ScreenshotNeo

BlogHow-to

URL2PNG API Setup in WordPress for Website Thumbnails

Add URL2PNG website thumbnails to WordPress with a legacy plugin or a server-side v6 API integration, including signing, options, caching, and troubleshooting.

By the ScreenshotNeo team4 October 20269 min read

To add URL2PNG website thumbnails to WordPress, either call the old URL2PNG Screenshots theme function or build a server-side integration around URL2PNG’s current v6 API. For a new integration, keep the API secret and request signing on the server: the v6 token is an MD5 hash derived from the complete query string and secret key, so the exact query string you sign must be the one you send. The WordPress plugin listing documents a theme function, but it is a historical plugin listing and does not establish compatibility with current WordPress.

1. Choose an integration route

Route What the source documents Use it when
URL2PNG Screenshots plugin A theme-callable PHP function named getScreenshot(). You are maintaining an older site and can verify the plugin safely in staging.
URL2PNG v6 API A request URL containing the API key, token, and encoded target/options. You want control over where credentials live, rendering, refresh behavior, and caching.
Cloudinary URL2PNG add-on An integration that requires a Cloudinary account and add-on registration; generated URLs by default require signing or eager generation unless unsigned add-on transformations are enabled. Your site already uses Cloudinary and you want to manage generated assets there.

The current URL2PNG API guide is the source to follow for v6 request construction and supported options. Its documented default viewport is 1480×1037 pixels, full-page capture is off by default, and the documented cache TTL is 2,592,000 seconds (30 days). See the URL2PNG service and current API documentation before deployment in case details have changed.

2. Legacy WordPress plugin route

The plugin directory listing describes a theme function with this signature:

getScreenshot('Website URL', WIDTH, HEIGHT, IMAGETAG, CLASS)

The fourth argument controls whether the function returns an image tag. The listing’s example uses true:

<?php
// Example for a theme template, after installing and configuring the plugin.
echo getScreenshot('https://example.com', 640, 360, true, 'site-thumbnail');
?>

Use this only after checking the plugin code and testing on a staging copy. The listing reports version 1.0.1, 10+ active installations, last updated February 15, 2014, and tested up to WordPress 3.2.1. These are historical listing details, not evidence that it works with current WordPress or current PHP. The listing documents a theme function, not a shortcode. WordPress does support shortcodes as a general plugin mechanism, but you would need a separate shortcode implementation if editors need to insert thumbnails in post content.

3. Build a current API integration on the server

URL2PNG’s v6 URL follows this shape:

https://api.url2png.com/v6/{APIKEY}/{TOKEN}/png/?{query_string}

The API key is assigned during signup and begins with P, according to the guide. The token is the MD5 hash of the entire query string and secret key. The guide’s signing contract is sensitive to the precise construction and encoding order. The example below illustrates the contract; confirm the exact delimiter, parameter encoding rules, and option names against the current official guide, then use one canonical query string for both hashing and sending.

Example PHP helper for a WordPress plugin or theme server-side component:

<?php
/**
 * Build a URL2PNG v6 request URL.
 * Keep the secret in server configuration, never in page HTML or JavaScript.
 * Verify signing and encoding details against the current URL2PNG v6 guide.
 */
function mysite_url2png_url(string $target, array $options = []): string {
    $api_key = getenv('URL2PNG_API_KEY');
    $secret  = getenv('URL2PNG_SECRET');
    if (!$api_key || !$secret) {
        throw new RuntimeException('URL2PNG credentials are not configured.');
    }

    // Example options for a 640 x 360 thumbnail. Keep the query order stable.
    $params = array_merge([
        'url' => $target,
        'viewport' => '640x360',
        'fullpage' => 'false',
    ], $options);

    // RFC 3986 encoding gives a deterministic query string. Confirm this
    // encoding convention matches the current URL2PNG guide exactly.
    $query = http_build_query($params, '', '&', PHP_QUERY_RFC3986);

    // The service guide defines the token from the entire query string and
    // secret. Confirm the precise concatenation format in the guide.
    $token = md5($query . $secret);

    return 'https://api.url2png.com/v6/' . rawurlencode($api_key) . '/' . $token . '/png/?' . $query;
}

// In a WordPress template:
$image_url = mysite_url2png_url('https://example.com');
echo '<img class="site-thumbnail" loading="lazy" src="' . esc_url($image_url) . '" alt="Screenshot of Example">';
?>

Signing caveat: The research confirms that the token covers the entire query string and secret, but the exact concatenation and encoding syntax must match the official guide. Do not deploy a guessed signing expression. Copy the official construction verbatim, then ensure the final bytes used for the token are identical to the query string sent in the URL. A mismatch can produce authentication or signature failures.

Keep credentials private

  • Put the API key and secret in server environment configuration or another server-only secret store.
  • Generate the signed URL on the server. A signed image URL may still be visible to visitors in the rendered HTML; assess whether that URL itself grants access and avoid exposing a reusable secret.
  • Do not calculate the signature in browser JavaScript or embed the private secret in a shortcode attribute.
  • Escape output with WordPress esc_url() and validate that the target is an allowed HTTP or HTTPS URL if users can supply it.

Render through a shortcode when editors need it in content

The URL2PNG plugin listing does not document a shortcode. A custom plugin can register one using WordPress’s Shortcode API. Keep generation server-side, validate attributes, and return escaped markup:

<?php
add_shortcode('website_thumbnail', function ($atts) {
    $atts = shortcode_atts([
        'url' => '',
        'alt' => 'Website screenshot',
    ], $atts, 'website_thumbnail');

    $target = esc_url_raw($atts['url']);
    if (!$target || !in_array(wp_parse_url($target, PHP_URL_SCHEME), ['http', 'https'], true)) {
        return '';
    }

    try {
        $src = mysite_url2png_url($target);
    } catch (Throwable $e) {
        return '';
    }

    return sprintf(
        '<img loading="lazy" class="site-thumbnail" src="%s" alt="%s">',
        esc_url($src),
        esc_attr($atts['alt'])
    );
});
?>

Usage in a post: [website_thumbnail url="https://example.com" alt="Example website screenshot"]. The shortcode is your integration, not a feature documented for the URL2PNG Screenshots plugin.

4. Choose capture options for thumbnails

Option Effect Thumbnail guidance
viewport Sets the browser viewport dimensions. The documented default is 1480×1037. Choose a viewport close to the layout you want to represent, such as a desktop or mobile page.
fullpage Attempts to capture the whole document; default is off. Leave off for a conventional card thumbnail. Enable it when the entire page matters, then resize/crop for display.
thumbnail_max_width Constrains output width. Set near the largest rendered card size to avoid serving unnecessarily wide images.
unique Varies a request to force a fresh capture. Use a stable value for reuse; change it only when the source page should refresh.
delay Waits after document readiness and asset loading. Increase only for pages that render key content late; extra delay increases response time.
ttl Sets cache lifetime; documented default is 2,592,000 seconds (30 days). Use a longer lifetime for stable pages and a shorter one for frequently changing pages.
custom CSS Applies styles during capture. Use when a source page has overlays or layout elements that obscure the content; confirm syntax in the guide.
user agent and accepted language Changes the browser identity and language sent to the target. Use only if the target has materially different localized or responsive behavior.

Use the exact parameter spelling and value format in the current API guide. A sensible starting point for a card is a fixed viewport, fullpage=false, a maximum width matching the display, and a cache lifetime appropriate to how often the target changes.

5. Store, cache, and display the result

The sources establish URL2PNG’s request options and the historical plugin function, but do not prescribe a modern WordPress storage or caching design. The following are implementation patterns to choose based on your site:

  1. Remote image URL: Render the generated request URL in an image tag. This is simple, but the visitor’s browser requests the image from the service and the URL is visible in page markup.
  2. Server-side fetch and media storage: Fetch the rendered image from WordPress, validate the response and content type, save it in the media library, and point the page to the local copy. This can reduce repeated remote dependencies, but requires refresh and cleanup logic.
  3. Refresh on a schedule or editor action: Regenerate only when the target URL changes or a refresh is requested. This avoids making screenshot generation part of every uncached page view.

Whichever route you choose, avoid generating a new unique value on every page view: that defeats reuse and can create unnecessary capture requests. Use WordPress transients, a persistent object cache, or stored attachment metadata for your own integration if suitable, and define an explicit refresh path. These are general WordPress patterns, not URL2PNG-certified instructions.

Or skip the browser setup

ScreenshotNeo is a website screenshot API and MCP server for developers. A single GET request returns PNG, JPEG, WebP, or PDF output. For WordPress, generate the URL server-side and store or render the response according to your site’s needs. See the API documentation.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

ScreenshotNeo removes cookie banners, newsletter popups, and chat widgets before capture. Bot checks, blank pages, and failed loads are never billed. Its MCP server lets AI agents take screenshots. The Free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000. Every feature is on every plan. Sign up for ScreenshotNeo’s free plan.

Troubleshooting

Symptom Likely cause What to check
Authentication or invalid token response The signed query differs from the sent query, an option changed after signing, or the signing expression does not match the official contract. Build the query once, sign that exact string, send it unchanged, and compare encoding and concatenation to the current v6 guide.
Target URL appears malformed The target was not encoded as a query value, or it was encoded twice. Use the guide’s URL encoding order and inspect the final request URL for a correctly encoded target.
Thumbnail shows an old page A cached response is still valid under the TTL. Use the documented refresh mechanism such as a changed unique value, or adjust TTL intentionally.
Important content is missing The site renders content after the capture becomes ready. Try an appropriate delay; check whether a different viewport or full-page capture is needed.
Plugin function is undefined The plugin is inactive, unavailable, or incompatible; the theme call may also run before plugin loading. Confirm activation and function availability in staging. Given the listing’s age, prefer a maintained custom server-side integration if it cannot be verified.
Shortcode prints literally or returns nothing The shortcode was not registered, code is not loaded, or validation rejected the URL. Register it in an active plugin, check the shortcode tag, and pass an HTTP or HTTPS URL.

Performance, reliability, and cost

  • Page latency: Do not synchronously generate thumbnails during every front-end request. Prefer pre-generation, stored output, or cache reuse so a slow target does not delay a WordPress page render.
  • Refresh: Match refresh cadence to how frequently the target changes. URL2PNG documents a 30-day default TTL; the current guide also documents a unique option to vary a request.
  • Failure handling: Keep an existing thumbnail when a refresh fails, record failures for diagnosis, and retry later with a bounded schedule. These are general reliability recommendations; the reviewed URL2PNG sources do not specify WordPress retry behavior.
  • Cost: The research sources do not establish URL2PNG pricing, so check its current service page and account terms. Reusing cached images and avoiding needless forced refreshes limits redundant work. ScreenshotNeo’s stated pricing is Free for 1,000 per month, Starter $5 for 3,000, Growth $15 for 15,000, Pro $39 for 60,000, Scale $99 for 250,000, and Business $249 for 1,000,000; yearly billing gives two months free.

FAQ

Does URL2PNG provide a current WordPress shortcode?

The reviewed plugin listing documents a PHP theme function, not a shortcode. WordPress lets plugin authors create shortcodes, so a site can implement one around its own server-side integration.

Can I put the signing secret in the page source?

No. Keep the secret on the server. The generated request URL may be visible in HTML, so evaluate whether exposing that URL is acceptable for your use case.

Should a thumbnail use full-page capture?

Usually not for a card image. Use a fixed viewport for a representative fold; use full-page capture when the whole document needs to be represented.

Is the old plugin known to work on current WordPress?

The directory details supplied here do not establish that. Test on staging and review the code before relying on it.

Sources