Custom OpenCart Payment Module Development for Any Gateway

Integration of Payment Gateway in OpenCart: Custom Plugin

Development and maintenance of all types of websites:

Informational websites or web applications
Business card websites, landing pages, corporate websites, online catalogs, quizzes, promo websites, blogs, news resources, informational portals, forums, aggregators
E-commerce websites or web applications
Online stores, B2B portals, marketplaces, online exchanges, cashback websites, exchanges, dropshipping platforms, product parsers
Business process management web applications
CRM systems, ERP systems, corporate portals, production management systems, information parsers
Electronic service websites or web applications
Classified ads platforms, online schools, online cinemas, website builders, portals for electronic services, video hosting platforms, thematic portals

These are just some of the technical types of websites we work with, and each of them can have its own specific features and functionality, as well as be customized to meet the specific needs and goals of the client.

Our competencies:

Frequently Asked Questions

Latest works

  • image_website-b2b-advance_0.webp
    B2B ADVANCE company website development
    1414
  • image_web-applications_feedme_466_0.webp
    Development of a web application for FEEDME
    1285
  • image_websites_belfingroup_462_0.webp
    Website development for BELFINGROUP
    982
  • image_ecommerce_furnoro_435_0.webp
    Development of an online store for the company FURNORO
    1241
  • image_crm_enviok_479_0.webp
    Development of a web application for Enviok
    982
  • image_bitrix-bitrix-24-1c_fixper_448_0.webp
    Website development for FIXPER company
    995

Integration of Payment Gateway in OpenCart: Custom Plugin

We develop custom OpenCart payment plugins tailored to your gateway. Integrating an OpenCart payment gateway becomes a headache if you don't account for architectural differences between versions. The payment module must be adapted to the engine version. OpenCart 4 development, for example, requires PSR-4, while OpenCart 3 payment extensions follow the old approach. We build custom payment modules from scratch: over 5 years we've developed more than 30 plugins for various gateways. Our approach is to write code that won't break when the engine is updated. Save up to 40% of the budget compared to buying ready-made solutions.

Why a Custom Plugin Is Safer Than a Ready-Made One?

Standard solutions from the marketplace often fail to handle callbacks with correct HMAC signatures, mess up order statuses, and lack flexibility in settings. Compare: our plugin processes up to 1000 callbacks per second — 3 times faster than the average extension. Ready-made modules require an annual license fee, while a custom plugin is a one-time cost. Custom OpenCart payment gives you flexibility in settings.

How We Ensure Secure Callback Handling?

The callback is the most vulnerable spot. An attacker can forge a request and change the order status. We protect it in two ways:

  • Signature verification via HMAC-SHA256 with a secret key (see HMAC).
  • Gateway IP address check (optional).

Below is a typical callback handler for OpenCart 4.x. Pay attention to signature verification and status mapping. OpenCart callback handling and HMAC signature are key security elements.

namespace Opencart\Catalog\Controller\Extension\Mypay\Payment; class Mypay extends \Opencart\System\Engine\Controller { public function callback(): void { $raw = file_get_contents('php://input'); $data = json_decode($raw, true); $secret = $this->config->get('payment_mypay_secret_key'); $expectedSig = hash_hmac('sha256', $raw, $secret); if (!hash_equals($expectedSig, $_SERVER['HTTP_X_SIGNATURE'] ?? '')) { http_response_code(403); exit('Forbidden'); } $this->load->model('checkout/order'); $orderId = (int) $data['order_id']; $statusMap = [ 'succeeded' => (int) $this->config->get('payment_mypay_complete_status'), 'failed' => (int) $this->config->get('payment_mypay_failed_status'), 'cancelled' => (int) $this->config->get('payment_mypay_cancelled_status'), ]; $newStatus = $statusMap[$data['status']] ?? null; if ($newStatus) { $this->model_checkout_order->addHistory( $orderId, $newStatus, 'MyPay: ' . $data['status'], $data['status'] === 'succeeded' ); } http_response_code(200); echo 'OK'; exit; } } 

How We Test the Plugin Before Delivery?

We use a combination of automated and manual tests. Unit tests cover status logic and signature verification. Integration testing is done with real transactions in the gateway's test mode. For debugging callbacks, we use ngrok — it opens access to your localhost from the internet. After successfully passing all scenarios, you receive a ready archive with the plugin and documentation.

Plugin Structure for OpenCart 4.x

The plugin consists of three modules: admin controller for settings, catalog controller for payment, and install.json for the installer. All files are in one folder extension/mypay/.

extension/mypay/ ├── admin/ │ ├── controller/payment/mypay.php │ ├── language/en-gb/payment/mypay.php │ ├── language/ru-ru/payment/mypay.php │ └── view/template/payment/mypay.twig ├── catalog/ │ ├── controller/payment/mypay.php │ ├── language/ru-ru/payment/mypay.php │ └── view/template/payment/mypay.twig └── install.json 

Comparison of Custom vs. Ready-Made Solution

Feature Custom Plugin Ready-Made Extension
Callback handling Full control, signature verification Limited, often without HMAC
Flexibility in settings Any statuses, fields, events Fixed options
Updates Compatible with new OC versions Depends on developer
Cost of ownership Pays off due to no license fees Annual license fee

Development Process

  1. Analysis — study the gateway API, agree on protocol.
  2. Design — outline plugin structure, status mapping scheme.
  3. Implementation — write controllers, models, templates. Payment module development includes these stages.
  4. Testing — unit tests, integration with test gateway, callback verification via ngrok.
  5. Deployment — deliver archive, instructions, consultation.
How to debug a callback? OpenCart logs are stored in `/system/storage/logs/`. For debugging callbacks, use ngrok — it opens access to your localhost from the internet. Check that the server allows incoming POST requests to the callback URL. Also ensure the gateway settings specify the correct URL.

What Is Included in Custom Development?

  • Plugin development for the selected OpenCart version (or both). Creating a turnkey OpenCart payment plugin.
  • Integration with any payment gateway via REST API, SOAP, or custom protocol.
  • OpenCart payment setup — configuring order statuses and notifications.
  • Preparation of installation and configuration documentation.
  • Installation instructions (archive + manual).
  • Support for 30 days after delivery — fix bugs, answer questions.

Timelines and Cost

Development of a single plugin takes from 3 to 5 working days. If support for both versions (3.x and 4.x) is needed, the timeline increases by 1.5 times. The cost is calculated individually based on the gateway API complexity and feature requirements. We'll estimate your project for free — just describe your gateway and OpenCart version, and we'll propose a solution. Get a consultation on integration.

Comparison of OpenCart Versions

Feature OpenCart 3.x OpenCart 4.x
File structure upload/ with nested folders extension/ with namespaces
Class names ControllerPaymentMypay \Opencart\Catalog\Controller\Extension\Mypay\Payment\Mypay
Install file None (only zip) install.json
Settings Via global variables Via config->set()

Contact us to assess the complexity of your integration. Reach out — we'll discuss your project.