{"id":369736,"date":"2026-10-05T20:03:18","date_gmt":"2026-10-05T20:03:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/payfast-pro-gateway-for-woocommerce\/"},"modified":"2026-10-06T16:55:11","modified_gmt":"2026-10-06T16:55:11","slug":"skillmerc-payment-gateway-for-payfast","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/skillmerc-payment-gateway-for-payfast\/","author":23564524,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.1.2","stable_tag":"0.1.2","tested":"7.1.3","requires":"6.4","requires_php":"7.4","requires_plugins":null,"header_name":"Skillmerc Payment Gateway for PayFast","header_author":"Skillmerc","header_description":"A reliable PayFast payment gateway for WooCommerce with dependable ITN order sync, refunds from the order screen, HPOS support and every setting on one screen.","assets_banners_color":"162a4b","last_updated":"2026-10-06 16:55:11","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/profiles.wordpress.org\/skillmerc\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":228,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.1.1":{"tag":"0.1.1","author":"skillmerc","date":"2026-10-05 20:03:06","revision":3729615},"0.1.2":{"tag":"0.1.2","author":"skillmerc","date":"2026-10-06 16:55:11","revision":3731263}},"upgrade_notice":{"0.1.1":"<p>Naming and link fixes. No functional changes.<\/p>","0.1.0":"<p>First release.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3729993,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3729993,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3729993,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3729993,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.1.1","0.1.2"],"block_files":[],"assets_screenshots":[],"screenshots":{"1":"The gateway settings: every option on one screen, with sandbox and live credentials kept apart.","2":"PayFast at checkout.","3":"The PayFast payment ID and fee on the WooCommerce order screen, with the refund button available.","4":"The debug log showing an ITN callback validated and applied."}},"plugin_section":[],"plugin_tags":[15615,6593,27219,286,284582],"plugin_category":[45],"plugin_contributors":[284583],"plugin_business_model":[],"class_list":["post-369736","plugin","type-plugin","status-publish","hentry","plugin_tags-payfast","plugin_tags-payment-gateway","plugin_tags-south-africa","plugin_tags-woocommerce","plugin_tags-zar","plugin_category-ecommerce","plugin_contributors-skillmerc","plugin_committers-skillmerc"],"banners":{"banner":"https:\/\/ps.w.org\/skillmerc-payment-gateway-for-payfast\/assets\/banner-772x250.png?rev=3729993","banner_2x":"https:\/\/ps.w.org\/skillmerc-payment-gateway-for-payfast\/assets\/banner-1544x500.png?rev=3729993","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/skillmerc-payment-gateway-for-payfast\/assets\/icon-128x128.png?rev=3729993","icon_2x":"https:\/\/ps.w.org\/skillmerc-payment-gateway-for-payfast\/assets\/icon-256x256.png?rev=3729993","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>Skillmerc Payment Gateway for PayFast lets South African stores take payments through PayFast's hosted payment page (card, instant EFT, SnapScan and Mobicred) and keeps WooCommerce order statuses in step with what PayFast actually reports.<\/p>\n\n<p>It was written to fix the things South African merchants complain about most: order statuses that never update because the ITN callback silently fails, no refund path from the order screen, no High-Performance Order Storage support, and settings scattered across several screens.<\/p>\n\n<p><strong>What it does<\/strong><\/p>\n\n<ul>\n<li>PayFast hosted checkout for card, instant EFT, SnapScan and Mobicred.<\/li>\n<li>One toggle to switch between the PayFast sandbox and your live account. Each mode keeps its own credentials, so switching back and forth never means retyping keys.<\/li>\n<li>Order status sync through Instant Transaction Notification (ITN), with signature verification, source host verification, amount matching, server confirmation and replay protection. Every rejection is logged with the reason, so a broken callback is diagnosable instead of silent.<\/li>\n<li>Refunds sent to PayFast straight from the WooCommerce order screen (needs API access on your PayFast account).<\/li>\n<li>Full High-Performance Order Storage (HPOS) compatibility, with no legacy post meta.<\/li>\n<li>Optional South African number formatting for Rand amounts (R 1 234,56).<\/li>\n<li>Works the moment you activate it: sandbox mode is on with PayFast's published test credentials already filled in.<\/li>\n<li>Every setting is on one screen, at WooCommerce \u2192 Settings \u2192 Payments \u2192 Skillmerc Payment Gateway for PayFast.<\/li>\n<\/ul>\n\n<p><strong>External services<\/strong><\/p>\n\n<p>This plugin talks to PayFast, and only to PayFast. There is no tracking, no analytics and no phone-home of any kind.<\/p>\n\n<ul>\n<li>Shoppers are redirected to <code>https:\/\/www.payfast.co.za<\/code> (or <code>https:\/\/sandbox.payfast.co.za<\/code> in sandbox mode) to complete payment. The order number, order total, item description and the billing name and email address are sent so PayFast can process and receipt the payment.<\/li>\n<li>When PayFast notifies your store of a payment, the plugin posts the notification back to <code>https:\/\/www.payfast.co.za\/eng\/query\/validate<\/code> (or the sandbox equivalent) to confirm PayFast really sent it. This is PayFast's documented server confirmation step and is what makes a forged callback unusable.<\/li>\n<li>If you switch refunds on, refund requests are sent to <code>https:\/\/api.payfast.co.za<\/code>. This only happens when you refund an order in WooCommerce, and the setting is off by default.<\/li>\n<li>Source host verification does a DNS lookup of PayFast's ITN hostnames. You can switch it off with the <code>wc_payfast_pro_verify_itn_source<\/code> filter if your host sits behind a proxy.<\/li>\n<\/ul>\n\n<p>PayFast is a service of DPO South Africa (Pty) Ltd. Terms: https:\/\/payfast.io\/legal\/ and privacy policy: https:\/\/payfast.io\/privacy-policy\/<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin folder to <code>\/wp-content\/plugins\/<\/code>, or install it from Plugins \u2192 Add New.<\/li>\n<li>Activate the plugin.<\/li>\n<li>Go to WooCommerce \u2192 Settings \u2192 Payments \u2192 Skillmerc Payment Gateway for PayFast.<\/li>\n<li>Set your store currency to ZAR under WooCommerce \u2192 Settings \u2192 General. PayFast only accepts South African Rand.<\/li>\n<li>Place a test order with sandbox mode on. When you are happy, untick sandbox mode and enter your live merchant ID, merchant key and salt passphrase from your PayFast dashboard.<\/li>\n<\/ol>\n\n<p>You do not need to configure a notify URL in your PayFast dashboard. The plugin sends its own ITN callback URL with every payment.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"do%20i%20need%20a%20payfast%20account%3F\"><h3>Do I need a PayFast account?<\/h3><\/dt>\n<dd><p>Yes. Register at payfast.co.za, then copy the merchant ID and merchant key from Settings in your PayFast dashboard.<\/p><\/dd>\n<dt id=\"why%20is%20payfast%20not%20showing%20at%20checkout%3F\"><h3>Why is PayFast not showing at checkout?<\/h3><\/dt>\n<dd><p>The gateway hides itself when it cannot complete a payment. Check that your store currency is ZAR and that a merchant ID and merchant key are filled in for the mode you are in (sandbox or live).<\/p><\/dd>\n<dt id=\"my%20orders%20stay%20on%20hold%20and%20never%20move%20to%20processing.\"><h3>My orders stay on hold and never move to processing.<\/h3><\/dt>\n<dd><p>That means the ITN callback is not arriving or not passing validation. Switch the debug log on in the gateway settings, place a test order, and read WooCommerce \u2192 Status \u2192 Logs, source <code>wc-payfast-pro<\/code>. The log names the exact reason: signature mismatch, amount mismatch, unknown source host or failed server confirmation. A signature mismatch is almost always a salt passphrase that is set in your PayFast dashboard but not in the plugin, or the other way round.<\/p><\/dd>\n<dt id=\"can%20i%20refund%20from%20woocommerce%3F\"><h3>Can I refund from WooCommerce?<\/h3><\/dt>\n<dd><p>Yes, once you tick the refunds setting. PayFast has to enable API access on your account first, and you must have a salt passphrase set. Refunds are not available in sandbox mode, because PayFast's sandbox does not implement the refunds API.<\/p><\/dd>\n<dt id=\"is%20this%20hpos%20compatible%3F\"><h3>Is this HPOS compatible?<\/h3><\/dt>\n<dd><p>Yes. The plugin declares compatibility with High-Performance Order Storage and reads and writes order data through the WooCommerce CRUD API only.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20the%20checkout%20block%3F\"><h3>Does it work with the checkout block?<\/h3><\/dt>\n<dd><p>Yes. The gateway registers a payment method with the checkout block as well as the classic shortcode checkout, so it appears in both.<\/p><\/dd>\n<dt id=\"does%20this%20plugin%20send%20my%20data%20anywhere%3F\"><h3>Does this plugin send my data anywhere?<\/h3><\/dt>\n<dd><p>Only to PayFast, only to process your payments, and only as described in the Description section. There is no telemetry.<\/p><\/dd>\n<dt id=\"is%20this%20the%20official%20payfast%20plugin%3F\"><h3>Is this the official PayFast plugin?<\/h3><\/dt>\n<dd><p>No. It is an independent plugin and is not affiliated with or endorsed by PayFast or DPO.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>0.1.2<\/h4>\n\n<ul>\n<li>Fixed: ITN signatures are now checked the way PayFast computes them (every posted field, including empty custom fields), and against the values exactly as posted. Before this fix genuine notifications were rejected with \"Invalid signature\" and orders stayed pending. Found against the live sandbox.<\/li>\n<li>Fixed: the default sandbox credentials now use PayFast's shared sandbox account with a passphrase (10004002), because the passphrase-free account rejects signed requests.<\/li>\n<li>Added: a \"Reverse proxy\" setting that reads the notification source from X-Forwarded-For for sites behind a proxy or CDN.<\/li>\n<\/ul>\n\n<h4>0.1.1<\/h4>\n\n<ul>\n<li>Plugin and author links point to live pages.<\/li>\n<li>The gateway uses the plugin's own name in the WooCommerce settings.<\/li>\n<\/ul>\n\n<h4>0.1.0<\/h4>\n\n<ul>\n<li>First release.<\/li>\n<li>PayFast hosted payment page checkout with sandbox and live modes.<\/li>\n<li>ITN listener with signature, source host, amount, server confirmation and replay checks.<\/li>\n<li>Refunds from the WooCommerce order screen.<\/li>\n<li>HPOS support and a cart\/checkout block payment method integration.<\/li>\n<li>Optional ZAR display formatting.<\/li>\n<\/ul>","raw_excerpt":"A dependable PayFast gateway for WooCommerce: reliable ITN order sync, refunds from the order screen, HPOS support, one settings screen.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/369736","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=369736"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/skillmerc"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=369736"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=369736"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=369736"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=369736"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=369736"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=369736"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}