TrustLens – Fraud Prevention & Chargeback Defense for WooCommerce
Most WooCommerce fraud doesn’t look like fraud. It looks like a customer. The shopper who returns nearly everything they buy. The “new” account that shares a shipping address with three others you already flagged. The checkout that’s quietly taking dozens of declined cards in a row. None of that trips a payment gateway’s per-transaction check — because each individual charge looks fine. It’s the pattern across orders that gives it away, and that’s the part most stores never see until the chargeback ratio is already climbing.
TrustLens watches that pattern. Here’s a two-minute walkthrough of how it works:
WooCommerce fraud prevention built on customer behavior, not just card checks
TrustLens is a customer trust scoring and fraud detection plugin for WooCommerce. Instead of judging a single transaction, it scores every shopper 0–100 from how they’ve actually behaved on your store — order history, returns, coupon use, disputes — and sorts them into six segments: VIP, Trusted, Normal, Caution, Risk, Critical. Open any customer’s profile and you see exactly which signals moved their score. Nothing is a black box.
How trust scoring works
Every customer starts at a neutral base score of 50. From there, TrustLens’ eight detection modules each contribute signals — positive or negative — based on what that customer has actually done: a clean return history nudges the score up, a pattern of coupon abuse pulls it down, a filed dispute pulls it down further. Customers also earn a small, transparent age bonus for sticking around, added in three steps as an account passes 90, 180, and 365 days since their first order — a customer who’s bought from you for over a year without causing a problem earns the benefit of the doubt. Every signal that touched the score — module, points, and a plain-English reason — is listed right on the customer’s profile. Nothing is a mystery number.
The final score is clamped to 0–100 and mapped into one of six segments:
- VIP (90+) — your best customers; bypasses velocity-based checkout rules by default
- Trusted (70+) — solid history, low risk
- Normal (50+) — the default for new or unremarkable accounts
- Caution (30+) — some signals worth watching
- Risk (10+) — meaningful abuse or dispute signals present
- Critical (0+) — the strongest risk signals TrustLens tracks
Every threshold above is the default and fully configurable in Settings, because a 40% return rate might be alarming for one store and unremarkable for another. For the full mechanics, see the customer trust score guide and the segments explained guide.
Eight detection modules, working in the background
Return abuse. Tracks refund rate, refund value, and refund frequency over time rather than judging any single return in isolation. A customer who returns one order out of twelve looks very different from one who returns three out of four.
Order patterns. Watches velocity and behavior across a customer’s order history — a signal that’s invisible when you’re looking at orders one at a time in the WooCommerce admin, but obvious once it’s plotted against everyone else’s normal buying pattern.
Coupon abuse. Catches the two most common ways discount codes get exploited: a “new customer” welcome code used repeatedly from accounts that are really the same person, and coupon codes applied in patterns that don’t match organic use.
Category-aware risk. Return behavior means something different depending on what’s being returned — a high return rate on apparel is often just sizing, while the same rate on electronics or consumables is a different story. This module scores returns in the context of the product category rather than one blanket rule for the whole catalog.
Linked accounts. Builds fingerprints from shipping address, billing address, phone number, IP address, payment method, and device user agent, then flags when multiple customer “accounts” share enough signals to plausibly be the same person or fraud ring behind separate identities. This is how TrustLens catches someone opening five accounts to claim five first-order discounts.
Shipping anomalies. Flags address-hopping and reshipping patterns associated with stolen-card fraud — an order pattern that looks like it’s testing which shipping addresses a stolen card will get through on.
Chargeback tracking. Automatically ingests disputes from Stripe and WooPayments the moment they’re filed, keeps a running per-customer dispute count, and feeds that history into the trust score, so a customer with two prior disputes isn’t treated the same as a first-time buyer.
Card-testing defense. Real-time protection against bots that probe your checkout with a rapid burst of small, mostly-declined charges to find out which stolen card numbers are still live. A one-click Panic Freeze button lets you lock down checkout instantly if you spot an attack your automatic thresholds haven’t caught yet.
Card-testing attacks: what they are and why they cost more than the declines
A card-testing attack isn’t someone trying to buy from you — it’s a bot using your checkout as a free tool to validate a batch of stolen card numbers before using them elsewhere. It fires small charges, often a different card on each attempt, and just wants a “declined” or “approved” answer. Most attempts fail, so it’s easy to mistake the pile of declined orders for nothing more than that.
The real cost shows up sideways: gateway fees on every attempted charge, a higher fraud score with your payment provider from the sudden spike in bad attempts, and — if even a handful of those stolen cards turn out to be live — chargebacks landing weeks later with your store’s name on them.
TrustLens watches decline velocity per device in real time, matching on both the browser fingerprint and a server-side fingerprint (IP and user agent) so a bot can’t dodge detection by rotating its browser signature. When a device crosses your threshold, it’s locked out of checkout automatically — before the attack reaches your gateway, runs up fees, or produces a chargeback down the line. VIP Customer Bypass is on by default, so real repeat customers are never caught in a velocity rule meant for bots. Full mechanics are in the card-testing defense docs.
The Command Center dashboard
One screen shows your store’s health score, trust-score trends, the six-segment distribution, your high-risk list, and a chargeback-ratio speedometer benchmarked against Visa, Mastercard, Amex, and Discover monitoring thresholds — so you can see a dispute problem building before it triggers a monitoring program, not after.
Chargebacks: seeing the ratio before the card networks do
Visa, Mastercard, Amex, and Discover each run monitoring programs that watch your chargeback ratio — disputes as a percentage of transactions — and enroll merchants who cross a threshold into a program with extra fees, extra scrutiny, and in bad cases the threat of losing processing entirely. Most merchants only learn the exact numbers when their processor emails them: Visa’s VFMP sits at 0.65%, Visa’s VDMP at 0.9%, Mastercard’s ECP at 1.5%, and Amex and Discover’s excessive-dispute programs at 1.0%.
TrustLens captures the card brand on every Stripe and WooPayments order and tracks how many end up disputed, so your blended monthly ratio shows up on the dashboard as a speedometer — Healthy, Approaching, or Action-needed — measured against those same four thresholds. The point isn’t to replace your processor’s own monitoring; it’s to give you the same number they’re watching, weeks before a threshold crossing becomes a phone call. See the chargeback speedometer and ratio thresholds guide and the Stripe chargeback tracking guide for the full picture.
How TrustLens compares
Your payment gateway scores the transaction — the charge itself, at the moment it happens. It’s genuinely good at catching an obviously stolen card, but has no memory of what that customer did last month and no way to connect two “different” accounts placing suspiciously similar orders. TrustLens scores the customer, over time, using exactly the signals a per-transaction check can’t see.
A simple IP blocklist stops a known-bad address and nothing else — it doesn’t adapt when someone switches networks, doesn’t know a “new” account is really a repeat offender, and does nothing for friendly-fraud chargebacks or return abuse, since those orders come from real cards on real networks. See the IP blocking vs. behavioral fraud scoring comparison for where each approach holds up and where it doesn’t.
For specific alternatives, see FraudLabs Pro vs. TrustLens and TrustLens vs. WooCommerce’s built-in anti-fraud tools.
Meet the customers TrustLens catches
The serial returner. Orders regularly, pays without issue, and sends back a third or more of what they buy. No single return looks wrong — the pattern across a dozen orders does. Return Abuse and Category-Aware Risk build that picture order by order.
The coupon farmer. Opens a “new” account every few weeks, each with a slightly different name and email, each claiming the same first-order discount. Individually, every account looks like a normal new customer. Linked Accounts connects them by shipping address, phone, or device, and Coupon Abuse flags the repeated pattern.
The fraud ring. Several accounts, several names, but the same billing address, payment method, or device turning up across all of them — invisible until someone cross-references order details by hand, which is exactly what Linked Accounts does automatically on every order.
The card-testing bot. Never intends to complete a purchase. Runs dozens of small, mostly-declined charges through checkout in a short burst, hunting for which stolen card numbers still work. Card-Testing Defense watches decline velocity per device and locks it out before the attack reaches your gateway.
Integrations and compatibility
TrustLens is built to sit inside the store you already run, not bolt on a parallel system. Stripe and WooPayments disputes are ingested automatically the moment they’re filed — no webhook setup required. Other gateways (PayPal, Square, offline payments) can be tracked through a manual chargeback entry form on the order edit screen. Classic checkout and the WooCommerce Blocks checkout are both enforced, so a blocked customer is blocked no matter which checkout your theme uses. TrustLens declares full compatibility with WooCommerce HPOS, works with GDPR data export and erasure requests through standard WordPress privacy tools, and includes a REST API for looking up customers, retrieving scores, filtering by segment, and triggering recalculations from external systems. Pro adds signed webhooks for pushing trust events to Slack, Zapier, or your own tools — see the webhooks and REST API integration guide.
Already have order history? Historical Sync builds trust profiles from your existing orders in small background batches, so you’re not starting from a blank slate. Details in the Historical Sync guide.
You stay in control
TrustLens never auto-blocks a single customer in the free version. It surfaces the risk; you decide — block at checkout, allowlist forever, or just watch the trend. Every score, badge, and detection module is visible and adjustable from Settings.
Privacy is built the same way: everything runs inside your own store, customer identifiers are pseudonymized with keyed HMAC-SHA256 (not reversible, not portable to another site), and no customer data is ever sent to a third party by default.
Free — the complete detection plugin
- All 8 detection modules — return abuse, order patterns, coupon abuse, category-aware risk, linked accounts / fraud rings, shipping anomalies, chargeback tracking (auto-ingest from Stripe & WooPayments), and real-time card-testing defense with a one-click Panic Freeze
- Trust scoring engine — 0–100 score, six segments, every signal visible on the profile, an account-age bonus for established customers, fully configurable thresholds
- Command Center dashboard — score trends, segment distribution, high-risk list, and a chargeback-ratio speedometer (Visa / Mastercard / Amex / Discover)
- Customer management — trust badges on the orders list, detailed profiles, bulk actions, allowlist protection, checkout enforcement (Classic + Blocks)
- Operational — Historical Sync, REST API, HPOS support, GDPR export/erasure, core email notifications
Pro — act on what TrustLens finds
Advanced Chargeback Monitor and Dispute Evidence Reports. Where the free speedometer shows your blended ratio, Pro breaks it down per card brand against Visa VDMP/VFMP, Mastercard ECP, Amex, and Discover, adds a 12-month trend chart and a dispute-deadline worklist, and generates a representment-ready Dispute Evidence Report that matches the disputed order against the customer’s prior order history and flags whether it qualifies for Visa Compelling Evidence 3.0. Each report carries a tamper-evident fingerprint and QR code so a card issuer can independently verify it’s genuine at a neutral domain. See the dispute evidence report guide.
Automation Rules. Build if-this-then-that logic on everything TrustLens detects: 15 triggers (score changes, new orders, refunds, disputes, linked-account detections, card-testing attacks, and more), 30-plus condition fields, and actions like blocking a customer, holding an order, sending an email, firing a signed webhook, allowlisting, cancelling, or tagging. A save-time validator catches rules that could never fire before you save them, and an inline inspector shows exactly why each rule did or didn’t trigger. See the automation rules playbook.
Card-Testing Defense Pro. Adds auto-escalation for attacks that outpace your base thresholds, a geo-diversity safeguard so a flash-sale traffic spike isn’t mistaken for a bot, fingerprint and IP-range allowlists, full attack history, and Slack or email alerts the moment a lockdown triggers. See the card-testing auto-escalation guide.
Payment Method Risk Controls, Scheduled Reports, and more. Restrict specific payment methods for risky segments without locking a customer out of checkout entirely, receive daily, weekly, or monthly trust-intelligence summaries by email, and get advanced notification types beyond the free version’s core alerts. See the scheduled reports guide.
Bottom line: Free surfaces the risk. Pro acts on it.
Getting started
Install TrustLens and open TrustLens → Dashboard. All 8 detection modules and card-testing defense are already running with sensible default thresholds — there’s nothing to configure before it starts working. If you have existing orders, Run Historical Sync to build trust profiles from that history in the background. Full steps are in the Installation section below, or the getting-started guide with screenshots.
Docs & resources
- Getting started with TrustLens
- How TrustLens scores a customer
- The 8 detection modules, explained
- Card-testing defense docs
- Chargeback Monitor docs
- Why TrustLens Free never auto-blocks
- Free vs Pro, in detail
- Full changelog
Who it’s for
If your store has outgrown “just watch the orders list” — because refunds are eating margin, a coupon code is circulating somewhere it shouldn’t, or you’ve had a chargeback ratio scare — TrustLens gives you the visibility to catch it early and the control to act on your own terms — starting with the order history your store already has.
More from Webstepper
TrustLens protects your revenue; Smart Cycle Discounts grows it — scheduled BOGO, bulk, tiered, and coupon campaigns for WooCommerce, with Cycle AI to build the deal from a plain-English description. Built and supported by the same team.
External Services
This plugin may connect to external services as described below.
Freemius SDK
This plugin uses the Freemius SDK for …
