We are all feeling the decline in Facebook advertising performance and remarketing audience sizes following the iOS 14.5 update (April 2021). In our previous article, we wrote about the dispute between Facebook and Apple and its massive impact on the advertising ecosystem—all under the guise of user privacy, or more accurately, who will control the new remarketing code standard. Now, on WordPress sites, you can easily set up server-side pixel implementation, also known as Conversions API or CAPI for short, using the PixelYourSite plugin.
What is the PixelYourSite plugin?
The PixelYourSite plugin allows you to automatically implement Facebook, Google (paid version only), and Google Analytics pixels. Using the plugin, you can set up automated events and other advanced settings. Furthermore, the PixelYourSite plugin is great for e-commerce sites, and you can use it to track Google Ads conversions in WooCommerce, build events for your customers, create a Facebook catalog feed, and more.
You can download the plugin for free from the WordPress plugin directory. You can check out the guide we previously wrote explaining how to install the plugin in a few simple steps.
So what exactly is Facebook Server-Side Pixel (CAPI) implementation?
Until now, we used to implement a pixel on the website and the browser would send visitor data to Facebook’s servers. To improve tracking following iOS 14.5 (for the webinar where we discussed this topic and how it will affect us as advertisers – click here), Facebook recommends implementing server-side pixel tracking. That means when a visitor visits your site, your server—and not the browser—will send their details to Facebook. This way, even if the visitor uses an ad blocker or opted out of tracking, the information will still reach Facebook through the server (instead of the browser).
So how do you do it? PixelYourSite’s solution is quite simple and is built into the plugin, and we will easily explain it to you:
How to set up Facebook Server-Side Pixel (CAPI)?
1. You need to obtain your pixel’s token. To do this, go to Events Manager in the Ads Manager menu, select your pixel, and then choose Settings.
2. Scroll down until you see Conversions API, click on Generate Access Token, and copy the token.
3. Add the token to the PixelYourSite plugin – Open the plugin and paste the token into the dedicated field under the Facebook pixel settings. Check the option to send Conversions API and click Save:
How to verify that the server-side pixel implementation is working properly?
To verify that you have implemented the server-side pixel correctly:
1. Go to Events Manager, click on Test Events, and copy the Test Code.
2. Open the PixelYourSite plugin, add the code you copied under test_event_code, and click Save.
If you have a caching plugin, clear the cache:
3. Browse the site to trigger the pixel.
4. Go back to Events Manager, and under Test Events you will see the pixel events working:
You will see that each event was triggered twice: once by the browser and once by the server. Click on the event to view its parameters and Event ID.
Only events that came through the browser where the Events Manager is open will appear under Test Events. If you browse your site in an incognito window or in another browser, events coming through the browser are counted but not reported; in this case, you will only see the server-side events.
To see events only from the server-side pixel, you will need to install an ad blocker and browse your site; this way, Facebook will only receive events from the server side and not from the browser.
5. When you finish testing the server-side pixel installation, remove the testing code from the PixelYourSite plugin.
Facebook Server-Side Pixel (CAPI) acts as a backup for the standard Facebook pixel
Facebook Server-Side Pixel (CAPI) does not replace the standard Facebook pixel; it functions as a backup. If for any reason the Facebook pixel in the browser is inactive (e.g., an ad blocker is present or the user prevented Facebook from tracking them), Facebook will use the server-side pixel.
This means that every pixel is actually sent twice: once via the browser, and once via the server.
Duplicate data from pixels
In order to maintain accurate pixel reporting, Facebook deduplicates the server-side report whenever a report is received from the standard browser pixel. This means that a pixel received twice (both through the browser and the server) will not be counted twice; only the standard pixel will be counted to prevent duplicate reporting of results.
Event ID
Facebook uses two key pieces of data: event name and event ID. Please note—when both a server-side event and a browser event share the same ID, the server-side event is not counted.
PixelYourSite always provides a unique event ID for each server and browser event pair.
Caching issue
Sometimes caching plugins on your site will contain the full Facebook pixel code on the page. This means that as different visitors enter the page, the same pixel fires repeatedly. Sometimes Facebook will view these pixels as the same pixel and therefore ignore these visits.
How to solve the problem?
Open an incognito window and visit the page, check the pixel using Pixel Helper, and locate its Event ID. Refresh the page and check the same pixel again. If the Event ID changed, everything is fine—meaning the Event ID is not cached, there is no pixel duplication, and everything is working properly. Note that Pixel Helper only displays the browser-side pixel, but for this test, that is sufficient.
Shortly, you will learn how to test the server-side pixel as well.
Server-side pixel data
Parameters – When sending a server-side pixel, PixelYourSite tries to send the same set of parameters as the browser-fired pixel. The only parameter we cannot obtain is the time the visitor spent on our page, and therefore this is sent in the regular pixel.
Match Key and User Data Keys – Server-side events also send additional information that helps Facebook match the visitor to a Facebook account: Browser ID, Facebook Click ID (FBC), and Facebook Browser ID (FBP) are collected via Facebook’s code and are called Match Keys. Whenever possible, Facebook collects data on visitors to your site, such as email, first name, IP address, last name, phone, country, city, and zip code; this information is called User Data Keys. The plugin can send user data when someone is logged into your site, using data associated with the WordPress account. Sales data from WooCommerce or Easy Digital Downloads is taken from the order details.
User Match Quality – Using Match Keys and User Data Keys, Facebook attempts to match the pixel to a Facebook account. Since on-site sales events have better access to user information, better results are likely to come from there. In addition, events sent by users who are not logged into their Facebook account will result in a lower match quality.
Troubleshooting
Sometimes we will see errors related to the server-side pixel under the Diagnostics tab. Occasionally, these errors are inaccurate or can be safely ignored.
The server is sending incorrect Match Key parameters for the pixel
The server is sending an invalid value for fbp, ip_address, or user_agent to your pixel; this can happen due to an error in the parameter value. This may cause issues with attribution and campaign optimization for campaigns using this pixel. This error is caused by bots triggering the pixel when the script cannot properly identify the fbp, ip_address, or user_agent.
However, this issue is minor and can be ignored.
Same event ID in server-side pixel received in multiple cases
If you are sending the same event ID on the server side, it may cause measurement issues.
Each server-side event must have a unique ID to prevent identical events received from the pixel and server-side pixel from being counted twice. To ensure Facebook counts events from your pixel accurately, every time a server-side pixel fires it must be unique. This could be related to the caching issue mentioned earlier. Therefore, check your events and ensure that each event sent via browser-server has its own event ID.
Another possible explanation is that the site’s code was copied and is being displayed by other sites. This could be Google’s cache, Google Translate, or another site. However, you can restrict the pixel to only work on your domain under the Settings tab in Events Manager. Look for Traffic Permissions and create a list of allowed sites.
To verify that the event ID is unique for each browser-server event pair, restrict the pixel to your domain only. Once done, you can ignore the issue.
New domain sending data to the pixel
If your pixel has started sending events from new domains, it might be an error, but if not, the solution here as well is to create a list of domains allowed to trigger the pixel.
Go to Events Manager, click on Settings, look for Traffic Permissions, and create a list of allowed domains.
About the Author
Or Fialkov is the CEO and owner of Fialkov Digital, a digital marketing and advertising agency. He runs paid campaigns on Google, Facebook, Instagram, YouTube, LinkedIn, and TikTok, and builds websites and landing pages. He also implements AI in businesses, including AI agents, agentic marketing automation, AI reporting systems, GEO (Generative Engine Optimization), and AI video for campaigns.