Universal Payment Gateway for WooCommerce
WooCommerce payment gateway plugin
by Universal Payment Gateway · github.com/raivis-kalnins/woo-payment-gateway
Install
No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:
wp plugin install https://github.com/raivis-kalnins/woo-payment-gateway/archive/refs/heads/master.zipUniversal Payment Gateway for WooCommerce is a provider-independent hosted-payment gateway framework for WooCommerce. It replaces the original single Rack Group/NatWest-style setup with a universal admin interface where multiple payment providers can be configured, enabled, disabled, tested and displayed at checkout independently.
Summary
The plugin creates one WooCommerce payment method called Universal Payment Gateway. Inside that method, the store owner can enable one or more provider options. At checkout, customers see the enabled providers as selectable payment choices, and the selected provider is saved to the WooCommerce order.
This update is designed to be independent from the old Rack Group naming and project path. The plugin folder and main file are now named for the universal gateway:
- Folder:
universal-payment-gateway-for-woocommerce - Main file:
universal-payment-gateway-for-woocommerce.php - Text domain:
universal-payment-gateway - Gateway ID:
universal_payments_gateway
Backward-compatible legacy callback hooks are still registered so old/pending transactions from the original version do not fatal after upgrade.
Requirements
- WordPress
- WooCommerce
- PHP version compatible with your active WooCommerce version
- HTTPS enabled on the live site
- Merchant credentials from each payment provider you want to enable
Included providers
Each provider has its own admin tab/section and can be enabled or disabled independently.
UK banks and UK-focused providers
- NatWest
- Barclays
- Lloyds
- HSBC
- Standard Chartered
Wallets, card processors and WooCommerce ecosystem providers
- PayPal
- Amazon Pay
- Square
- WooPayments
- Stripe
Latvia and Baltic providers
- Swedbank
- SEB
- Luminor
International provider
- Revolut
What each provider tab includes
Every provider section includes:
- Provider on/off control
- Customer-facing checkout label
- Customer-facing checkout description
- Test/Live mode selector
- Test Gateway URL
- Live Gateway URL
- Test Merchant / Store ID
- Live Merchant / Store ID
- Test Shared Secret
- Live Shared Secret
- Provider-specific help text explaining what details are required
- Admin-side Test configuration button
Only enabled providers are shown to customers at checkout.
Important integration note
This plugin is a universal hosted redirect framework. It does not replace every official provider extension.
The original payment flow was based on a hosted/IPG-style redirect with a SHA-256 hash and posted payment fields. NatWest/IPG-style defaults are included because that is closest to the original implementation.
Some providers, such as PayPal, Amazon Pay, Square, WooPayments, Stripe and Revolut, often require provider-specific APIs, official WooCommerce extensions, wallet buttons, webhooks, tokenisation, refund APIs, Payment Intents or hosted checkout sessions. Their tabs are included for cases where the provider, bank or payment service provider supplies a hosted redirect endpoint, merchant/store ID and signing secret.
Before enabling any provider in Live mode, confirm the following with that provider or PSP:
- Correct test and live endpoint URLs
- Required request fields
- Required response fields
- Hash/signature algorithm
- Callback/webhook format
- Allowed currencies
- Settlement account and merchant ID
- Whether 3D Secure is required
- Whether IP allowlisting is needed
Installation
- Download the plugin zip.
- Go to WordPress Admin > Plugins > Add New Plugin > Upload Plugin.
- Upload the zip file.
- Activate Universal Payment Gateway for WooCommerce.
- Go to WooCommerce > Settings > Payments.
- Enable Universal Payment Gateway.
- Click Manage.
- Configure the general settings and the provider tabs you need.
Upgrade from the old Rack Group plugin
The new package is provider-independent. For a clean migration:
- Back up the site files and database.
- Deactivate the old plugin if it is still active.
- Upload and activate the new full plugin package.
- Go to WooCommerce > Settings > Payments.
- Configure Universal Payment Gateway.
- Re-enter or verify provider credentials.
- Place a test order before enabling Live mode.
Legacy callback URLs from the old single-provider version are still registered for compatibility, but new orders should use the Universal callback URLs generated by this plugin.
General settings
The General settings control the whole WooCommerce payment method.
| Setting | Description |
|---|---|
| Enable / Disable | Turns the whole gateway on or off at checkout. |
| Checkout Title | Main payment method title shown to the customer. |
| Checkout Description | Intro text shown above provider options. |
| Default Provider | Provider pre-selected at checkout when it is enabled. |
| Transaction Type | Sale or Pre-Auth. |
| Debug Log | Writes gateway debugging information to WooCommerce logs. |
Provider settings
Each provider has matching settings.
| Setting | Description |
|---|---|
| Provider Status | Enables or disables that provider at checkout. |
| Checkout Label | Provider name shown to the customer. |
| Provider Description | Short description shown under the provider option. |
| Mode | Select Test or Live credentials. |
| Test Gateway URL | Sandbox/test hosted payment endpoint. |
| Live Gateway URL | Production hosted payment endpoint. |
| Test Merchant / Store ID | Sandbox merchant/store identifier. |
| Live Merchant / Store ID | Production merchant/store identifier. |
| Test Shared Secret | Sandbox signing secret. |
| Live Shared Secret | Production signing secret. |
| Test configuration | Checks required fields and basic URL reachability. |
The Test configuration button does not run a real transaction. It validates that the selected provider has the required local values and performs a lightweight URL reachability check.
Provider connection guidance
NatWest
Use this tab for NatWest/IPG-style hosted payment pages. Enter the Store ID and Shared Secret supplied by NatWest, keep Test mode enabled first, complete test orders, then switch to Live mode after approval.
Barclays
Create or access your Barclays merchant/payment gateway account. Copy the hosted payment endpoint, merchant/store ID and signing secret into the Barclays tab. Confirm the required hash/signature format before Live mode.
Lloyds
Use the credentials and hosted payment URL supplied by Lloyds/Cardnet or the connected PSP. Confirm the required request fields and hash format with Lloyds before taking live payments.
HSBC
Enter the hosted payment URL, merchant ID and secret supplied by HSBC or the HSBC payment gateway provider. Test with sandbox details before Live mode.
Standard Chartered
Add the hosted payment endpoint and merchant credentials supplied by Standard Chartered or its PSP partner. Confirm supported currencies, required fields and response validation rules.
PayPal
For full PayPal Checkout, refunds, webhooks and wallet buttons, the official PayPal WooCommerce integration is usually required. This tab is for hosted redirect/payment-link style endpoints where those are supplied by the provider or PSP.
Amazon Pay
For native Amazon Pay buttons and buyer wallet features, use the official Amazon Pay integration. This tab supports hosted redirect configurations only where endpoint and credentials are supplied.
Square
For Square card forms, refunds, inventory sync and native APIs, use the official Square WooCommerce integration. This tab is for hosted Square/payment-link style endpoint setups.
WooPayments
WooPayments normally runs as its own WooCommerce extension. This tab can be used only where a hosted redirect endpoint and signing credentials are available from the payment setup.
Stripe
For native Stripe Elements, Payment Intents, refunds and webhooks, use the official Stripe WooCommerce extension. This tab supports hosted redirect or hosted checkout URL style configurations where endpoint and secret are supplied.
Swedbank
Use Swedbank Baltic e-commerce credentials or PSP-provided hosted payment credentials. Add endpoint, merchant ID and signing secret, then test each required Baltic market and currency.
SEB
Use the SEB merchant portal or PSP documentation to obtain the hosted endpoint, merchant ID and signing secret. Test EUR payments before enabling Live mode.
Luminor
Enter the hosted payment URL and merchant credentials supplied by Luminor or the chosen Baltic PSP. Confirm exact response fields, callback behavior and hash validation before live use.
Revolut
For native Revolut Pay, card processing and API-based payment flows, use Revolut Business/API credentials or the official integration. This tab is for hosted redirect configurations where endpoint and secret are supplied.
Checkout behaviour
When the whole gateway is enabled and at least one provider is enabled:
- Customer selects Universal Payment Gateway at checkout.
- Customer selects one enabled provider inside the gateway.
- The selected provider is stored on the order.
- The plugin builds the hosted redirect request using that provider's active Test or Live settings.
- Customer is redirected to the provider's hosted payment page.
- The provider redirects or notifies the WooCommerce callback URL.
- The order is marked paid, failed or left pending based on the response validation.
If no provider is enabled, the gateway will not be available for checkout.
Callback URLs
The plugin automatically sends these callback URLs in the hosted payment request:
- Success URL:
/?wc-api=wc_gateway_universal_payments_response - Failure URL:
/?wc-api=wc_gateway_universal_payments_response - Notification URL:
/?wc-api=wc_gateway_universal_payments_notify
Use the full site URL version of these URLs when the provider portal asks you to enter callback URLs manually.
Example:
https://example.com/?wc-api=wc_gateway_universal_payments_response
https://example.com/?wc-api=wc_gateway_universal_payments_notify
Testing checklist
Before going live:
- Enable the whole gateway.
- Enable only the provider you are testing.
- Set that provider to Test mode.
- Add Test Gateway URL, Test Merchant / Store ID and Test Shared Secret.
- Click Test configuration.
- Place a WooCommerce test order.
- Confirm the customer reaches the hosted payment page.
- Complete the sandbox payment.
- Confirm the WooCommerce order status changes correctly.
- Confirm order notes contain the selected provider and approval details.
- Repeat for each provider.
- Switch a provider to Live mode only after the provider confirms approval.
Debugging
Enable Debug Log in the General settings to write diagnostic entries to WooCommerce logs.
Logs can usually be found under:
WooCommerce > Status > Logs
Do not share logs publicly if they include order IDs, customer details, merchant IDs or gateway responses.
Security notes
- The plugin is designed for hosted payment pages, so card data is not collected directly on the WooCommerce site.
- Always use HTTPS in Live mode.
- Keep shared secrets private.
- Do not send shared secrets by email or chat.
- Restrict admin access to trusted users.
- Confirm provider-specific webhook signing and callback validation.
- Confirm whether the provider requires IP allowlisting.
- Test in staging before production.
Limitations
- This is not a complete native API integration for every listed provider.
- Provider-specific features such as tokenised cards, Apple Pay, Google Pay, refunds, disputes, subscriptions and saved payment methods may require official provider plugins or custom API work.
- Each provider may require different request/response fields. The included framework provides a common hosted redirect structure and configurable credentials.
Changelog
1.0.0
- Renamed the plugin to Universal Payment Gateway for WooCommerce.
- Renamed folder and main file to remove Rack Group-specific naming.
- Added provider-independent admin wording.
- Added separate provider sections for NatWest, Barclays, Lloyds, HSBC, Standard Chartered, PayPal, Amazon Pay, Square, WooPayments, Stripe, Swedbank, SEB, Luminor and Revolut.
- Added provider on/off controls.
- Added provider Test/Live configuration.
- Added provider checkout labels and descriptions.
- Added provider help descriptions.
- Added admin-side configuration test button.
- Added checkout provider selector.
- Saved selected provider to WooCommerce orders.
- Retained legacy callback compatibility.
Support / customisation notes
For full production support, each provider should be checked against that provider's current integration documentation. Where a provider requires a native API or official extension, this plugin should be extended with provider-specific request creation, response validation, webhook handling and refund support.
Version 1.0.1 payment processor error hardening
This release adds extra protection for IPG/NatWest-style hosted payment errors such as:
Your transaction may not be completed successfully. Unknown application error occurred.
The plugin now:
- Removes empty optional billing/shipping fields before posting to the hosted gateway.
- Sends only the required minimum payment fields plus non-empty customer fields.
- Does not send
threeDSRequestorChallengeIndicatorby default, because unsupported or incorrectly formatted 3-D Secure fields can cause hosted gateway application errors. - Adds an optional setting to send
threeDSRequestorChallengeIndicator=01only when the processor asks for it. - Adds a provider-level hash encoding option:
SHA256 over hex-encoded string, the common IPG Connect format.SHA256 over raw string, for processors that require raw-string hashing.
- Adds compatibility fallback for NatWest settings from the original Rack Group plugin option key.
- Blocks redirects before leaving checkout if required fields such as
storename,oid,chargetotal,currencyor URLs are missing. - Improves debug logging for generated outbound fields without logging the shared secret or hash value.
Troubleshooting: Store Id or Order Id blank on the gateway error page
If the hosted gateway error page shows blank values such as Store Id: or Order Id:, check the following:
- Confirm the enabled provider tab is the one selected at checkout.
- Confirm the active mode is correct: Test credentials must use the Test Gateway URL, and Live credentials must use the Live Gateway URL.
- Confirm the Store ID is copied exactly from the payment processor portal. Do not use the merchant legal name unless the processor says that is the Store ID.
- Confirm the Shared Secret belongs to the same Store ID and environment.
- Enable Debug Log and check WooCommerce > Status > Logs >
universal-payment-gatewayto confirm thatstorename,oid,chargetotal,currency,txndatetime, and callback URLs are present before redirect. - Keep 3-D Secure Challenge Indicator disabled unless the processor specifically asks for it.
- Use
SHA256 over hex-encoded stringfor standard IPG Connect/NatWest-style accounts. Switch to raw only if the processor documentation says so.
If all fields are present in the debug log but the gateway still shows the error, the most likely causes are wrong environment URL, Store ID not enabled by the processor, incorrect shared secret, or a processor account that does not use the IPG Connect hosted-form field set.