Charitable Blog

Everything you need to know about Charitable and our team.

How PayPal’s SSL Certificate Upgrade Will Affect You — And How You Can Prepare for It

Last updated on

  • By

PayPal is in the process of making a series of security-related upgrades to its platform. Many of these changes won’t take effect until midway through 2017, but one important change is happening next month (October 2016).

Here’s what you need to know about PayPal’s SSL Certificate upgrade and how it might affect you.

How Charitable’s PayPal integration works

Before we unpack the implications of PayPal’s SSL Certificate upgrade, I’m going to tell you a little story about Joe.

Joe really loves the work that Awesome Charity is doing to support rural communities in northern Africa. He reads about their current fundraising campaign and decides to donate $50.

After filling out a donation form, Joe is directed to PayPal where he finishes making his donation.

Behind the scenes, PayPal sends a message to Awesome Charity’s website to advise that Joe has completed a payment for the donation (this message is called the Instant Payment Notification, or IPN).  Now, Awesome Charity has to check that PayPal really sent that message, since there are nasty people out there that know how to fake these kinds of messages. PayPal responds and basically says: “Yeah, that was me.”

That’s the confirmation that Awesome Charity’s website needs to process Joe’s donation. It already recorded Joe’s donation when he first filled out the donation form, but now it marks it off as Paid.

All of that behind the scenes stuff happens without Joe or anyone from Awesome Charity doing anything. The back-and-forth conversation between Awesome Charity’s website and PayPal is usually finished within seconds.

How Will the SSL Upgrade Change This?

This basic process will remain the same after PayPal’s SSL Certificate upgrade takes place. As far as Joe is concerned, everything will work pretty much the same. He will still be able to make a donation, and Awesome Charity will still receive the money.

But if Awesome Charity’s website is running on a web server with some old libraries, that little behind the scenes conversation may stop working. Awesome Charity will still get PayPal’s original message to say the donation has been paid for, but when it asks PayPal to confirm, PayPal might send back a message like this:

cURL error 35: error:14077410:SSL routines:SSL23_GET_SERVER_HELLO:sslv3 alert handshake failure

That’s basically PayPal’s way of giving the cold shoulder.

That turns out to be really annoying for Alice, who is the campaign manager for Awesome Charity. When she logs into their website and checks their latest donations, she sees Joe’s donation but it’s still listed as Pending. She now has to log into Awesome Charity’s PayPal account to check whether Joe’s donation is showing up there.

What You Can Do About It

If you’re like Alice, you don’t want to be stuck spending all day cross-referencing the donations you receive with your PayPal account records. Here is what you should do.

1. Check whether you’re affected

Hopefully, you won’t have any issues at all when PayPal’s SSL certificate is upgraded. If your web hosting company is responsible and cares about the security of its customers’ websites, they’ve probably already made sure this won’t be a problem for you. But you should still check, so here’s how:

  1. You’ll need to create a couple of PayPal sandbox accounts. Here’s a guide showing just how to do that.
  2. After you have done that, log into your WordPress dashboard and go to Charitable > SettingsPayment Gateways. Click on the “Gateway Settings” button for PayPal.
  3. Scroll down to the “Run a Test Donation” section (if you don’t see it, make sure you have updated Charitable to version 1.4.3):Screenshot showing the test donation tool in Charitable's PayPal settings
  4. In the “Sandbox Seller Email Address” field, enter the email address of the Merchant account you created a moment ago in PayPal’s sandbox.
  5. Click on “Make a Test Donation”.
  6. You will be redirected to PayPal, where you should complete the donation using the Buyer account you created in step 1.
  7. When done, click on the PayPal link to return back to your website, where you should see a message telling you whether your site can communicate with PayPal. You will also receive an email from Charitable.

2. Contact your hosting company

If the communication process between PayPal and your website fails, your website is running on a server with outdated software. You should get in touch with your host immediately and refer them to the upgrade information provided by PayPal. You should also provide them with the error message that was listed in the email sent to you from Charitable.

It’s important to note that this isn’t just about making sure your integration with PayPal works. You’re also making sure that your website isn’t powered by a server with unsupported and insecure software. 

If your host is unable or unwilling to move you to a modern server with secure software, you should seriously consider migrating to a new hosting company. There are plenty of good hosting companies out there, and many of them offer tools to help you migrate your website to their platform.

3. Disable IPN verification – a temporary workaround

If for some reason you can’t switch (or can’t switch yet), we have added a way for you to skip the IPN verification process in Charitable. You should not rely on this permanently, since it makes your PayPal integration less secure, but it can help you temporarily avoid having all your donations stuck as Pending.

In your WordPress dashboard, go to Charitable > SettingsPayment Gateways. Click on the “Gateway Settings” button for PayPal. Tick the box for “Disable IPN Verification” and save the changes.

Again, this is a temporary workaround. Don’t rely on it. Make sure your host is upgrading its system or switch to a better host.

If you run into any problems along the way, please post your comments below or get in touch with us via our support form.

author avatar
Eric Daams

Disclosure: Our content is reader-supported. This means if you click on some of our links, then we may earn a commission. We only recommend products that we believe will add value to our readers.

Leave a Reply

Your email address will not be published. Required fields are marked *

Get free tips and resources right in your inbox, along with 60,000+ others

Join our Newsletter

We won’t spam you. We only send an email when we think it will genuinely help you. Unsubscribe at any time!

Featured Video:

Watch more videos on our YouTube channel.

What's New In Charitable

View The Latest Updates
🔔 Subscribe to get our latest updates
📧 Subscribe to Emails

Email Subscription

Join our Newsletter

We won’t spam you. We only send an email when we think it will genuinely help you. Unsubscribe at any time!

GiveWP Migrations New

White Glove Migration Service for GiveWP

Thinking about switching your fundraising platform from GiveWP to Charitable, but don’t want to risk losing your data or handle a complex technical setup yourself? Charitable’s White Glove Migration Service features:

👥 Flawless Donor Mapping: Safely transfer your entire supporter database with zero data loss.

📊 Complete Financial History: Meticulously preserve every historical transaction for continuous, accurate reporting.

🔄 Seamless Recurring Giving: Safely transfer active sustaining subscriptions without disrupting your incoming revenue or requiring your donors to update their information.

💳 Zero Gateway Disruptions: Keep using Stripe, PayPal, or any other GiveWP-compatible processor you already love.

🚀 Expert Technical Setup: Relax while our team handles the heavy lifting to install and configure your forms—plus, qualifying users get a full year of Charitable Pro completely free.

Visit this page to learn more.

author avatar
Eric Daams
automation Improvement

📢 New Feature Alert: Automation Connect 2.0 Is Here! 🚀

Thinking about connecting your fundraising data to tools like Mailchimp, Slack, or Google Sheets, but don’t want to hire a developer or write custom code? Charitalbe’s new automation addon has:

⚡ 17 Event Triggers: Instantly fire webhooks for a donor’s first gift, renewal payments, or reached campaign milestones.

🎯 Smart Conditional Logic: Use powerful AND/OR logic across 11 fields to only send data when it meets your exact criteria, like newsletter opt-ins.

📊 Custom Payload Control: Select from 80+ clean data fields across donor, donation, and campaign metadata so your apps get exactly what they need.

🚀 Pre-Built Platform Templates: Skip the setup from scratch with ready-to-go templates for Zapier, Make.com, n8n, HubSpot, and Slack.

🛡️ Reliable Developer Tools: Power your workflows with signed HMAC-SHA256 payloads, complete WordPress filters, and automatic retry logs.

author avatar
Eric Daams
automation Improvement

🔌 Charitable Meets Zapier: Connect to 7,000+ Apps and Automate Your Fundraising

Tired of manually copying donation data into accounting sheets or tracking down new donor signups? Put your administrative tasks on autopilot. Charitable is now officially on Zapier, giving you a powerful, no-code way to plug your fundraising directly into the rest of your favorite tools.

Every donation, donor signup, and campaign milestone can now trigger an automated workflow seamlessly.

What’s New:

♾️ Connect to 7,000+ Apps: Bridge your Charitable campaigns with everyday software like Google Sheets, QuickBooks, Slack, Mailchimp, HubSpot, Notion, Airtable, and thousands more.

⚡ 12 Powerful Triggers: Build deep workflows using smart automation triggers covering the entire donation lifecycle—including New Donation, New Donor, Subscription Cancelled, and Campaign Goal Reached.

📋 Pre-Built Action Templates: Get started in three minutes or less with our pre-made template combinations, like automatically logging new donations straight into a Google Sheet or firing custom donor welcome emails through Gmail.

🚫 Zero Code Needed: No complex webhooks or custom PHP scripts required. Just pick your trigger, choose your app, map your fields, and let Zapier handle the heavy lifting.

Ready to save hours of admin time? Grab Charitable Pro with the Automation Connect addon today and launch your first Zap!

author avatar
Eric Daams
Improvement Payments

🚀 Introducing PayPal Commerce: One Connection, Six Ways to Donate

Donors expect modern, flexible payment options when they support a cause. If they don’t see their preferred method on your donation form, they often disappear without a word. With PayPal Commerce, we are bringing a completely modernized checkout experience right to your campaigns.

Enjoy a single integration that upgrades your forms, makes giving seamless, and helps you capture every single donation.

What’s New:

🔌 One-Click Connection: Skip messy API keys and developer docs. Simply click “Connect with PayPal,” sign in to your business account, and your modern form is live in under five minutes.

💳 Six Ways to Give: Give your supporters instant access to PayPal balance, Venmo (US), Pay Later financing, major credit/debit cards, Apple Pay (Safari), and Google Pay (Chrome) all from the exact same form.

🔄 Flexible Recurring Giving: Fully supports monthly giving. Choose between the PayPal Subscriptions API (handled automatically on PayPal’s end) or Vault + Cron (handled securely right on your site).

💬 Friendly Error Recovery: No more confusing browser alerts. If a payment is declined, donors see plain-language, inline messages that guide them on how to fix the issue and complete their gift.

Ready for PayPal, modernized? Update to Charitable Pro 1.8.15+ (or Charitable Lite 1.8.11+) and connect your account today!

author avatar
Eric Daams
Campaigns New

⏳ Campaign Countdown: Drive Urgency and Lift Donations

Urgency is one of the most powerful tools in fundraising! Meet Campaign Countdown—a live, real-time timer built to turn procrastination into immediate generosity.

campaign_countdown_animation

What’s New:

⏱️ Live, Real-Time Urgency: Beautifully track days, hours, minutes, and seconds down to your campaign’s deadline w/ live-updating visual countdowns.

🎨 Tailored to Your Look: Choose between Boxed bordered tiles or a clean, single-line Inline display. Match your theme instantly with font and deep color controls.

🛠️ Place it Anywhere: Drop the countdown anywhere you like using the Campaign Builder field, a dedicated Gutenberg block, or a simple shortcode.

🚨 Smart Expiry Actions: Total control over the end state—choose to automatically replace the timer with a custom message, freeze it at zero, and more.

author avatar
Eric Daams