FreeAdvancedPHP 8.1+v1.3

PHP Payment Gateway Integration

Integrate Stripe and PayPal payments into your PHP application with pre-built checkout flows, secure webhook handling, subscription management, invoice generation, and a payment administration dashboard.

Overview

Accepting payments online requires careful attention to security, reliability, and compliance. This script provides a tested integration layer for both Stripe and PayPal that handles the complexity of payment processing so you can focus on your application logic. It supports one-time payments, recurring subscriptions, and invoice-based billing.

The architecture uses a provider-agnostic payment service interface, making it easy to switch between Stripe and PayPal or offer both options to your customers. Webhook handlers process asynchronous events like successful charges, failed payments, subscription renewals, and disputes. All payment data is logged in your database for reconciliation and reporting.

Key Features

  • Stripe Checkout session creation
  • Stripe Elements for embedded card forms
  • PayPal Smart Payment Buttons
  • PayPal Checkout SDK integration
  • Secure webhook signature verification
  • Automatic retry for failed webhooks
  • Subscription creation and management
  • Plan upgrades and downgrades
  • Invoice generation with PDF export
  • Refund processing
  • Payment admin dashboard
  • Multi-currency support

Code Example

Creating a Stripe checkout session with the payment service:

// Initialize the payment service $payment = new PaymentService( provider: 'stripe', config: $config['stripe'] ); // Create a one-time checkout session $session = $payment->createCheckout([ 'items' => [ ['name' => 'Pro License', 'price' => 4900], ], 'currency' => 'usd', 'success_url' => '/payment/success', 'cancel_url' => '/payment/cancel', 'metadata' => ['user_id' => $userId], ]); // Redirect to hosted checkout header('Location: ' . $session->url); // Webhook handler (separate endpoint) $payment->handleWebhook($payload, $signature, [ 'checkout.session.completed' => function($event) { // Fulfill the order activateLicense($event->metadata->user_id); }, ]);

Webhook Security

Webhooks are the most critical part of any payment integration. This script verifies every incoming webhook using the provider's signature mechanism. For Stripe, it validates the Stripe-Signature header against your webhook secret. For PayPal, it verifies the event through PayPal's verification API. Invalid signatures are rejected with a 400 response and logged for security auditing. Webhook events are stored in a database table with idempotency checks to prevent duplicate processing.

Subscription Management

The subscription module handles the full lifecycle of recurring billing. Create plans with different pricing tiers, intervals, and trial periods. Customers can upgrade or downgrade between plans with prorated charges calculated automatically. The system handles renewal successes, payment failures with grace periods, and cancellations. Subscription status changes are synchronized via webhooks so your application always reflects the current billing state.

Installation Steps

  1. Download and extract the script files to your web server
  2. Install dependencies: composer require stripe/stripe-php paypal/paypal-checkout-sdk
  3. Import database.sql for payments, subscriptions, and webhook log tables
  4. Edit config.php with your Stripe and PayPal API keys
  5. Configure webhook endpoints in your Stripe and PayPal dashboards
  6. Test with Stripe test mode and PayPal sandbox before going live

Server Requirements

RequirementMinimumRecommended
PHP Version8.18.3+
DatabaseMySQL 5.7MySQL 8.0+
PHP ExtensionsPDO, curl, json, OpenSSL+ mbstring
ComposerRequiredLatest version
HTTPSRequiredRequired (TLS 1.2+)

Security Considerations

This script never stores raw credit card numbers or sensitive payment data. All card processing happens on Stripe or PayPal's servers via their hosted checkout or tokenized Elements. Your server only receives payment tokens and webhook events. API keys are stored in environment configuration files outside the web root. All database queries use prepared statements, and webhook endpoints are protected against replay attacks with timestamp validation.

Admin Dashboard

The included admin dashboard gives you an overview of payment activity including recent transactions, revenue charts, subscription metrics, failed payment alerts, and dispute notifications. Filter transactions by date, status, customer, or payment method. Export transaction data to CSV for accounting and reconciliation. The dashboard is protected by the authentication system and can be restricted to admin-role users.