Linux 软件免费装
Banner图

TrustLens – Fraud Prevention & Chargeback Defense for WooCommerce

开发者 webstepper
freemius
更新时间 2026年6月29日 01:31
PHP版本: 7.4 及以上
WordPress版本: 7.0
版权: GPLv3 or later
版权网址: 版权信息

标签

chargeback anti-fraud woocommerce security fake orders card testing

下载

1.0.1 1.0.3 1.0.4 1.0.5 1.0.6 1.1.0 1.1.1 1.1.2 1.1.3 1.1.4 1.1.5 1.1.6 1.1.7 1.1.8 1.2.0 1.2.1 1.2.2 1.2.3 1.2.4 1.2.5 1.2.6 1.2.7 1.2.8 1.3.0 1.3.1 1.3.3 1.3.4

详情介绍:

Stop losing money to WooCommerce fraud you can't see. Serial returners, coupon abusers, fraud rings, and stolen-card bots quietly drain stores — often thousands per year. By the time the chargeback ratio climbs or your margin disappears, the damage is done. TrustLens is a behavior-based customer trust scoring and fraud detection plugin for WooCommerce. It scores every shopper from 0 to 100 using real store behavior and sorts them into six risk segments — VIP, Trusted, Normal, Caution, Risk, Critical. Eight detection modules run in the background: returns, orders, coupons, categories, linked accounts, shipping anomalies, chargebacks, and card-testing attacks at checkout. You see exactly which signals moved each score, and you decide what to do about it. TrustLens never auto-blocks in Free. You review the customer profile and choose: block at checkout, allowlist forever, or simply watch the trend. Nothing happens behind your back. All customer data stays inside your store — no third-party calls — and linked-account fingerprints are pseudonymized with keyed HMAC-SHA256 hashes. Video Tutorial https://youtu.be/Xxz8lcTnAlU Abuse patterns TrustLens catches TrustLens turns the WooCommerce data you already have into actionable customer intelligence. Instead of reading hundreds of orders and refunds line by line, you get one clear score per customer and a six-segment view of your entire customer base. The dashboard surfaces the patterns that move the needle: You see who's worth rewarding, who's silently costing you, and you take the call. What's included in the free version The WordPress.org download is the complete plugin — no trial limits, no disabled scoring, no locked modules. Everything below ships in Free. Detection — all 8 modules included Trust scoring engine Dashboard and monitoring Customer management Operational What Pro adds Pro is for stores that want TrustLens to act on what it finds — automation, advanced alerts, deeper chargeback analytics, and payment-risk workflows. Advanced Chargeback Monitor A dedicated TrustLens → Chargeback Monitor page built to keep you clear of card-network monitoring programs: Chargeback Ratio Email Alerts — daily check that emails you before any brand crosses its network threshold, deduplicated per brand per calendar month so you're never spammed. Automation Rules Build trigger-based rules that fire when customer risk changes, orders are placed, refunds are processed, disputes are filed, linked accounts are detected, card-testing attacks happen, or shipping anomalies are spotted. Card-Testing Defense Pro On top of free Card-Testing Defense, Pro adds attack-scale protection: Payment Method Risk Controls — hide specific payment gateways for high-risk customers, linked accounts, or velocity spikes. Fine-grained checkout protection without blocking the whole order. Scheduled Reports — daily, weekly, or monthly email summaries of store risk activity, customer trends, and protection KPIs. 10 advanced notification types — High-Risk Order Alert, Segment Change Alert, Daily Digest, High-Value Order Alert, Repeat Refunder Alert, Velocity Alert, Score Recovery Alert, New Customer Risk Alert, Monthly Revenue Protection Report, Chargeback Filed Alert. Advanced Address Analysis — diversity-trend detection and enhanced country-mismatch severity for deeper shipping-fraud insight. Bottom line: Free surfaces the risk. Pro acts on it. How trust scoring works Every customer starts at a neutral 50. TrustLens detection modules analyze behavior and apply positive or negative signals: Scores are always clamped to 0–100. Every signal is visible on the customer profile so you can see exactly how each score was calculated and trust the decision. Customers below the configurable minimum order threshold (default: 3 orders) stay in the Normal segment until enough data exists for confident scoring — so new stores don't get noisy false positives in their first weeks. Who TrustLens is for Privacy and data handling TrustLens works entirely inside your WordPress and WooCommerce installation and never sends customer personal data off your site. The one default external call is the optional Pro report-verification feature, which — while enabled — sends a non-personal, one-way fingerprint of a dispute report to the TrustLens verification service (webstepper.io) so a card issuer can confirm the report is genuine; it sends no customer data and can be disabled (see External Services below). All other external delivery (webhooks, Slack alerts, email notifications) happens only if you configure it. Built for production WooCommerce TrustLens is engineered for busy stores and growing order volume: If you need chargeback prevention, return-abuse detection, fraud-ring detection, or stolen-card attack protection for WooCommerce, TrustLens gives you the data and the tools to act — without taking control out of your hands.

安装:

  1. Install TrustLens directly from the WordPress plugin repository, or upload the trustlens folder to /wp-content/plugins/
  2. Activate the plugin through the Plugins menu — TrustLens checks for WooCommerce automatically
  3. Open TrustLens → Dashboard to see the Command Center
  4. Click Run Historical Sync to build trust profiles from your existing WooCommerce orders — the sync runs in the background in small batches and does not affect site performance
  5. Visit TrustLens → Settings to adjust scoring thresholds, checkout blocking, and notification preferences
What works out of the box: If you use Stripe or WooPayments, no extra setup is required for chargeback and card-brand capture. Other gateways can be tracked through the manual chargeback entry form on the order edit page.

屏幕截图:

  • **Card-Testing Defense** — Real-time decline-velocity monitoring, attacker fingerprints, one-click Panic Freeze, and the recent-attack feed
  • **Customer List** — Searchable, sortable list with segment badges, trust scores, return rates, and bulk actions
  • **Customer Detail** — Full profile with the trust-score gauge, signal impact, return-rate trend, and linked accounts
  • **Order Integration** — Customer trust score, segment, and dispute status shown right on the WooCommerce order edit screen
  • **Settings** — Detection modules and scoring thresholds, with checkout-blocking and notification controls

升级注意事项:

1.3.4 Fixes a fatal error that could prevent the plugin from activating. Recommended for everyone. 1.3.3 Fixes a bug where saving one Settings tab could reset settings on other tabs — recommended for everyone. Note for Pro stores: chargeback auto-block now defaults to OFF (opt-in); stores that already set a threshold keep it. 1.3.1 Free stores: this restores the Chargeback Tracking module (per-customer disputes + the chargeback-ratio speedometer) that recent free builds were missing — Pro stores were unaffected. It also clears up the activation and account screens. Recommended for all users. 1.3.0 The headline is the new Chargeback Evidence Report (Pro): it assembles your Visa Compelling Evidence 3.0 case automatically and is independently verifiable — a card issuer can confirm it's genuine and unaltered at webstepper.io/verify via a tamper-evidence fingerprint and scannable QR code (no customer data is sent; it can be switched off). Also includes a broad reliability and accuracy pass: correct chargeback brand attribution and ratios, accurate monthly ROI, correct scheduled-report timing on non-UTC stores, REST score recalculation now triggering automation/webhooks, worklist and dashboard data fixes, CSV-export hardening, and a Freemius SDK update. Recommended for all users. 1.2.8 Adds a video walkthrough to the plugin page and refreshes the banner artwork. No functional changes — safe to skip if you're current. 1.2.7 A major automation reliability pass, 10 new rule conditions, a first-class Flagged customer status, and a chargeback dispute-deadline worklist. 1.2.6 Smoother day-to-day controls: in-place customer actions, a guided setup card, plain-language score explanations, and clearer Card-Testing Defense.

常见问题:

How is TrustLens different from my payment gateway's fraud tools?

Your payment gateway (Stripe Radar and similar) scores a single transaction at the moment of charge — card, IP, AVS, device — and is blind to what happens before and after on your store. TrustLens scores the customer's behavior over time: refund and return patterns, coupon abuse, multi-account links, dispute history, category-specific returns, and card-testing activity at checkout. Those are signals your gateway never sees. They're complementary, not competing. Your gateway blocks obvious stolen-card charges; TrustLens surfaces friendly-fraud chargebacks, serial returners, coupon abusers, fraud rings, and card-testing bots that slip past a per-transaction view — and it keeps you in control (the free version never auto-blocks; you decide). Everything runs inside your own store, so no customer data leaves your site.

Does TrustLens work with guest checkout?

Yes. Customers are identified by a hash of their email address, so guest and registered customers are tracked equally. If a guest later registers, their history carries over.

Will TrustLens automatically block customers?

By default, no. The free version is manual: it surfaces customer risk data, and you decide when to block or allowlist someone. Pro can optionally automate specific actions, including alerts, order holds, verification requirements, and customer blocking if you configure automation rules or chargeback auto-blocking.

How does linked accounts detection work?

TrustLens creates fingerprints from shipping addresses, billing addresses, phone numbers, IP addresses, payment methods, and device user agents. When multiple customer accounts share fingerprints, they are flagged as linked. This helps detect multi-account abuse like repeated first-order discounts.

Can TrustLens help reduce return abuse and refund abuse in WooCommerce?

Yes. TrustLens tracks refund rate, refund value, refund frequency, category-specific return behavior, and related customer patterns over time. This helps you spot serial returners and high-risk refund behavior earlier instead of reviewing refunds one order at a time.

Can TrustLens help with chargebacks and disputes?

Yes — and the core chargeback tracking is in the free version. TrustLens automatically ingests disputes from Stripe and WooPayments, accepts manual entry for other gateways (PayPal, Square, offline), keeps per-customer dispute counters, and feeds dispute history into trust scores. The free dashboard also shows a Chargeback Ratio Speedometer with a Healthy / Approaching / Action-needed status against Visa, Mastercard, Amex, and Discover thresholds. Pro adds a dedicated Advanced Chargeback Monitor with per-brand breakdown (Visa VDMP/VFMP, Mastercard ECP, Amex, Discover), 12-month trend, trailing-30-day window, daily ratio email alerts, a one-click Dispute Evidence Report for processor responses, and auto-block after N lost disputes.

How does the Chargeback Ratio Monitor work?

TrustLens captures the card brand on every Stripe and WooPayments paid order and tracks how many of those orders end up as disputes. Your blended monthly chargeback ratio is shown on the dashboard speedometer, with status colors keyed to Visa VDMP/VFMP, Mastercard ECP, Amex, and Discover monitoring thresholds — so you can see if you're approaching enrollment before it happens. Pro adds per-brand ratios, the 12-month trend chart, the trailing-30-day window, and daily email alerts.

What is Card-Testing Defense?

Card-Testing Defense (free) is real-time protection against stolen-card attack bots that probe your checkout with thousands of declined payment attempts. TrustLens watches per-device decline rates in a 60-second rolling window, matching on both the browser fingerprint and a server-side fingerprint (IP and user agent) so bots can't slip through by rotating their browser fingerprint. When a device crosses the threshold it's locked out of checkout for 90 seconds, blocking the attack before it reaches your payment gateway and runs up gateway fees, fraud fees, and downstream chargebacks. VIP Customer Bypass is enabled by default, so established customers — those who meet your minimum-order threshold (default 3 completed orders) and aren't already in a Risk or Critical segment — are never blocked by velocity rules. A one-click Panic Freeze button halts all checkouts for 15 minutes during an active attack your thresholds haven't caught. Pro adds auto-escalation, a geographic-diversity safeguard so flash-sale traffic isn't mistaken for an attack, fingerprint and IP CIDR allowlists, attack analytics with CSV export, and Slack alerts.

Can I automate actions based on customer risk?

Yes, with Pro. Automation Rules let you build trigger-based rules that fire when customer risk changes, orders are placed, refunds are processed, disputes are filed, linked accounts are detected, card-testing attacks happen, or shipping anomalies are spotted. Each rule supports 30+ condition fields and actions like block customer, hold order, send email, fire webhook, allowlist customer, cancel order, or tag customer. Pro automation also includes a save-time validator that blocks rules that can never fire, an inline inspector that shows exactly why each rule fired or didn't, and async HMAC-SHA256-signed webhooks with automatic retry.

What happens when I block a customer?

Blocked customers see a customizable message when they try to add items to their cart or proceed to checkout. The block applies to both logged-in users and guest checkouts matching the blocked email. All blocked checkout attempts are logged.

Can I undo a block?

Yes. You can unblock a customer at any time from their profile page or the customer list. You can also add customers to the allowlist, which locks their score at 100 and prevents any negative signals from affecting them.

What happens right after I install TrustLens?

New WooCommerce orders are analyzed automatically after activation. If you already have historical orders, you can run Historical Sync from the dashboard to build trust profiles from your existing store data without slowing down the frontend.

Does this slow down my store?

No. Score calculations run asynchronously via Action Scheduler (the same system WooCommerce uses). Checkout blocking uses a lightweight email-hash lookup. The historical sync processes orders in small batches in the background.

Does TrustLens send customer data to an external service?

No customer personal data ever leaves your site. TrustLens works inside your WordPress and WooCommerce installation. The only default external call is the optional Pro report-verification feature, which (while enabled) sends a non-personal, one-way fingerprint of a dispute report to the TrustLens verification service so issuers can confirm it is genuine — never customer data, and it can be disabled. All other external delivery (webhooks, email notifications) happens only if you configure it.

Is TrustLens compatible with WooCommerce HPOS?

Yes. TrustLens declares full compatibility with High-Performance Order Storage and works with both legacy and HPOS-enabled stores.

Does TrustLens store personal data?

TrustLens stores customer email addresses and behavioral data (order counts, refund counts, trust scores) in custom database tables. Matching identifiers used for linked-account detection are pseudonymized using keyed HMAC-SHA256 hashes, preventing the raw values from being exposed or reused across sites. The plugin integrates with WordPress privacy tools — customers can request data export or erasure through the standard WordPress privacy workflow.

Can I access TrustLens data from external systems?

Yes. TrustLens includes a REST API with 8 endpoints for looking up customers, retrieving scores, filtering by segment, and triggering recalculations. API access requires either the manage_woocommerce capability or a valid API key configured in settings.

Can I get alerts and reports by email?

Yes. The free version includes core email notifications such as blocked checkout alerts, a welcome summary, and a weekly summary. Pro adds advanced alerts, daily digests, monthly revenue protection reports, and scheduled email reports.

What is the minimum data needed for accurate scoring?

By default, customers need at least 3 orders before they move out of the Normal segment. You can adjust this threshold in Settings > General. Customers below the threshold still accumulate signals — they just aren't classified until enough data exists.

Does the free version include all detection modules?

Yes. All 8 detection modules ship in the free version — returns, orders, coupons, categories, linked accounts, shipping address anomalies, chargebacks, and card-testing defense. There are no trial limits, no disabled scoring, and no locked modules. Pro adds automation rules, webhooks, scheduled reports, payment-method risk controls, the advanced per-brand Chargeback Monitor with daily alerts, Card-Testing Defense Pro (auto-escalation + analytics + Slack alerts), and 10 advanced notification types.

What happens if I rotate my WordPress secret keys?

Important: TrustLens uses your WordPress auth secret key (via wp_salt('auth')) as the HMAC keying material for hashing customer emails and linked-account fingerprints. This is a deliberate security choice — it makes stored hashes non-reversible and non-portable across sites. The trade-off is that regenerating your WordPress secret keys (whether through a security plugin's "regenerate keys" tool or by editing wp-config.php directly) will permanently invalidate every customer hash and fingerprint already stored in your TrustLens tables. After rotation, the plugin won't be able to match a returning customer to their existing trust profile, and linked-account detection will reset. If you ever need to rotate WordPress secret keys, plan to run Historical Sync afterward so TrustLens rebuilds the customer table from your existing WooCommerce order data using the new keying material. Allowlisted/blocked status set manually on individual customer rows is the exception that won't auto-recover — re-apply those after the sync.

更新日志:

1.3.4 1.3.3 1.3.1 1.3.0 The centerpiece of 1.3.0 is the new Chargeback Evidence Report (Pro) — a representment-ready document that builds your Visa Compelling Evidence 3.0 case automatically and, uniquely, lets a card issuer independently verify it as genuine and unaltered at a neutral domain: every report carries a tamper-evidence SHA-256 fingerprint, a scannable QR code, and a public verification page. It's rounded out by a broad reliability and accuracy pass across scoring, reporting, chargebacks, automation, and the dashboard. 1.2.8 1.2.7 1.2.6