Half of Spain's Savings Banks Run on Cecabank.
Your Joomla Store Should Too.
Cecabank's TPV Virtual, native in J2Commerce. SHA-256 signing, PSD2/SCA handled by Cecabank's certified infrastructure, 15 payment page languages, and a callback handler that cross-validates three independent data points before touching your order.
Everything Your Spanish Checkout Needs
Every feature was extracted from the actual working code — not a spec sheet. If it is in the list, it is in the plugin.
SHA-256 Signed Transactions
Defaults to SHA-256 — Cecabank's current mandatory signing standard. SHA-1 stays available for merchants on legacy agreements. Get the algorithm right from day one.
PSD2/SCA Compliant
Cecabank handles 3D Secure and EU Strong Customer Authentication server-side on their certified infrastructure. Your store is completely out of card-data scope.
15 Payment Page Languages
Spanish, Catalan, Basque, Galician, Valencian, English, French, German, Portuguese, Italian, Swedish, Danish, Russian, Dutch, Norwegian. Basque Country customers pay in Basque. It is that simple.
Dual Sandbox / Live Credentials
Sandbox and live merchant IDs, encryption keys, acquirer BINs, and terminal IDs in completely separate fields. Flip the toggle to switch modes. Your live terminal stays untouched during testing.
3-Layer Replay-Proof Callbacks
Every Cecabank callback is checked three ways: signature verification, Merchant ID match, and amount cross-validation within one cent. Spoofed or replayed callbacks go nowhere.
Idempotency Guard
If Cecabank fires the callback twice, your order confirms once. Your customer gets one email. Your inventory moves once. Duplicate callbacks are caught and acknowledged cleanly.
Surcharge Engine
Set a percentage, a fixed amount, or both. Attach a tax class for IVA on payment surcharges. The surcharge line appears transparently in the order summary — no custom code, no workarounds.
Geozone Restriction
Show Cecabank only to buyers in Spain, specific autonomous communities, or any geographic zone you define. International customers see different options. The right gateway shows up for the right buyer.
EUR Enforcement
Cecabank TPV is EUR-native. If the active cart currency is not EUR, the payment option hides itself and the admin sees a clear error — no silent misfires, no rejected transactions from misconfigured stores.
Configurable Order Status Mapping
Pick the success status and failure status from your own defined order states. No hardcoded status IDs. Your workflow, your logic — whether confirmed means "Paid" or "Processing" or something custom entirely.
Bootstrap 5 / UIkit 3 Templates
Switch between Bootstrap 5 and UIkit 3 layout templates in one dropdown. Fits the app_bootstrap5 and app_uikit J2Commerce themes out of the box — no template customisation required.
Auto-Generated IPN URL
Your Cecabank notification URL is calculated automatically and displayed in the admin as a ready-to-copy field. Paste it into your Cecabank merchant portal. Done.
Security That Matches Your Bank's Standards
Cecabank is a licensed credit institution regulated by the Bank of Spain. The plugin's callback verification is built to match that standard. Three independent checks happen before any order state changes — and each one is a hard stop, not a logged warning.
- SHA-256 firma signature verified with a constant-time comparison function
- Merchant ID in callback cross-checked against your configured terminal
- Transaction amount verified against order total within one cent
- Duplicate callbacks caught and acknowledged without re-confirming the order
- Sandbox credential preflight — no silent fallback to live keys during testing
Spain Has 17 Autonomous Communities. Your Payment Page Can Speak to All of Them.
Catalan buyers in Barcelona, Basque speakers in Bilbao, Galician customers in Santiago, Valencian shoppers in Valencia — Cecabank's TPV supports 15 language settings, and this plugin exposes all of them. Set the language that matches your primary customer base and let the payment page speak for itself.
- Spanish (Castellano) — default for most Spanish merchants
- Catalan, Basque, Galician, Valencian — Spain's co-official languages
- English, French, German, Portuguese — European neighbours
- Italian, Swedish, Danish, Russian, Dutch, Norwegian
- One dropdown in admin. One setting. Every language covered.
Test Without Breaking Anything. Go Live Without Surprises.
Sandbox and live credentials live in completely separate fields. Toggle between them with one switch. And if you enable sandbox mode without filling in your sandbox credentials — Merchant ID, encryption key, acquirer BIN — the plugin stops right there and tells you. No silent fallback to your live terminal from a test checkout.
- Separate Merchant ID, encryption key, acquirer BIN, and terminal ID for each environment
- One toggle switches the entire credential set
- Missing sandbox credentials throw a clear error immediately
- Live keys untouched during test runs
Real-World Use Cases
Spanish Buyers Are Ready. Your Checkout Should Be.
Your customers already trust Cecabank. They have paid their bills on it, bought their train tickets on it, and settled their accounts through it for decades. Give them a checkout that feels like home — and stop handing 3.4% to a processor they have never heard of.
Translated In The Following Languages
Arabic Unitag (ar-AA), Chinese, Traditional (zh-TW), Danish (da-DK), Dutch (nl-NL), English (en-GB), English, USA (en-US), Finnish (fi-FI), French (fr-FR), German (de-DE), Greek (el-GR), Hebrew (he-IL), Italian (it-IT), Japanese (ja-JP), Norwegian Bokmål (nb-NO), Persian Farsi (fa-IR), Polish (pl-PL), Portuguese, Brazil (pt-BR), Portuguese, Portugal (pt-PT), Russian (ru-RU), Spanish (es-ES), Swedish (sv-SE), Turkish (tr-TR)
License Information
An active license entitles you to updates, downloads, and support for the duration of the license period. You may continue using this plugin indefinitely without an active license; however, support, updates, and downloads will not be available while your license is inactive.
- Developer J2Commerce
- Extension Type Payment
- J2Commerce Version 4.x, 6.x
- Joomla Version 4.x, 5.x, 6.x
Arabic Unitag
Chinese, Traditional
Danish
Dutch
English
English, USA
Finnish
French
German
Greek
Hebrew
Italian
Japanese
Norwegian Bokmål
Persian Farsi
Polish
Portuguese, Brazil
Portuguese, Portugal
Russian
Spanish
Swedish
TurkishFix correct callback URL field type so it renders
Improvement Resolve event dispatcher from the DI container (Joomla 7 deprecation prep)
Update Replaces the deprecated application getDispatcher() accessor; no behaviour change
New Feature Initial J2Commerce 6 release of the CECA TPV Virtual payment gateway
New Feature Redirect checkout flow with server-to-server notification finalization
New Feature SHA-256 signature signing and verification of CECA requests/responses
New Feature Sandbox and Live environment switching with showon-gated credentials
New Feature Bootstrap 5 and default template variants for the storefront
New Feature Translations for 21 locales (en-US/en-GB plus 19 languages)
Improvement Native Joomla 6 namespaced MVC plugin (migrated from J2Store v4 FOF)
Improvement Vanilla ES6 storefront JS, no jQuery
Update Requires Joomla 6.x + J2Commerce 6.x + a CECA merchant account
New Feature J2Commerce v4 and Joomla 4/5 support
Update J2Commerce/J2Store v4 and Joomla 4/5 plugin support
You may also be interested in these products
Stay Updated
Subscribe for free and be the first to know about the latest features, updates, and new additions.