manage. The Connect with Facebook flow uses ShootCal’s Meta app, so you do not need to create your own developer app. Advanced users can enter their own numeric Instagram account ID and Page access token instead. The plugin uses the official Instagram API with Facebook Login. It does not scrape Instagram or support Personal accounts.
The plugin contacts ShootCal only when an administrator starts or completes Connect with Facebook. During one-click connection, the plugin sends this site’s WordPress admin callback URL, WordPress Address, plugin version, and a one-time cryptographic challenge to the ShootCal OAuth broker at api.shootcal.com. ShootCal redirects the administrator to Meta, temporarily handles the resulting Page-token candidate, and releases it only to this WordPress server after the server proves possession of the one-time verifier. Tokens are never placed in browser URLs. The broker attempt expires after ten minutes.
After connection, this plugin connects to Meta’s Graph API at graph.facebook.com during a scheduled or administrator-requested refresh. It sends the configured Instagram business account ID and Page access token to request the account username, captions, media type, media URLs, post links, timestamps, and carousel cover data. The token is decrypted only for these server-to-server requests and is never included in front-end HTML.
Feed images are served from the remote Meta/Facebook CDN URLs returned by the API. A visitor’s browser therefore connects directly to Meta to load each visible image, which can disclose ordinary request information such as the visitor’s IP address and browser user agent to Meta. The plugin applies a no-referrer policy to image requests.
Service terms and privacy policies:
For help with connection or feed display, contact [email protected]. Include your WordPress and plugin versions and a description of the issue. Never send your access token or Facebook password.