What do you mean by "take payments"? You mean you collect CC/other info and send it to a merchant like Stripe? Or do you have a merchant account (as in an ISO account), and are actually communicating with a processor directly?
If it's the former and you store any customer information at all, I would caution against it, since it identifies your application as being something that people can attack and possibly get data from.
If it's the former and you don't store any information that can even remotely identify customers, it wouldn't really hurt. I don't think Stripe/Paypal/etc require that integration with their APIs be kept secret.
If it's the latter (merchant account) I would assume that you're required to maintain PCI compliance, in which case even if you remove all "secrets", it still may be unacceptable to open source that code.
Keep in mind, if you store data and transact with processors, any bug in your code opens both the processors and users up to fraud. Generally I don't consider that a good idea. Code audits are one thing (which can be done by hiring a firm to internally review your code), but giving it to everyone I think would be a bad idea.