Linux 软件免费装
Banner图

TrustLens – Fraud Prevention & Chargeback Defense for WooCommerce

开发者 webstepper
freemius
更新时间 2026年7月11日 08:13
PHP版本: 7.4 及以上
WordPress版本: 7.0
版权: GPLv3 or later
版权网址: 版权信息

标签

chargeback anti-fraud woocommerce security fake orders card testing

下载

1.3.7 1.0.3 1.3.9 1.0.1 1.0.4 1.0.5 1.0.6 1.1.0 1.1.1 1.1.2 1.1.3 1.1.4 1.1.5 1.1.6 1.1.7 1.1.8 1.2.0 1.2.1 1.2.2 1.2.3 1.2.4 1.2.5 1.2.6 1.2.7 1.2.8 1.3.0 1.3.1 1.3.3 1.3.4 1.3.5

详情介绍:

Stop losing money to WooCommerce fraud you can't see. Serial returners, coupon abusers, fraud rings, and stolen-card bots quietly drain stores — often thousands a year, and by the time your chargeback ratio climbs the damage is done. TrustLens is a behavior-based customer trust scoring and fraud detection plugin for WooCommerce. It scores every shopper 0–100 from real store behavior and sorts them into six segments — VIP, Trusted, Normal, Caution, Risk, Critical. Eight detection modules run in the background, from return abuse to card-testing attacks at checkout. You see exactly which signals moved each score, and you decide what to do. TrustLens never auto-blocks in Free. You review the profile and choose: block at checkout, allowlist forever, or just watch the trend. All data stays inside your store (no third-party calls), with identifiers pseudonymized via keyed HMAC-SHA256. Free — the complete plugin Pro — act on what TrustLens finds Bottom line: Free surfaces the risk. Pro acts on it.

安装:

  1. Install TrustLens directly from the WordPress plugin repository, or upload the trustlens folder to /wp-content/plugins/
  2. Activate the plugin through the Plugins menu — TrustLens checks for WooCommerce automatically
  3. Open TrustLens → Dashboard to see the Command Center
  4. Click Run Historical Sync to build trust profiles from your existing WooCommerce orders — the sync runs in the background in small batches and does not affect site performance
  5. Visit TrustLens → Settings to adjust scoring thresholds, checkout blocking, and notification preferences
What works out of the box: If you use Stripe or WooPayments, no extra setup is required for chargeback and card-brand capture. Other gateways can be tracked through the manual chargeback entry form on the order edit page.

屏幕截图:

  • **Card-Testing Defense** — Real-time decline-velocity monitoring, attacker fingerprints, one-click Panic Freeze, and the recent-attack feed
  • **Customer List** — Searchable, sortable list with segment badges, trust scores, return rates, and bulk actions
  • **Customer Detail** — Full profile with the trust-score gauge, signal impact, return-rate trend, and linked accounts
  • **Order Integration** — Customer trust score, segment, and dispute status shown right on the WooCommerce order edit screen
  • **Settings** — Detection modules and scoring thresholds, with checkout-blocking and notification controls

升级注意事项:

1.3.9 Activation now reliably opens the TrustLens dashboard. Includes a routine licensing framework update. 1.3.7 The Store Trust Network now retracts a shared flag when you win a chargeback, allowlist a customer, or their risk clears — removing it from your linked stores instead of leaving it in place. Allowlisted customers are never shared. No data or settings change. 1.3.6 Surfaces Store Trust Network flags on the customer profile and the order screen, with a new dashboard status + early-warnings summary (Pro, multi-site). Also clearer plan messaging for single-site Pro. No data or settings change. 1.3.5 Adds the Store Trust Network (Pro, multi-site): privately share customer risk flags across the stores you own. Opt-in and off by default; existing data is unaffected. 1.3.4 Fixes a fatal error that could prevent the plugin from activating. Recommended for everyone. 1.3.3 Fixes a bug where saving one Settings tab could reset settings on other tabs — recommended for everyone. Note for Pro stores: chargeback auto-block now defaults to OFF (opt-in); stores that already set a threshold keep it. 1.3.1 Free stores: this restores the Chargeback Tracking module (per-customer disputes + the chargeback-ratio speedometer) that recent free builds were missing — Pro stores were unaffected. It also clears up the activation and account screens. Recommended for all users. 1.3.0 New Chargeback Evidence Report (Pro): auto-builds your Visa CE 3.0 dispute case, independently verifiable by issuers at webstepper.io/verify (no customer data sent; optional). Plus a reliability pass — chargeback ratios, ROI, non-UTC report timing, and CSV-export fixes. Recommended for all. 1.2.8 Adds a video walkthrough to the plugin page and refreshes the banner artwork. No functional changes — safe to skip if you're current.

常见问题:

How is TrustLens different from my payment gateway's fraud tools?

Your payment gateway (Stripe Radar and similar) scores a single transaction at the moment of charge — card, IP, AVS, device — and is blind to what happens before and after on your store. TrustLens scores the customer's behavior over time: refund and return patterns, coupon abuse, multi-account links, dispute history, category-specific returns, and card-testing activity at checkout. Those are signals your gateway never sees. They're complementary, not competing. Your gateway blocks obvious stolen-card charges; TrustLens surfaces friendly-fraud chargebacks, serial returners, coupon abusers, fraud rings, and card-testing bots that slip past a per-transaction view — and it keeps you in control (the free version never auto-blocks; you decide). Everything runs inside your own store, so no customer data leaves your site.

Does TrustLens work with guest checkout?

Yes. Customers are identified by a hash of their email address, so guest and registered customers are tracked equally. If a guest later registers, their history carries over.

Will TrustLens automatically block customers?

By default, no. The free version is manual: it surfaces customer risk data, and you decide when to block or allowlist someone. Pro can optionally automate specific actions, including alerts, order holds, verification requirements, and customer blocking if you configure automation rules or chargeback auto-blocking.

How does linked accounts detection work?

TrustLens creates fingerprints from shipping addresses, billing addresses, phone numbers, IP addresses, payment methods, and device user agents. When multiple customer accounts share fingerprints, they are flagged as linked. This helps detect multi-account abuse like repeated first-order discounts.

Can TrustLens help reduce return abuse and refund abuse in WooCommerce?

Yes. TrustLens tracks refund rate, refund value, refund frequency, category-specific return behavior, and related customer patterns over time. This helps you spot serial returners and high-risk refund behavior earlier instead of reviewing refunds one order at a time.

Can TrustLens help with chargebacks and disputes?

Yes — and the core chargeback tracking is in the free version. TrustLens automatically ingests disputes from Stripe and WooPayments, accepts manual entry for other gateways (PayPal, Square, offline), keeps per-customer dispute counters, and feeds dispute history into trust scores. The free dashboard also shows a Chargeback Ratio Speedometer with a Healthy / Approaching / Action-needed status against Visa, Mastercard, Amex, and Discover thresholds. Pro adds a dedicated Advanced Chargeback Monitor with per-brand breakdown (Visa VDMP/VFMP, Mastercard ECP, Amex, Discover), 12-month trend, trailing-30-day window, daily ratio email alerts, a one-click Dispute Evidence Report for processor responses, and auto-block after N lost disputes.

How does the Chargeback Ratio Monitor work?

TrustLens captures the card brand on every Stripe and WooPayments paid order and tracks how many of those orders end up as disputes. Your blended monthly chargeback ratio is shown on the dashboard speedometer, with status colors keyed to Visa VDMP/VFMP, Mastercard ECP, Amex, and Discover monitoring thresholds — so you can see if you're approaching enrollment before it happens. Pro adds per-brand ratios, the 12-month trend chart, the trailing-30-day window, and daily email alerts.

What is Card-Testing Defense?

Card-Testing Defense (free) is real-time protection against stolen-card attack bots that probe your checkout with thousands of declined payment attempts. TrustLens watches per-device decline rates in a 60-second rolling window, matching on both the browser fingerprint and a server-side fingerprint (IP and user agent) so bots can't slip through by rotating their browser fingerprint. When a device crosses the threshold it's locked out of checkout for 90 seconds, blocking the attack before it reaches your payment gateway and runs up gateway fees, fraud fees, and downstream chargebacks. VIP Customer Bypass is enabled by default, so established customers — those who meet your minimum-order threshold (default 3 completed orders) and aren't already in a Risk or Critical segment — are never blocked by velocity rules. A one-click Panic Freeze button halts all checkouts for 15 minutes during an active attack your thresholds haven't caught. Pro adds auto-escalation, a geographic-diversity safeguard so flash-sale traffic isn't mistaken for an attack, fingerprint and IP CIDR allowlists, attack analytics with CSV export, and Slack alerts.

Can I automate actions based on customer risk?

Yes, with Pro. Automation Rules let you build trigger-based rules that fire when customer risk changes, orders are placed, refunds are processed, disputes are filed, linked accounts are detected, card-testing attacks happen, or shipping anomalies are spotted. Each rule supports 30+ condition fields and actions like block customer, hold order, send email, fire webhook, allowlist customer, cancel order, or tag customer. Pro automation also includes a save-time validator that blocks rules that can never fire, an inline inspector that shows exactly why each rule fired or didn't, and async HMAC-SHA256-signed webhooks with automatic retry.

What happens when I block a customer?

Blocked customers see a customizable message when they try to add items to their cart or proceed to checkout. The block applies to both logged-in users and guest checkouts matching the blocked email. All blocked checkout attempts are logged.

Can I undo a block?

Yes. You can unblock a customer at any time from their profile page or the customer list. You can also add customers to the allowlist, which locks their score at 100 and prevents any negative signals from affecting them.

What happens right after I install TrustLens?

New WooCommerce orders are analyzed automatically after activation. If you already have historical orders, you can run Historical Sync from the dashboard to build trust profiles from your existing store data without slowing down the frontend.

Does this slow down my store?

No. Score calculations run asynchronously via Action Scheduler (the same system WooCommerce uses). Checkout blocking uses a lightweight email-hash lookup. The historical sync processes orders in small batches in the background.

Does TrustLens send customer data to an external service?

No customer personal data ever leaves your site. TrustLens works inside your WordPress and WooCommerce installation. The only default external call is the optional Pro report-verification feature, which (while enabled) sends a non-personal, one-way fingerprint of a dispute report to the TrustLens verification service so issuers can confirm it is genuine — never customer data, and it can be disabled. All other external delivery (webhooks, email notifications) happens only if you configure it.

Is TrustLens compatible with WooCommerce HPOS?

Yes. TrustLens declares full compatibility with High-Performance Order Storage and works with both legacy and HPOS-enabled stores.

Does TrustLens store personal data?

TrustLens stores customer email addresses and behavioral data (order counts, refund counts, trust scores) in custom database tables. Matching identifiers used for linked-account detection are pseudonymized using keyed HMAC-SHA256 hashes, preventing the raw values from being exposed or reused across sites. The plugin integrates with WordPress privacy tools — customers can request data export or erasure through the standard WordPress privacy workflow.

Can I access TrustLens data from external systems?

Yes. TrustLens includes a REST API with 8 endpoints for looking up customers, retrieving scores, filtering by segment, and triggering recalculations. API access requires either the manage_woocommerce capability or a valid API key configured in settings.

Can I get alerts and reports by email?

Yes. The free version includes core email notifications such as blocked checkout alerts, a welcome summary, and a weekly summary. Pro adds advanced alerts, daily digests, monthly revenue protection reports, and scheduled email reports.

What is the minimum data needed for accurate scoring?

By default, customers need at least 3 orders before they move out of the Normal segment. You can adjust this threshold in Settings > General. Customers below the threshold still accumulate signals — they just aren't classified until enough data exists.

Does the free version include all detection modules?

Yes. All 8 detection modules ship in the free version — returns, orders, coupons, categories, linked accounts, shipping address anomalies, chargebacks, and card-testing defense. There are no trial limits, no disabled scoring, and no locked modules. Pro adds automation rules, webhooks, scheduled reports, payment-method risk controls, the advanced per-brand Chargeback Monitor with daily alerts, Card-Testing Defense Pro (auto-escalation + analytics + Slack alerts), and 10 advanced notification types.

What happens if I rotate my WordPress secret keys?

Important: TrustLens uses your WordPress auth secret key (via wp_salt('auth')) as the HMAC keying material for hashing customer emails and linked-account fingerprints. This is a deliberate security choice — it makes stored hashes non-reversible and non-portable across sites. The trade-off is that regenerating your WordPress secret keys (whether through a security plugin's "regenerate keys" tool or by editing wp-config.php directly) will permanently invalidate every customer hash and fingerprint already stored in your TrustLens tables. After rotation, the plugin won't be able to match a returning customer to their existing trust profile, and linked-account detection will reset. If you ever need to rotate WordPress secret keys, plan to run Historical Sync afterward so TrustLens rebuilds the customer table from your existing WooCommerce order data using the new keying material. Allowlisted/blocked status set manually on individual customer rows is the exception that won't auto-recover — re-apply those after the sync.

更新日志:

1.3.9 1.3.8 1.3.7 1.3.6 1.3.5 1.3.4 1.3.3 1.3.1 1.3.0 The centerpiece of 1.3.0 is the new Chargeback Evidence Report (Pro) — a representment-ready document that builds your Visa Compelling Evidence 3.0 case automatically and, uniquely, lets a card issuer independently verify it as genuine and unaltered at a neutral domain: every report carries a tamper-evidence SHA-256 fingerprint, a scannable QR code, and a public verification page. It's rounded out by a broad reliability and accuracy pass across scoring, reporting, chargebacks, automation, and the dashboard. 1.2.8