Simple Social Auto Post
Automatically share newly published WordPress content to connected X and Instagram accounts using official APIs.
Install
No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:
wp plugin install https://github.com/dknweb/simple-social-auto-post/archive/refs/heads/main.zipAutomatically share newly published WordPress content to connected X and Instagram accounts using official APIs.
Description
Native settings, OAuth connections, encrypted credentials, editor controls, templates, featured images, a persistent Cron queue, bounded retries and publishing history. No third-party automation service, Composer or frontend scripts required. PHP OpenSSL is required. WordPress must have working outbound HTTPS and a reliable Cron runner.
X supports text or JPEG/PNG image posts. Instagram supports a single public HTTPS JPEG on a professional (Business or Creator) account. Personal Instagram accounts and text-only Instagram posts are not supported by this API flow.
Automatic posting is off by default. Activate separately per site; network activation is intentionally blocked.
Installation
- Upload the simple-social-auto-post ZIP in Plugins > Add New > Upload Plugin, or copy the directory into wp-content/plugins.
- Activate Simple Social Auto Post.
- Configure your X and Meta developer apps, then add the credentials in the plugin settings.
- Open Settings > Social Auto Post. Save app credentials, connect and test the accounts.
- Select post types, templates and providers; enable automatic posting when ready.
- Publish a post and inspect Tools > Social Auto Post Log.
External services and privacy
When an administrator connects an account, OAuth credentials are exchanged with X (x.com, api.x.com) or Meta (instagram.com, api.instagram.com, graph.instagram.com). Connection tests fetch the authorized profile. Daily maintenance refreshes expiring tokens. Enabled publishing sends the rendered message and, when selected, featured image bytes to X or a public image URL to Instagram. Instagram fetches that image from your host. No other service receives plugin data.
Account credentials are encrypted in non-autoloaded WordPress options using keys derived from WordPress salts. Site/server administrators and other privileged plugins can access decrypted credentials; encryption does not protect a compromised WordPress installation. Salt rotation requires reconnecting accounts and re-entering app secrets. Never log HTTP request bodies or token exchange URLs in production debugging tools.
X terms: https://developer.x.com/en/developer-terms/agreement-and-policy X privacy: https://x.com/en/privacy Meta terms: https://developers.facebook.com/terms/ Meta privacy: https://privacycenter.instagram.com/policy/
Queue/history records contain rendered social text and are retained until opt-in uninstall. Deactivation preserves all data and stops scheduled hooks. Disconnect removes local account tokens; revoke app access in the platform dashboard as needed.
Frequently Asked Questions
Why is my job pending?
New jobs trigger an immediate non-blocking Cron wake-up, while the recurring minute event remains the fallback and retry runner. On hosts that disable or block WordPress loopback Cron, use a real server scheduler for reliable production processing.
Will editing a published post share it again?
No. Only transitions into publish enqueue automatic jobs; unique automatic job keys also prevent unpublish/republish duplication. Use the explicit manual form to publish again.
Why was a network failure not retried?
An interrupted final publishing request may already have created a social post. Such ambiguous outcomes stop for administrator review. Safe preparatory requests and explicit rate limits are retried up to three attempts.
Can Instagram post without an image?
No. The image requirement remains enforced. Use a public JPEG up to 8 MB, 320–1440 pixels wide and aspect ratio 4:5–1.91:1. PNG/WebP, private URLs and offloaded images without a readable local copy are rejected.
Are all valid X messages accepted locally?
The lightweight validator conservatively counts complex emoji sequences and URLs. Some messages accepted by X may need shortening. The API remains authoritative.
Changelog
1.0.3
- Trigger an immediate asynchronous queue wake-up when a new social job is recorded, while retaining the recurring Cron worker for retries and fallback processing.
- Keep automatic unpublish/republish deduplication; use manual republishing when a second social post is intentional.
1.0.2
- Store pending OAuth state in user meta with explicit expiry and one-use validation.
- Add safe OAuth callback diagnostics.
- Retain saved Client Secret status indicator.
1.0.0
Initial release: X and Instagram OAuth, templates, per-post controls, background publishing and logs.