

DebugPay Toolkit logs screen with Payfast payment diagnostics, filters, pagination, and issue labels.
DebugPay Toolkit for Payfast helps WooCommerce store owners, developers, and support teams investigate Payfast payment issues without acting as a payment gateway.
Use it when Payfast payment activity appears successful but a WooCommerce order stays pending, failed, cancelled, on-hold, or unpaid. The plugin creates local payment logs, order debug panels, and reports for comparing order activity, callback delivery, ITN observations, sandbox/live mode signals, and common mismatch symptoms.
The plugin records WooCommerce order creation events for Payfast-related orders, order status changes, likely Payfast ITN/callback metadata on recognized WooCommerce callback routes, and environment diagnostics. It does not change order statuses automatically.
This plugin does not include, register, enable, or replace a payment gateway. For full logging, your site must already have an active Payfast-compatible WooCommerce gateway that creates Payfast orders and receives Payfast callbacks. If no compatible gateway is detected, the admin screen shows setup diagnostics and a non-affiliated checklist.
DebugPay Toolkit for Payfast is an independent diagnostic tool and is not affiliated with, endorsed by, or sponsored by Payfast, WooCommerce, Woo, Automattic, or WordPress.
This plugin does not phone home, track usage, or load remote assets. It stores diagnostic data locally in your WordPress database.
The plugin avoids storing passwords, secrets, passphrases, API keys, sensitive tokens, and card or bank details. Diagnostic log rows include event details, order/payment identifiers, request IP address, and user agent. Customer email and billing phone are masked in generated reports by default.
Sandbox/live diagnostics are read-only. The plugin may inspect safe gateway settings, endpoint hostnames, and callback context to label activity as Sandbox, Live, or Unknown. It does not modify gateway mode and does not read or store Payfast passphrases, API secrets, or sensitive credentials.