Linux 软件免费装
Banner图

TrustLens – Fraud Prevention & Chargeback Defense for WooCommerce

开发者 webstepper
freemius
更新时间 2026年8月11日 06:48
PHP版本: 7.4 及以上
WordPress版本: 7.0
版权: GPLv3 or later
版权网址: 版权信息

标签

chargeback anti-fraud woocommerce security fake orders card testing

下载

1.3.7 1.3.12 1.3.13 1.1.7 1.3.11 1.3.10 1.0.3 1.3.9 1.0.1 1.0.4 1.0.5 1.0.6 1.1.0 1.1.1 1.1.2 1.1.3 1.1.4 1.1.5 1.1.6 1.1.8 1.2.0 1.2.1 1.2.2 1.2.3 1.2.4 1.2.5 1.2.6 1.2.7 1.2.8 1.3.0 1.3.1 1.3.3 1.3.4 1.3.5

详情介绍:

Most WooCommerce fraud doesn't look like fraud. It looks like a customer. The shopper who returns nearly everything they buy. The "new" account that shares a shipping address with three others you already flagged. The checkout that's quietly taking dozens of declined cards in a row. None of that trips a payment gateway's per-transaction check — because each individual charge looks fine. It's the pattern across orders that gives it away, and that's the part most stores never see until the chargeback ratio is already climbing. TrustLens watches that pattern. Here's a two-minute walkthrough of how it works: https://youtu.be/Xxz8lcTnAlU WooCommerce fraud prevention built on customer behavior, not just card checks TrustLens is a customer trust scoring and fraud detection plugin for WooCommerce. Instead of judging a single transaction, it scores every shopper 0–100 from how they've actually behaved on your store — order history, returns, coupon use, disputes — and sorts them into six segments: VIP, Trusted, Normal, Caution, Risk, Critical. Open any customer's profile and you see exactly which signals moved their score. Nothing is a black box. How trust scoring works Every customer starts at a neutral base score of 50. From there, TrustLens' eight detection modules each contribute signals — positive or negative — based on what that customer has actually done: a clean return history nudges the score up, coupon abuse pulls it down, a filed dispute pulls it down further. Customers also earn a small, transparent age bonus as an account passes 90, 180, and 365 days since their first order. Every signal that touched the score — module, points, and a plain-English reason — is listed right on the customer's profile. Nothing is a mystery number. The final score is clamped to 0–100 and mapped into one of six segments: Every threshold above is the default and fully configurable in Settings, because a 40% return rate might be alarming for one store and unremarkable for another. For the full mechanics, see the customer trust score guide and the segments explained guide. Eight detection modules, working in the background Return abuse. Tracks refund rate, refund value, and refund frequency over time rather than judging any single return in isolation. A customer who returns one order out of twelve looks very different from one who returns three out of four. Order patterns. Watches velocity and behavior across a customer's order history — a signal that's invisible when you're looking at orders one at a time in the WooCommerce admin, but obvious once it's plotted against everyone else's normal buying pattern. Coupon abuse. Catches the two most common ways discount codes get exploited: a "new customer" welcome code used repeatedly from accounts that are really the same person, and coupon codes applied in patterns that don't match organic use. Category-aware risk. Return behavior means something different depending on what's being returned — a high return rate on apparel is often just sizing, while the same rate on electronics or consumables is a different story. This module scores returns in the context of the product category rather than one blanket rule for the whole catalog. Linked accounts. Builds fingerprints from shipping address, billing address, phone number, IP address, payment method, and device user agent, then flags when multiple customer "accounts" share enough signals to plausibly be the same person or fraud ring behind separate identities. This is how TrustLens catches someone opening five accounts to claim five first-order discounts. Shipping anomalies. Flags address-hopping and reshipping patterns associated with stolen-card fraud — an order pattern that looks like it's testing which shipping addresses a stolen card will get through on. Chargeback tracking. Automatically ingests disputes from Stripe and WooPayments the moment they're filed, keeps a running per-customer dispute count, and feeds that history into the trust score, so a customer with two prior disputes isn't treated the same as a first-time buyer. Card-testing defense. Real-time protection against bots that probe your checkout with a rapid burst of small, mostly-declined charges to find out which stolen card numbers are still live. A one-click Panic Freeze button lets you lock down checkout instantly if you spot an attack your automatic thresholds haven't caught yet. Card-testing attacks: what they are and why they cost more than the declines A card-testing attack isn't someone trying to buy from you — it's a bot using your checkout to validate a batch of stolen card numbers before using them elsewhere, firing small charges that just want a "declined" or "approved" answer. Most fail, so the pile of declined orders looks harmless. The real cost shows up sideways: gateway fees on every attempt, a higher fraud score with your payment provider, and — if even a handful of those cards are live — chargebacks landing weeks later with your store's name on them. TrustLens watches decline velocity per device in real time, matching on both the browser fingerprint and a server-side fingerprint (IP and user agent) so a bot can't dodge detection by rotating its browser signature. When a device crosses your threshold, it's locked out of checkout automatically — before the attack reaches your gateway, runs up fees, or produces a chargeback down the line. VIP Customer Bypass is on by default, so real repeat customers are never caught in a velocity rule meant for bots. Full mechanics are in the card-testing defense docs. The Command Center dashboard One screen shows your store's health score, trust-score trends, the six-segment distribution, your high-risk list, and a chargeback-ratio speedometer benchmarked against Visa, Mastercard, Amex, and Discover monitoring thresholds — so you can see a dispute problem building before it triggers a monitoring program, not after. Chargebacks: seeing the ratio before the card networks do Visa, Mastercard, Amex, and Discover each run monitoring programs that watch your chargeback ratio — disputes as a percentage of transactions — and enroll merchants who cross a threshold into a program with extra fees, extra scrutiny, and in bad cases the threat of losing processing entirely. Most merchants only learn the exact numbers when their processor emails them: Visa's VFMP sits at 0.65%, Visa's VDMP at 0.9%, Mastercard's ECP at 1.5%, and Amex and Discover's excessive-dispute programs at 1.0%. TrustLens captures the card brand on every Stripe and WooPayments order and tracks how many end up disputed, so your blended monthly ratio shows up on the dashboard as a speedometer — Healthy, Approaching, or Action-needed — measured against those same four thresholds. The point isn't to replace your processor's own monitoring; it's to give you the same number they're watching, weeks before a threshold crossing becomes a phone call. See the chargeback speedometer and ratio thresholds guide and the Stripe chargeback tracking guide for the full picture. How TrustLens compares Your payment gateway scores the transaction — the charge itself, at the moment it happens. It's genuinely good at catching an obviously stolen card, but has no memory of what that customer did last month and no way to connect two "different" accounts placing suspiciously similar orders. TrustLens scores the customer, over time, using exactly the signals a per-transaction check can't see. A simple IP blocklist stops a known-bad address and nothing else — it doesn't adapt when someone switches networks, doesn't know a "new" account is really a repeat offender, and does nothing for friendly-fraud chargebacks or return abuse, since those orders come from real cards on real networks. See the IP blocking vs. behavioral fraud scoring comparison for where each approach holds up and where it doesn't. For specific alternatives, see FraudLabs Pro vs. TrustLens and TrustLens vs. WooCommerce's built-in anti-fraud tools. Meet the customers TrustLens catches The serial returner — sends back a third or more of what they buy; no single return looks wrong, the pattern across a dozen orders does (Return Abuse + Category-Aware Risk). The coupon farmer — a "new" account every few weeks for the same first-order discount, connected by Linked Accounts and flagged by Coupon Abuse. The fraud ring — one billing address, payment method, or device spread across several names, surfaced automatically by Linked Accounts. The card-testing bot — dozens of small, mostly-declined charges hunting for live stolen cards; Card-Testing Defense locks it out before it reaches your gateway. Integrations and compatibility TrustLens sits inside the store you already run. Stripe and WooPayments disputes are ingested automatically — no webhook setup required; other gateways (PayPal, Square, offline) use a manual chargeback form on the order screen. Both Classic and WooCommerce Blocks checkout are enforced, so a blocked customer is blocked either way. TrustLens declares full WooCommerce HPOS compatibility, supports GDPR data export and erasure via standard WordPress privacy tools, and includes a REST API for looking up customers, scores, and segments, and for triggering recalculations. Pro adds signed webhooks for pushing trust events to Slack, Zapier, or your own tools — see the webhooks and REST API integration guide. Already have order history? Historical Sync builds trust profiles from your existing orders in small background batches, so you're not starting from a blank slate. Details in the Historical Sync guide. You stay in control TrustLens never auto-blocks a single customer in the free version. It surfaces the risk; you decide — block at checkout, allowlist forever, or just watch the trend. Every score, badge, and detection module is visible and adjustable from Settings. Privacy is built the same way: everything runs inside your own store, customer identifiers are pseudonymized with keyed HMAC-SHA256 (not reversible, not portable to another site), and no customer data is ever sent to a third party by default. Free — the complete detection plugin Pro — act on what TrustLens finds Advanced Chargeback Monitor and Dispute Evidence Reports. Where the free speedometer shows your blended ratio, Pro breaks it down per card brand against Visa VDMP/VFMP, Mastercard ECP, Amex, and Discover, adds a 12-month trend chart and a dispute-deadline worklist, and generates a representment-ready Dispute Evidence Report that matches the disputed order against the customer's prior order history and flags whether it qualifies for Visa Compelling Evidence 3.0. Each report carries a tamper-evident fingerprint and QR code so a card issuer can independently verify it's genuine at a neutral domain. See the dispute evidence report guide. Automation Rules. Build if-this-then-that logic on everything TrustLens detects: 15 triggers (score changes, new orders, refunds, disputes, linked-account detections, card-testing attacks, and more), 30-plus condition fields, and actions like blocking a customer, holding an order, sending an email, firing a signed webhook, allowlisting, cancelling, or tagging. A save-time validator catches rules that could never fire before you save them, and an inline inspector shows exactly why each rule did or didn't trigger. See the automation rules playbook. Card-Testing Defense Pro. Adds auto-escalation for attacks that outpace your base thresholds, a geo-diversity safeguard so a flash-sale traffic spike isn't mistaken for a bot, fingerprint and IP-range allowlists, full attack history, and Slack or email alerts the moment a lockdown triggers. See the card-testing auto-escalation guide. Payment Method Risk Controls, Scheduled Reports, and more. Restrict specific payment methods for risky segments without locking a customer out of checkout entirely, receive daily, weekly, or monthly trust-intelligence summaries by email, and get advanced notification types beyond the free version's core alerts. See the scheduled reports guide. Bottom line: Free surfaces the risk. Pro acts on it. Getting started Install TrustLens and open TrustLens → Dashboard. All 8 detection modules and card-testing defense are already running with sensible default thresholds — there's nothing to configure before it starts working. If you have existing orders, Run Historical Sync to build trust profiles from that history in the background. Full steps are in the Installation section below, or the getting-started guide with screenshots. Docs & resources Who it's for If your store has outgrown "just watch the orders list" — because refunds are eating margin, a coupon code is circulating somewhere it shouldn't, or you've had a chargeback ratio scare — TrustLens gives you the visibility to catch it early and the control to act on your own terms — starting with the order history your store already has. More from Webstepper TrustLens protects your revenue; Smart Cycle Discounts grows it — scheduled BOGO, bulk, tiered, and coupon campaigns for WooCommerce, with Cycle AI to build the deal from a plain-English description. Built and supported by the same team.

安装:

  1. Install TrustLens directly from the WordPress plugin repository, or upload the trustlens folder to /wp-content/plugins/
  2. Activate the plugin through the Plugins menu — TrustLens checks for WooCommerce automatically
  3. Open TrustLens → Dashboard to see the Command Center
  4. Click Run Historical Sync to build trust profiles from your existing WooCommerce orders — the sync runs in the background in small batches and does not affect site performance
  5. Visit TrustLens → Settings to adjust scoring thresholds, checkout blocking, and notification preferences
What works out of the box: If you use Stripe or WooPayments, no extra setup is required for chargeback and card-brand capture. Other gateways can be tracked through the manual chargeback entry form on the order edit page.

屏幕截图:

  • **Card-Testing Defense** — Real-time decline-velocity monitoring, attacker fingerprints, one-click Panic Freeze, and the recent-attack feed
  • **Customer List** — Searchable, sortable list with segment badges, trust scores, return rates, and bulk actions
  • **Customer Detail** — Full profile with the trust-score gauge, signal impact, return-rate trend, and linked accounts
  • **Order Integration** — Customer trust score, segment, and dispute status shown right on the WooCommerce order edit screen
  • **Settings** — Detection modules and scoring thresholds, with checkout-blocking and notification controls

升级注意事项:

1.3.13 Recommended for stores using payment gateways other than Stripe or WooPayments, and for any store seeing failed orders that Card-Testing Defense did not count. Failed payment orders are now attributed and counted consistently across gateways. No settings change is needed. 1.3.12 Recommended for any store that has seen card testing. Repeat offenders are now locked out for progressively longer instead of getting a fresh allowance every hour, and the 24-hour decline and submission figures no longer read about double on stores where the device-fingerprint script runs. 1.3.11 Important fix for stores seeing repeated failed orders. Card-Testing Defense now stops paced attacks and repeat offenders, guards the pay-for-order checkout route, and correctly applies the card-testing penalty to trust scores. Recommended for everyone; no settings change needed. 1.3.10 Improves scoring accuracy: partial refunds and re-completed orders no longer inflate a customer's return and order counts, so return, dispute, and cancellation rates read true. Also fixes a 100x WooPayments chargeback amount and a duplicate-worklist edge case. Existing counts aren't retroactively adjusted; new events are counted correctly. No settings change. 1.3.9 Activation now reliably opens the TrustLens dashboard. Includes a routine licensing framework update. 1.3.7 The Store Trust Network now retracts a shared flag when you win a chargeback, allowlist a customer, or their risk clears — removing it from your linked stores instead of leaving it in place. Allowlisted customers are never shared. No data or settings change. 1.3.6 Surfaces Store Trust Network flags on the customer profile and the order screen, with a new dashboard status + early-warnings summary (Pro, multi-site). Also clearer plan messaging for single-site Pro. No data or settings change.

常见问题:

How is TrustLens different from my payment gateway's fraud tools?

Your payment gateway (Stripe Radar and similar) scores a single transaction at the moment of charge — card, IP, AVS, device — and is blind to what happens before and after on your store. TrustLens scores the customer's behavior over time: refund and return patterns, coupon abuse, multi-account links, dispute history, category-specific returns, and card-testing activity at checkout. Those are signals your gateway never sees. They're complementary, not competing. Your gateway blocks obvious stolen-card charges; TrustLens surfaces friendly-fraud chargebacks, serial returners, coupon abusers, fraud rings, and card-testing bots that slip past a per-transaction view — and it keeps you in control (the free version never auto-blocks; you decide). Everything runs inside your own store, so no customer data leaves your site.

Does TrustLens work with guest checkout?

Yes. Customers are identified by a hash of their email address, so guest and registered customers are tracked equally. If a guest later registers, their history carries over.

Will TrustLens automatically block customers?

By default, no. The free version is manual: it surfaces customer risk data, and you decide when to block or allowlist someone. Pro can optionally automate specific actions, including alerts, order holds, verification requirements, and customer blocking if you configure automation rules or chargeback auto-blocking.

How does linked accounts detection work?

TrustLens creates fingerprints from shipping addresses, billing addresses, phone numbers, IP addresses, payment methods, and device user agents. When multiple customer accounts share fingerprints, they are flagged as linked. This helps detect multi-account abuse like repeated first-order discounts.

Can TrustLens help reduce return abuse and refund abuse in WooCommerce?

Yes. TrustLens tracks refund rate, refund value, refund frequency, category-specific return behavior, and related customer patterns over time. This helps you spot serial returners and high-risk refund behavior earlier instead of reviewing refunds one order at a time.

Can TrustLens help with chargebacks and disputes?

Yes — and the core chargeback tracking is in the free version. TrustLens automatically ingests disputes from Stripe and WooPayments, accepts manual entry for other gateways (PayPal, Square, offline), keeps per-customer dispute counters, and feeds dispute history into trust scores. The free dashboard also shows a Chargeback Ratio Speedometer with a Healthy / Approaching / Action-needed status against Visa, Mastercard, Amex, and Discover thresholds. Pro adds a dedicated Advanced Chargeback Monitor with per-brand breakdown (Visa VDMP/VFMP, Mastercard ECP, Amex, Discover), 12-month trend, trailing-30-day window, daily ratio email alerts, a one-click Dispute Evidence Report for processor responses, and auto-block after N lost disputes.

How does the Chargeback Ratio Monitor work?

TrustLens captures the card brand on every Stripe and WooPayments paid order and tracks how many of those orders end up as disputes. Your blended monthly chargeback ratio is shown on the dashboard speedometer, with status colors keyed to Visa VDMP/VFMP, Mastercard ECP, Amex, and Discover monitoring thresholds — so you can see if you're approaching enrollment before it happens. Pro adds per-brand ratios, the 12-month trend chart, the trailing-30-day window, and daily email alerts.

What is Card-Testing Defense?

Card-Testing Defense (free) is real-time protection against stolen-card attack bots that probe your checkout with thousands of declined payment attempts. TrustLens watches per-device decline rates in a 60-second rolling window, matching on both the browser fingerprint and a server-side fingerprint (IP and user agent) so bots can't slip through by rotating their browser fingerprint. When a device crosses the threshold it's locked out of checkout for 90 seconds, blocking the attack before it reaches your payment gateway and runs up gateway fees, fraud fees, and downstream chargebacks. VIP Customer Bypass is enabled by default, so established customers — those who meet your minimum-order threshold (default 3 completed orders) and aren't already in a Risk or Critical segment — are never blocked by velocity rules. A one-click Panic Freeze button halts all checkouts for 15 minutes during an active attack your thresholds haven't caught. Pro adds auto-escalation, a geographic-diversity safeguard so flash-sale traffic isn't mistaken for an attack, fingerprint and IP CIDR allowlists, attack analytics with CSV export, and Slack alerts.

Can I automate actions based on customer risk?

Yes, with Pro. Automation Rules let you build trigger-based rules that fire when customer risk changes, orders are placed, refunds are processed, disputes are filed, linked accounts are detected, card-testing attacks happen, or shipping anomalies are spotted. Each rule supports 30+ condition fields and actions like block customer, hold order, send email, fire webhook, allowlist customer, cancel order, or tag customer. Pro automation also includes a save-time validator that blocks rules that can never fire, an inline inspector that shows exactly why each rule fired or didn't, and async HMAC-SHA256-signed webhooks with automatic retry.

What happens when I block a customer?

Blocked customers see a customizable message when they try to add items to their cart or proceed to checkout. The block applies to both logged-in users and guest checkouts matching the blocked email. All blocked checkout attempts are logged.

Can I undo a block?

Yes. You can unblock a customer at any time from their profile page or the customer list. You can also add customers to the allowlist, which locks their score at 100 and prevents any negative signals from affecting them.

What happens right after I install TrustLens?

New WooCommerce orders are analyzed automatically after activation. If you already have historical orders, you can run Historical Sync from the dashboard to build trust profiles from your existing store data without slowing down the frontend.

Does this slow down my store?

No. Score calculations run asynchronously via Action Scheduler (the same system WooCommerce uses). Checkout blocking uses a lightweight email-hash lookup. The historical sync processes orders in small batches in the background.

Does TrustLens send customer data to an external service?

No customer personal data ever leaves your site. TrustLens works inside your WordPress and WooCommerce installation. The only default external call is the optional Pro report-verification feature, which (while enabled) sends a non-personal, one-way fingerprint of a dispute report to the TrustLens verification service so issuers can confirm it is genuine — never customer data, and it can be disabled. All other external delivery (webhooks, email notifications) happens only if you configure it.

Is TrustLens compatible with WooCommerce HPOS?

Yes. TrustLens declares full compatibility with High-Performance Order Storage and works with both legacy and HPOS-enabled stores.

Does TrustLens store personal data?

TrustLens stores customer email addresses and behavioral data (order counts, refund counts, trust scores) in custom database tables. Matching identifiers used for linked-account detection are pseudonymized using keyed HMAC-SHA256 hashes, preventing the raw values from being exposed or reused across sites. The plugin integrates with WordPress privacy tools — customers can request data export or erasure through the standard WordPress privacy workflow.

Can I access TrustLens data from external systems?

Yes. TrustLens includes a REST API with 8 endpoints for looking up customers, retrieving scores, filtering by segment, and triggering recalculations. API access requires either the manage_woocommerce capability or a valid API key configured in settings.

Can I get alerts and reports by email?

Yes. The free version includes core email notifications such as blocked checkout alerts, a welcome summary, and a weekly summary. Pro adds advanced alerts, daily digests, monthly revenue protection reports, and scheduled email reports.

What is the minimum data needed for accurate scoring?

By default, customers need at least 3 orders before they move out of the Normal segment. You can adjust this threshold in Settings > General. Customers below the threshold still accumulate signals — they just aren't classified until enough data exists.

Does the free version include all detection modules?

Yes. All 8 detection modules ship in the free version — returns, orders, coupons, categories, linked accounts, shipping address anomalies, chargebacks, and card-testing defense. There are no trial limits, no disabled scoring, and no locked modules. Pro adds automation rules, webhooks, scheduled reports, payment-method risk controls, the advanced per-brand Chargeback Monitor with daily alerts, Card-Testing Defense Pro (auto-escalation + analytics + Slack alerts), and 10 advanced notification types.

What happens if I rotate my WordPress secret keys?

Important: TrustLens uses your WordPress auth secret key (via wp_salt('auth')) as the HMAC keying material for hashing customer emails and linked-account fingerprints. This is a deliberate security choice — it makes stored hashes non-reversible and non-portable across sites. The trade-off is that regenerating your WordPress secret keys (whether through a security plugin's "regenerate keys" tool or by editing wp-config.php directly) will permanently invalidate every customer hash and fingerprint already stored in your TrustLens tables. After rotation, the plugin won't be able to match a returning customer to their existing trust profile, and linked-account detection will reset. If you ever need to rotate WordPress secret keys, plan to run Historical Sync afterward so TrustLens rebuilds the customer table from your existing WooCommerce order data using the new keying material. Allowlisted/blocked status set manually on individual customer rows is the exception that won't auto-recover — re-apply those after the sync.

更新日志:

1.3.13 1.3.12 1.3.11 1.3.10 1.3.9 1.3.8 1.3.7