This is an info Alert.
x402 Logo
  • Product
    • Become Agent-Ready
      • Merchants
        Agentic Commerce — list your store across ChatGPT, Gemini, Claude & Perplexity
      • Publishers
        Monetize your content when AI agents read, cite, or train on it
      • SaaS Companies
        Treat AI agents as first-class customers with agent-priced checkout
    • Monetize
      • Monetize MCP Server
        Charge per call on any MCP server in 2 minutes
      • Monetize AI Agents
        Turn n8n, Zapier, Activepieces workflows into revenue
      • Agent Feed
        Pay-per-query access to licensed publisher content for your agents
  • Resources
    • xpay Ecosystem
      • xpay✦ Tools
        1,000+ pay-per-use tools for your AI agents
      • Agent-Ready SaaS Index
        25,481 SaaS scored on agent-buyability
      • SaaS Pricing Database
        Pricing pages indexed across 1,000+ categories
      • Shopify Apps Directory
        Every Shopify app, with its full review history
      • WooCommerce Plugins Directory
        Every WooCommerce plugin, scored on how well it is maintained
      • GitHub
        Open source repositories
    • Agent Building
      • Agent Frameworks
        AI frameworks for building multi-agent systems
      • x402 Integration
        AI frameworks with x402 payment integration
      • Networks
        Blockchain networks supporting x402
    • Company
      • About xpay✦
        Our mission, products, and protocols
      • Blog
        Latest insights and updates
      • Docs
        Complete xpay documentation
  • Pricing
  • Blog
  • Docs
Get Started
  1. xpay✦ Commerce

  2. Directory

  3. WooCommerce plugins

  4. TrustLens – Fraud Prevention & Chargeback Defense for WooCommerce

TrustLens – Fraud Prevention & Chargeback Defense for WooCommerce

Prevent WooCommerce fraud with behavioral trust scoring. Catch chargebacks, return abuse, coupon fraud, and card-testing attacks.

10+ active installs
5.0
(3 ratings)
Free on WordPress.org
View on WordPress.orgSupport forum
Will this break my store?

What the WordPress.org registry says about keeping TrustLens – Fraud Prevention & Chargeback Defense for WooCommerce running.

WordPress compatibility
Tested to 7.0.2
Tested against the WordPress branch in use today.
Last updated
23 days ago
Requires PHP
7.4
Your host must be running at least this version.
Requires WordPress
6.4
Requires other plugins
woocommerce
These must be installed and active first.
Contributors
2

10+ active installsWordPress.org reports installs in bands, not exact counts.
Maintenance & trust

Scored on how TrustLens – Fraud Prevention & Chargeback Defense for WooCommerce is looked after — not on how many stores run it.

95

out of 100
Well maintainedSome ratings or support history.

Maintenance
35 / 35
Updated 21 days ago.
WordPress compatibility
20 / 20
Tested to WP 7.0.2 (current).
Support responsiveness
Not enough data
Only 0 support thread(s) — not enough to judge.
Merchant satisfaction
11 / 15
5.0/5 across 3 rating(s).
Listing transparency
10 / 10
Provides: screenshots, description, homepage
1 of 5 measures had too little evidence to score. They are left out of the total rather than counted as zero — otherwise a plugin would be marked down for being small rather than for being poorly kept.Measured 2026-08-01 from the WordPress.org plugin registry.
Ratings

5.0

3 ratings
5★3
4★0
3★0
2★0
1★0
Every rating WordPress.org holds for this plugin, not a sample. Written reviews live in the plugin's WordPress.org reviews forum.

Stop losing money to WooCommerce fraud you can’t see. Serial returners, coupon abusers, fraud rings, and stolen-card bots quietly drain stores — often thousands a year, and by the time your chargeback ratio climbs the damage is done.

TrustLens is a behavior-based customer trust scoring and fraud detection plugin for WooCommerce. It scores every shopper 0–100 from real store behavior and sorts them into six segments — VIP, Trusted, Normal, Caution, Risk, Critical. Eight detection modules run in the background, from return abuse to card-testing attacks at checkout. You see exactly which signals moved each score, and you decide what to do.

TrustLens never auto-blocks in Free. You review the profile and choose: block at checkout, allowlist forever, or just watch the trend. All data stays inside your store (no third-party calls), with identifiers pseudonymized via keyed HMAC-SHA256.

Free — the complete plugin

  • All 8 detection modules — return abuse, order patterns, coupon abuse, category-aware risk, linked accounts / fraud rings, shipping anomalies, chargeback tracking (auto-ingest from Stripe & WooPayments), and real-time card-testing defense with a one-click Panic Freeze
  • Trust scoring engine — 0–100 score, six segments, every signal visible on the profile, loyalty bonus, configurable thresholds
  • Command Center dashboard — score trends, segment distribution, high-risk list, and a chargeback-ratio speedometer (Visa / Mastercard / Amex / Discover)
  • Customer management — trust badges on the orders list, detailed profiles, bulk actions, allowlist protection, checkout enforcement (Classic + Blocks)
  • Operational — Historical Sync, REST API, HPOS support, GDPR export/erasure, core email notifications

Pro — act on what TrustLens finds

  • Advanced Chargeback Monitor — per-brand ratios, 12-month trends, a dispute-deadline worklist, and independently verifiable Dispute Evidence Reports (tamper-evident fingerprint + QR, auto-flags Visa CE 3.0)
  • Automation Rules — 15 triggers, 30+ conditions, signed webhooks, async retry, save-time validation
  • Card-Testing Defense Pro — auto-escalation, geo-diversity safeguard, allowlists, attack history, and Slack/email alerts
  • Payment Method Risk Controls, Scheduled Reports, advanced notifications, and address analysis

Bottom line: Free surfaces the risk. Pro acts on it.

External Services

This plugin may connect to external services as described below.

Freemius SDK

This plugin uses the Freemius SDK for optional usage tracking, license management, and plugin updates.

When data is sent:

  • During plugin activation, only if the user explicitly opts in
  • When checking for plugin updates
  • When activating or deactivating a Pro license

What data is sent:

  • Site URL, WordPress version, and PHP version
  • Plugin version and activation status
  • Admin email (only if opted in)
  • License key (Pro version only)

Important: No data is sent unless you explicitly opt in during plugin activation. You can skip the opt-in entirely and use the free version without sharing any data.

  • Service: Freemius
  • Terms of Service: https://freemius.com/terms/
  • Privacy Policy: https://freemius.com/privacy/

Webhooks (Pro, Optional)

When webhooks are enabled in TrustLens settings (Pro feature), the plugin sends HTTP POST requests to URLs configured by the administrator.

When data is sent:

  • When a customer’s trust score is updated (if enabled)
  • When a customer is blocked (if enabled)
  • When a checkout is blocked (if enabled)
  • When a high-risk order is placed (if enabled)
  • When testing webhook connectivity

What data is sent:

  • Customer email hash and, when available, the customer email stored in TrustLens
  • Trust score and customer segment
  • Event type and timestamp
  • Order details for high-risk order events (order ID, total, status)
  • Site URL and site name

Important: Webhook endpoints are entirely configured by you. No data is sent to any third-party service unless you explicitly add webhook URLs. The plugin does not send data to the plugin developer or any default external service.

Report Verification (Pro, Optional)

When a Pro “dispute evidence report” is generated, TrustLens can register a tamper-evidence fingerprint of that report with the TrustLens verification service (webstepper.io), so a card issuer or payment processor can independently confirm at a public URL that the report is genuine and has not been altered.

When data is sent:

  • Each time a dispute evidence report is generated (Pro feature), while Report Verification is enabled (TrustLens → Chargeback Monitor)

What data is sent:

  • A one-way SHA-256 fingerprint of the report and a short derived report ID
  • The disputed order’s ID (number only) and a timestamp
  • The report’s risk figures: compelling-evidence count, trust score, risk segment, and return rate
  • Your site URL

No customer personal data is sent — no names, emails, addresses, IP addresses, or email hashes. The fingerprint is one-way and cannot be reversed into report contents.

Important: This feature is enabled by default and can be turned off at any time on the TrustLens → Chargeback Monitor page (“Report verification”). When disabled, nothing is sent to webstepper.io and the report simply omits the public verification link (it still shows its local fingerprint).

  • Service: Webstepper TrustLens Verification
  • Terms of Service: https://webstepper.io/terms-of-service/
  • Privacy Policy: https://webstepper.io/privacy-policy/

How is TrustLens different from my payment gateway’s fraud tools?

Your payment gateway (Stripe Radar and similar) scores a single transaction at the moment of charge — card, IP, AVS, device — and is blind to what happens before and after on your store. TrustLens scores the customer’s behavior over time: refund and return patterns, coupon abuse, multi-account links, dispute history, category-specific returns, and card-testing activity at checkout. Those are signals your gateway never sees.

They’re complementary, not competing. Your gateway blocks obvious stolen-card charges; TrustLens surfaces friendly-fraud chargebacks, serial returners, coupon abusers, fraud rings, and card-testing bots that slip past a per-transaction view — and it keeps you in control (the free version never auto-blocks; you decide). Everything runs inside your own store, so no customer data leaves your site.

Does TrustLens work with guest checkout?

Yes. Customers are identified by a hash of their email address, so guest and registered customers are tracked equally. If a guest later registers, their history carries over.

Will TrustLens automatically block customers?

By default, no. The free version is manual: it surfaces customer risk data, and you decide when to block or allowlist someone. Pro can optionally automate specific actions, including alerts, order holds, verification requirements, and customer blocking if you configure automation rules or chargeback auto-blocking.

How does linked accounts detection work?

TrustLens creates fingerprints from shipping addresses, billing addresses, phone numbers, IP addresses, payment methods, and device user agents. When multiple customer accounts share fingerprints, they are flagged as linked. This helps detect multi-account abuse like repeated first-order discounts.

Can TrustLens help reduce return abuse and refund abuse in WooCommerce?

Yes. TrustLens tracks refund rate, refund value, refund frequency, category-specific return behavior, and related customer patterns over time. This helps you spot serial returners and high-risk refund behavior earlier instead of reviewing refunds one order at a time.

Can TrustLens help with chargebacks and disputes?

Yes — and the core chargeback tracking is in the free version. TrustLens automatically ingests disputes from Stripe and WooPayments, accepts manual entry for other gateways (PayPal, Square, offline), keeps per-customer dispute counters, and feeds dispute history into trust scores. The free dashboard also shows a Chargeback Ratio Speedometer with a Healthy / Approaching / Action-needed status against Visa, Mastercard, Amex, and Discover thresholds.

Pro adds a dedicated Advanced Chargeback Monitor with per-brand breakdown (Visa VDMP/VFMP, Mastercard ECP, Amex, Discover), 12-month trend, trailing-30-day window, daily ratio email alerts, a one-click Dispute Evidence Report for processor responses, and auto-block after N lost disputes.

How does the Chargeback Ratio Monitor work?

TrustLens captures the card brand on every Stripe and WooPayments paid order and tracks how many of those orders end up as disputes. Your blended monthly chargeback ratio is shown on the dashboard speedometer, with status colors keyed to Visa VDMP/VFMP, Mastercard ECP, Amex, and Discover monitoring thresholds — so you can see if you’re approaching enrollment before it happens. Pro adds per-brand ratios, the 12-month trend chart, the trailing-30-day window, and daily email alerts.

What is Card-Testing Defense?

Card-Testing Defense (free) is real-time protection against stolen-card attack bots that probe your checkout with thousands of declined payment attempts. TrustLens watches per-device decline rates in a 60-second rolling window, matching on both the browser fingerprint and a server-side fingerprint (IP and user agent) so bots can’t slip through by rotating their browser fingerprint. When a device crosses the threshold it’s locked out of checkout for 90 seconds, blocking the attack before it reaches your payment gateway and runs up gateway fees, fraud fees, and downstream chargebacks.

VIP Customer Bypass is enabled by default, so established customers — those who meet your minimum-order threshold (default 3 completed orders) and aren’t already in a Risk or Critical segment — are never blocked by velocity rules. A one-click Panic Freeze button halts all checkouts for 15 minutes during an active attack your thresholds haven’t caught.

Pro adds auto-escalation, a geographic-diversity safeguard so flash-sale traffic isn’t mistaken for an attack, fingerprint and IP CIDR allowlists, attack analytics with CSV export, and Slack alerts.

Can I automate actions based on customer risk?

Yes, with Pro. Automation Rules let you build trigger-based rules that fire when customer risk changes, orders are placed, refunds are processed, disputes are filed, linked accounts are detected, card-testing attacks happen, or shipping anomalies are spotted. Each rule supports 30+ condition fields and actions like block customer, hold order, send email, fire webhook, allowlist customer, cancel order, or tag customer.

Pro automation also includes a save-time validator that blocks rules that can never fire, an inline inspector that shows exactly why each rule fired or didn’t, and async HMAC-SHA256-signed webhooks with automatic retry.

What happens when I block a customer?

Blocked customers see a customizable message when they try to add items to their cart or proceed to checkout. The block applies to both logged-in users and guest checkouts matching the blocked email. All blocked checkout attempts are logged.

Can I undo a block?

Yes. You can unblock a customer at any time from their profile page or the customer list. You can also add customers to the allowlist, which locks their score at 100 and prevents any negative signals from affecting them.

What happens right after I install TrustLens?

New WooCommerce orders are analyzed automatically after activation. If you already have historical orders, you can run Historical Sync from the dashboard to build trust profiles from your existing store data without slowing down the frontend.

Does this slow down my store?

No. Score calculations run asynchronously via Action Scheduler (the same system WooCommerce uses). Checkout blocking uses a lightweight email-hash lookup. The historical sync processes orders in small batches in the background.

Does TrustLens send customer data to an external service?

No customer personal data ever leaves your site. TrustLens works inside your WordPress and WooCommerce installation. The only default external call is the optional Pro report-verification feature, which (while enabled) sends a non-personal, one-way fingerprint of a dispute report to the TrustLens verification service so issuers can confirm it is genuine — never customer data, and it can be disabled. All other external delivery (webhooks, email notifications) happens only if you configure it.

Is TrustLens compatible with WooCommerce HPOS?

Yes. TrustLens declares full compatibility with High-Performance Order Storage and works with both legacy and HPOS-enabled stores.

Does TrustLens store personal data?

TrustLens stores customer email addresses and behavioral data (order counts, refund counts, trust scores) in custom database tables. Matching identifiers used for linked-account detection are pseudonymized using keyed HMAC-SHA256 hashes, preventing the raw values from being exposed or reused across sites. The plugin integrates with WordPress privacy tools — customers can request data export or erasure through the standard WordPress privacy workflow.

Can I access TrustLens data from external systems?

Yes. TrustLens includes a REST API with 8 endpoints for looking up customers, retrieving scores, filtering by segment, and triggering recalculations. API access requires either the manage_woocommerce capability or a valid API key configured in settings.

Can I get alerts and reports by email?

Yes. The free version includes core email notifications such as blocked checkout alerts, a welcome summary, and a weekly summary. Pro adds advanced alerts, daily digests, monthly revenue protection reports, and scheduled email reports.

What is the minimum data needed for accurate scoring?

By default, customers need at least 3 orders before they move out of the Normal segment. You can adjust this threshold in Settings > General. Customers below the threshold still accumulate signals — they just aren’t classified until enough data exists.

Does the free version include all detection modules?

Yes. All 8 detection modules ship in the free version — returns, orders, coupons, categories, linked accounts, shipping address anomalies, chargebacks, and card-testing defense. There are no trial limits, no disabled scoring, and no locked modules.

Pro adds automation rules, webhooks, scheduled reports, payment-method risk controls, the advanced per-brand Chargeback Monitor with daily alerts, Card-Testing Defense Pro (auto-escalation + analytics + Slack alerts), and 10 advanced notification types.

What happens if I rotate my WordPress secret keys?

Important: TrustLens uses your WordPress auth secret key (via wp_salt('auth')) as the HMAC keying material for hashing customer emails and linked-account fingerprints. This is a deliberate security choice — it makes stored hashes non-reversible and non-portable across sites.

The trade-off is that regenerating your WordPress secret keys (whether through a security plugin’s “regenerate keys” tool or by editing wp-config.php directly) will permanently invalidate every customer hash and fingerprint already stored in your TrustLens tables. After rotation, the plugin won’t be able to match a returning customer to their existing trust profile, and linked-account detection will reset.

If you ever need to rotate WordPress secret keys, plan to run Historical Sync afterward so TrustLens rebuilds the customer table from your existing WooCommerce order data using the new keying material. Allowlisted/blocked status set manually on individual customer rows is the exception that won’t auto-recover — re-apply those after the sync.

Plugin details
Version1.3.9
Last updated2026-07-11 12:13am GMT
Added2026-02-13
Requires WordPress6.4
Tested up to7.0.2
Requires PHP7.4

Tags on WordPress.org
anti-fraud
card-testing
chargeback
fake orders
woocommerce security
x402 Logo

The agent-readiness stack for the AI shopping era — helping merchants, publishers and SaaS companies get discovered, cited and transacted with by ChatGPT, Perplexity, Claude, Gemini and the custom shopping agents underneath them.

CompanyAgentically Inc. (d/b/a xpay✦)1875 Mission St, Ste 103San Francisco, CA 94103, United Stateslegal@xpay.sh · privacy@xpay.sh
or ask your AI app
Company
About xpayAgency PartnersGitHubDiscordllms.txt
DevelopersDocumentationAPI ReferenceSDKs & LibrariesQuickstart GuideOpenAPI Spec
Stay Updated
Occasional product updates and agent-readiness playbooks from xpay (Agentically Inc.) — typically a couple of emails a month. Double opt-in: we email you a link to confirm before sending anything, and every email has one-click unsubscribe.
Social
  • For Publishers
    • News
    • Finance
    • Dev / Tech
    • Travel
    • View all verticals
  • Agent Feed
    • AI Search Engines
    • RAG Builders
    • Browser Agents
    • Vertical Research
    • Browse full catalog
  • Agent-Ready Index
    • SaaS Pricing Database
    • Agent-Ready SaaS Index
    • Verified band
    • AI & ML
    • Sales & CRM
  • Products
    • Pricing Widget
    • Monetize MCP Server
    • Paywall
    • Smart Proxy
    • Monetize AI Agents
    • xpay x402 Facilitator
  • Agentic Economy
    • Timeline
    • Resources
    • Manifesto
    • Stack
  • Agentic Commerce
    • Get listed
    • ChatGPT Ads
    • How ChatGPT Ads work
    • ChatGPT Ads · Apparel
    • ChatGPT Ads · Health & Beauty
    • xpay Listings · Amazon + Google
    • Pricing
    • Free audit
    • Shopify
    • WooCommerce
    • Apparel & Accessories
    • Health & Beauty
    • Overview
  • Commerce Index
    • Shopify apps directory
    • Agentic Commerce Ready Index
    • Methodology
    • Pet brands · WooCommerce
    • Pet brands · Shopify
  • Marketplace
    • 🛍️ xpay.deals — agentic storefront for deals
  • Protocols
    • Overview
    • x402
    • MPP
    • UCP
    • ACP
    • AP2
    • TAP
    • A2A
  • Agent Frameworks
    • Overview
    • LangChain
    • CrewAI
    • Claude MCP
    • AutoGPT
    • LangChain vs Mastra
    • LangGraph vs Pydantic AI
  • Company
    • About xpay
    • Blog
    • Docs
    • GitHub
  • Free prompts
    • Ecommerce prompts
    • Email marketing prompts
    • Product description prompts
    • Facebook ad prompts
    • Skincare prompts
    • Supplement prompts
    • Wine prompts
    • Electronics prompts

© 2025 Agentically Inc. All rights reserved.
Privacy PolicyTerms of UseAcceptable Use Policy