Title: Skillmerc Payment Gateway for PayFast
Author: skillmerc
Published: <strong>October 5, 2026</strong>
Last modified: October 6, 2026

---

Search plugins

![](https://ps.w.org/skillmerc-payment-gateway-for-payfast/assets/banner-772x250.
png?rev=3729993)

![](https://ps.w.org/skillmerc-payment-gateway-for-payfast/assets/icon-256x256.png?
rev=3729993)

# Skillmerc Payment Gateway for PayFast

 By [skillmerc](https://profiles.wordpress.org/skillmerc/)

[Download](https://downloads.wordpress.org/plugin/skillmerc-payment-gateway-for-payfast.0.1.2.zip)

 * [Details](https://wordpress.org/plugins/skillmerc-payment-gateway-for-payfast/#description)
 * [Reviews](https://wordpress.org/plugins/skillmerc-payment-gateway-for-payfast/#reviews)
 *  [Installation](https://wordpress.org/plugins/skillmerc-payment-gateway-for-payfast/#installation)
 * [Development](https://wordpress.org/plugins/skillmerc-payment-gateway-for-payfast/#developers)

 [Support](https://wordpress.org/support/plugin/skillmerc-payment-gateway-for-payfast/)

## Description

Skillmerc Payment Gateway for PayFast lets South African stores take payments through
PayFast’s hosted payment page (card, instant EFT, SnapScan and Mobicred) and keeps
WooCommerce order statuses in step with what PayFast actually reports.

It was written to fix the things South African merchants complain about most: order
statuses that never update because the ITN callback silently fails, no refund path
from the order screen, no High-Performance Order Storage support, and settings scattered
across several screens.

**What it does**

 * PayFast hosted checkout for card, instant EFT, SnapScan and Mobicred.
 * One toggle to switch between the PayFast sandbox and your live account. Each 
   mode keeps its own credentials, so switching back and forth never means retyping
   keys.
 * Order status sync through Instant Transaction Notification (ITN), with signature
   verification, source host verification, amount matching, server confirmation 
   and replay protection. Every rejection is logged with the reason, so a broken
   callback is diagnosable instead of silent.
 * Refunds sent to PayFast straight from the WooCommerce order screen (needs API
   access on your PayFast account).
 * Full High-Performance Order Storage (HPOS) compatibility, with no legacy post
   meta.
 * Optional South African number formatting for Rand amounts (R 1 234,56).
 * Works the moment you activate it: sandbox mode is on with PayFast’s published
   test credentials already filled in.
 * Every setting is on one screen, at WooCommerce  Settings  Payments  Skillmerc
   Payment Gateway for PayFast.

**External services**

This plugin talks to PayFast, and only to PayFast. There is no tracking, no analytics
and no phone-home of any kind.

 * Shoppers are redirected to `https://www.payfast.co.za` (or `https://sandbox.payfast.
   co.za` in sandbox mode) to complete payment. The order number, order total, item
   description and the billing name and email address are sent so PayFast can process
   and receipt the payment.
 * When PayFast notifies your store of a payment, the plugin posts the notification
   back to `https://www.payfast.co.za/eng/query/validate` (or the sandbox equivalent)
   to confirm PayFast really sent it. This is PayFast’s documented server confirmation
   step and is what makes a forged callback unusable.
 * If you switch refunds on, refund requests are sent to `https://api.payfast.co.
   za`. This only happens when you refund an order in WooCommerce, and the setting
   is off by default.
 * Source host verification does a DNS lookup of PayFast’s ITN hostnames. You can
   switch it off with the `wc_payfast_pro_verify_itn_source` filter if your host
   sits behind a proxy.

PayFast is a service of DPO South Africa (Pty) Ltd. Terms: https://payfast.io/legal/
and privacy policy: https://payfast.io/privacy-policy/

## Installation

 1. Upload the plugin folder to `/wp-content/plugins/`, or install it from Plugins  
    Add New.
 2. Activate the plugin.
 3. Go to WooCommerce  Settings  Payments  Skillmerc Payment Gateway for PayFast.
 4. Set your store currency to ZAR under WooCommerce  Settings  General. PayFast only
    accepts South African Rand.
 5. Place a test order with sandbox mode on. When you are happy, untick sandbox mode
    and enter your live merchant ID, merchant key and salt passphrase from your PayFast
    dashboard.

You do not need to configure a notify URL in your PayFast dashboard. The plugin 
sends its own ITN callback URL with every payment.

## FAQ

### Do I need a PayFast account?

Yes. Register at payfast.co.za, then copy the merchant ID and merchant key from 
Settings in your PayFast dashboard.

### Why is PayFast not showing at checkout?

The gateway hides itself when it cannot complete a payment. Check that your store
currency is ZAR and that a merchant ID and merchant key are filled in for the mode
you are in (sandbox or live).

### My orders stay on hold and never move to processing.

That means the ITN callback is not arriving or not passing validation. Switch the
debug log on in the gateway settings, place a test order, and read WooCommerce  
Status  Logs, source `wc-payfast-pro`. The log names the exact reason: signature
mismatch, amount mismatch, unknown source host or failed server confirmation. A 
signature mismatch is almost always a salt passphrase that is set in your PayFast
dashboard but not in the plugin, or the other way round.

### Can I refund from WooCommerce?

Yes, once you tick the refunds setting. PayFast has to enable API access on your
account first, and you must have a salt passphrase set. Refunds are not available
in sandbox mode, because PayFast’s sandbox does not implement the refunds API.

### Is this HPOS compatible?

Yes. The plugin declares compatibility with High-Performance Order Storage and reads
and writes order data through the WooCommerce CRUD API only.

### Does it work with the checkout block?

Yes. The gateway registers a payment method with the checkout block as well as the
classic shortcode checkout, so it appears in both.

### Does this plugin send my data anywhere?

Only to PayFast, only to process your payments, and only as described in the Description
section. There is no telemetry.

### Is this the official PayFast plugin?

No. It is an independent plugin and is not affiliated with or endorsed by PayFast
or DPO.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“Skillmerc Payment Gateway for PayFast” is open source software. The following people
have contributed to this plugin.

Contributors

 *   [ skillmerc ](https://profiles.wordpress.org/skillmerc/)

[Translate “Skillmerc Payment Gateway for PayFast” into your language.](https://translate.wordpress.org/projects/wp-plugins/skillmerc-payment-gateway-for-payfast)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/skillmerc-payment-gateway-for-payfast/),
check out the [SVN repository](https://plugins.svn.wordpress.org/skillmerc-payment-gateway-for-payfast/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/skillmerc-payment-gateway-for-payfast/)
by [RSS](https://plugins.trac.wordpress.org/log/skillmerc-payment-gateway-for-payfast/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 0.1.2

 * Fixed: ITN signatures are now checked the way PayFast computes them (every posted
   field, including empty custom fields), and against the values exactly as posted.
   Before this fix genuine notifications were rejected with “Invalid signature” 
   and orders stayed pending. Found against the live sandbox.
 * Fixed: the default sandbox credentials now use PayFast’s shared sandbox account
   with a passphrase (10004002), because the passphrase-free account rejects signed
   requests.
 * Added: a “Reverse proxy” setting that reads the notification source from X-Forwarded-
   For for sites behind a proxy or CDN.

#### 0.1.1

 * Plugin and author links point to live pages.
 * The gateway uses the plugin’s own name in the WooCommerce settings.

#### 0.1.0

 * First release.
 * PayFast hosted payment page checkout with sandbox and live modes.
 * ITN listener with signature, source host, amount, server confirmation and replay
   checks.
 * Refunds from the WooCommerce order screen.
 * HPOS support and a cart/checkout block payment method integration.
 * Optional ZAR display formatting.

## Meta

 *  Version **0.1.2**
 *  Last updated **6 hours ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.4 or higher **
 *  Tested up to **7.1.3**
 *  PHP version ** 7.4 or higher **
 * Tags
 * [payfast](https://wordpress.org/plugins/tags/payfast/)[payment gateway](https://wordpress.org/plugins/tags/payment-gateway/)
   [south africa](https://wordpress.org/plugins/tags/south-africa/)[woocommerce](https://wordpress.org/plugins/tags/woocommerce/)
 *  [Advanced View](https://wordpress.org/plugins/skillmerc-payment-gateway-for-payfast/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/skillmerc-payment-gateway-for-payfast/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/skillmerc-payment-gateway-for-payfast/reviews/)

## Contributors

 *   [ skillmerc ](https://profiles.wordpress.org/skillmerc/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/skillmerc-payment-gateway-for-payfast/)