Skip to navigation Skip to main content

Free Grow sales & stop fraud — Smart Cycle Discounts + TrustLens, free on WordPress.org Two free WooCommerce plugins

Explore both

Free Grow sales & stop fraud — Smart Cycle Discounts + TrustLens, free on WordPress.org Two free WooCommerce plugins

Explore both
  • WordPress
    WordPress Plugins
    View all
    Smart Cycle Discounts logo

    Smart Cycle Discounts

    Automate discount campaigns with scheduling, analytics, and smart product targeting.

    7 Discount Types Cycle AI
    Free Pro from $59
    TrustLens logo

    TrustLens

    Customer trust intelligence for WooCommerce. Score customers, spot abuse, protect revenue.

    Trust Scores Abuse Detection
    Free Pro from $79

    New Plugin

    Coming Soon

    Something exciting is in the works. Join the waitlist to be first to know.

    Get Notified
    Notify Me
    Secure Checkout
    WordPress.org
    14-Day Refund
    Resources
    Documentation Guides & tutorials
    Discount Calculator Plan your strategy
    Support Get help
    SCD Changelog Discount plugin updates
    TrustLens Changelog Trust intelligence updates
    Get notified on new releases
  • Affiliate
    Program
    Overview How the program works
    How It Works 4 steps from apply to earn
    Commission Details 30% · 60-day cookie · recurring
    Get Started
    Apply Now Open
    Takes ~2 minutes
    Earnings Calculator Estimate your monthly income
    FAQ Payouts, cookies, renewals
    Resources
    Brand Kit Logos, banners, copy, social
    Playbook Tactics that actually convert
    FTC Disclosure How to disclose properly
    Affiliate Terms Full program agreement
    Contact Team Open the contact form
    Earn 30% recurring on every sale Free to join · 60-day cookie · monthly PayPal payouts
    Apply Now
  • Blog
  • DOCS
    Docs & Resources

    Guides, references, and answers for every Webstepper plugin.

    Smart Cycle Discounts Automated WooCommerce discount campaigns
    Getting started › Discount types › Cycle AI ›
    TrustLens Customer trust & fraud intelligence
    Trust scoring › Detection modules › Card-testing defense ›
    Docs Home Guides FAQ Pricing Support
    WordPress tools that solve real problems
  • Contact Us
  • About
    Company

    Our Story

    Founded 2020

    Built by store owners, for store owners. We create WordPress tools that solve real problems.

    Learn more
    Built from Experience Real solutions we use ourselves
    Time is Precious Simple, intuitive tools
    Real Support Talk to the founders
    Legal & Contact
    Contact Us Privacy Policy Terms of Service Refund Policy
    14-Day Money-Back Guarantee No questions asked
Popular requests
  • smart cycle discounts
  • trustlens
  • chargeback protection
GET STARTED

Glossary

1
  • TrustLens Glossary

Detection Modules

9
  • Card Testing Defense
  • Chargeback Tracking
  • Shipping Anomalies
  • Linked Accounts Detection
  • Category Aware Risk
  • Coupon Abuse Detection
  • Order Pattern Analysis
  • Return Abuse Detection
  • Modules Overview

Card Testing Defense

9
  • Attack History
  • Allowlists
  • Geo Diversity
  • Auto Escalation
  • Fingerprinting
  • VIP Bypass
  • Panic Button
  • Velocity Thresholds
  • Overview

Chargeback Monitor

7
  • Ratio Email Alerts
  • Dispute Evidence Report
  • Chargeback Monitor
  • Manual Dispute Entry
  • Stripe WooPayments Ingestion
  • Card Network Thresholds
  • Chargeback Ratio Speedometer

Customer Management

7
  • Admin Notes
  • Checkout Enforcement
  • Order Trust Column
  • Bulk Actions
  • Blocking and Allowlisting
  • Customer Detail Profile
  • Customer List

Automation

7
  • Async Dispatch Retries
  • Webhooks and HMAC
  • Rule Inspector
  • Actions Reference
  • Conditions Reference
  • Triggers Reference
  • Automation Overview

Trust Scoring

5
  • Account Age Loyalty Bonus
  • Signals Explained
  • Six Customer Segments
  • The 0–100 Score
  • How Trust Scoring Works
View Categories
  • Home
  • Docs
  • Trustlens
  • Card Testing Defense
  • VIP Bypass

VIP Bypass

4 min read

VIP Customer Bypass is the setting that prevents your top customers from being caught by Card-Testing Defense velocity rules. It’s on by default. This page explains how the bypass identifies VIPs, when it applies, and when (rarely) you might want to turn it off.


How VIPs Are Identified #

The bypass identifies a customer as VIP at checkout time using two paths:

  1. Logged-in user: If the customer is logged in to a WooCommerce account, TrustLens looks up the user’s email hash in the customer table. If the customer’s segment is VIP, bypass applies.
  2. Guest checkout with VIP email: If the billing email matches a known VIP customer record (including allowlisted customers, who are locked at VIP), bypass applies even without a login.

Both checks happen before velocity counters are read or incremented.


What Bypass Does #

When a VIP is identified at checkout:

  • The velocity counters are not read for their fingerprint
  • The lockout flag is not checked
  • The Panic Freeze block is skipped (unless explicitly disabled)
  • Their checkout proceeds normally regardless of any rules that would otherwise block them

The bypass is comprehensive — it short-circuits the entire Card-Testing Defense layer for that request. The customer’s checkout experience is identical to having no defense in place.


Why Bypass Exists #

The bypass solves a specific class of false positive: legitimate VIPs producing high checkout velocity for innocent reasons. Common scenarios:

  • VIP placing several orders in quick succession (gift-giving, bulk restocking)
  • VIP using a corporate card that requires multiple validation attempts
  • VIP testing payment options across multiple cards
  • VIP returning after a typo’d email or expired session and retrying checkout

Without the bypass, any of these could trip the velocity threshold and produce a lockout error message on a customer who is, by definition, the kind of customer you want to keep.


When to Turn Bypass Off #

Bypass is a tradeoff between false-positive prevention and defense coverage. Turn it off if:

  • You suspect a VIP fingerprint has been compromised. If an attacker has somehow stolen a VIP’s session or fingerprint, bypass would let them through.
  • You’ve allowlisted very broadly. If your VIP segment includes many customers (e.g. you’ve allowlisted hundreds), the bypass exposes a larger surface than it protects.
  • You’re under active attack and uncertain about VIP integrity. Temporarily disable bypass during the incident.

For most stores, the default of “on” is the right choice. The bypass is most valuable when you have meaningful VIP populations and active velocity protection.


Bypass vs Allowlist #

These are different concepts that work together:

Mechanism Effect
Allowlist (per customer) Locks customer score at 100, marks as VIP, prevents all negative signals
VIP Bypass (system-wide) Skips Card-Testing Defense velocity rules for customers in the VIP segment

Allowlisting puts a customer into VIP; the bypass then skips them through Card-Testing rules. Disabling bypass doesn’t affect their allowlist status — they’re still segment-VIP, just subject to velocity rules.


Configuration #

Settings: TrustLens → Settings → Modules → Card Testing.

Setting Default Description
VIP customer bypass On Skip velocity checks for VIP segment customers

Changes take effect immediately on the next checkout request.


Bypass and Panic Freeze #

By default, VIP bypass applies even during a Panic Freeze — meaning your VIPs can still complete checkout even when the store is otherwise frozen. This is intentional: the most valuable customers should not be punished for an attack they’re not part of.

If you want a Panic Freeze to halt all checkouts including VIPs (e.g. you suspect VIP fingerprints are compromised), turn bypass off before activating the freeze.


How to Verify Bypass Is Working #

Quick sanity check:

  1. Identify a VIP customer (or allowlist a test account)
  2. Have them attempt a few checkouts in quick succession with a card that intentionally declines (e.g. a card with insufficient funds)
  3. Confirm they’re not locked out after the 5th attempt
  4. For comparison, repeat with a non-VIP fingerprint — confirm lockout triggers

This is also useful regression testing if you’ve customized the customer-identification logic via filters.


Reading Bypass Activity #

The Pro Attack History tab shows bypass events in the event log:

  • How many checkout attempts went through bypass
  • Which VIPs triggered it
  • Whether any VIP fingerprints would have been locked without bypass

If the last item is non-zero — meaning bypass is consistently saving VIPs from lockouts — your VIPs are producing velocity above the threshold, and you should consider whether they need allowlisting or if there’s an underlying issue.

Updated on June 4, 2026

What are your Feelings

  • Happy
  • Normal
  • Sad

Share This Article :

  • Facebook
  • X
  • LinkedIn
  • Pinterest
FingerprintingPanic Button
Table of Contents
  • How VIPs Are Identified
  • What Bypass Does
  • Why Bypass Exists
  • When to Turn Bypass Off
  • Bypass vs Allowlist
  • Configuration
  • Bypass and Panic Freeze
  • How to Verify Bypass Is Working
  • Reading Bypass Activity
Newsletter

Insights that grow your business

Join thousands of WooCommerce store owners who get actionable tips, plugin updates, and industry news every week.

We respect your privacy. Unsubscribe at any time.

Weekly updates — Fresh content every Tuesday
Exclusive content — Tips you won't find on our blog
Early access — Be first to know about new plugins
Webstepper
Weekly WooCommerce Tips
Just now
This week: 5 proven strategies to boost your average order value using smart discount campaigns...
New issue!
Webstepper

Tools for store owners who'd rather grow than grind.

Simple, powerful plugins that help WooCommerce store owners sell more — without the learning curve.

500+ happy stores

Products

  • Smart Cycle Discounts
  • TrustLens
  • Discount Calculator
  • Sale Calendar

Company

  • About Us
  • Blog
  • Contact
  • Affiliates

Resources

  • Help Center
  • Guides
  • Affiliate Program
  • Become a Partner

Questions? We actually answer.

Real humans, real help. No bots, no runaround. Usually within a few hours.

Get in touch
Operated by Setmood LLC · 7901 4th St N, St Petersburg, FL 33702 · United States

© 2026 Webstepper. All rights reserved.

Privacy Terms Refunds
Visa Mastercard PayPal Apple Pay Google Pay & more
Limited Time Offer

Save 15% on
SCD, TrustLens & the Bundle

Smart Cycle Discounts and TrustLens — buy either plugin or grab both in the bundle. Use code at checkout.

WELCOME15
23 hours
:
59 minutes
:
59 seconds
Claim My Discount

Just want one? Smart Cycle Discounts · TrustLens

  • WordPress
    Back
    WordPress Plugins
    View all
    Smart Cycle Discounts logo

    Smart Cycle Discounts

    Automate discount campaigns with scheduling, analytics, and smart product targeting.

    7 Discount Types Cycle AI
    Free Pro from $59
    TrustLens logo

    TrustLens

    Customer trust intelligence for WooCommerce. Score customers, spot abuse, protect revenue.

    Trust Scores Abuse Detection
    Free Pro from $79

    New Plugin

    Coming Soon

    Something exciting is in the works. Join the waitlist to be first to know.

    Get Notified
    Notify Me
    Secure Checkout
    WordPress.org
    14-Day Refund
    Resources
    Documentation Guides & tutorials
    Discount Calculator Plan your strategy
    Support Get help
    SCD Changelog Discount plugin updates
    TrustLens Changelog Trust intelligence updates
    Get notified on new releases
  • Affiliate
    Back
    Program
    Overview How the program works
    How It Works 4 steps from apply to earn
    Commission Details 30% · 60-day cookie · recurring
    Get Started
    Apply Now Open
    Takes ~2 minutes
    Earnings Calculator Estimate your monthly income
    FAQ Payouts, cookies, renewals
    Resources
    Brand Kit Logos, banners, copy, social
    Playbook Tactics that actually convert
    FTC Disclosure How to disclose properly
    Affiliate Terms Full program agreement
    Contact Team Open the contact form
    Earn 30% recurring on every sale Free to join · 60-day cookie · monthly PayPal payouts
    Apply Now
  • Blog
  • DOCS
    Back
    Docs & Resources

    Guides, references, and answers for every Webstepper plugin.

    Smart Cycle Discounts Automated WooCommerce discount campaigns
    Getting started › Discount types › Cycle AI ›
    TrustLens Customer trust & fraud intelligence
    Trust scoring › Detection modules › Card-testing defense ›
    Docs Home Guides FAQ Pricing Support
    WordPress tools that solve real problems
  • Contact Us
  • About
    Back
    Company

    Our Story

    Founded 2020

    Built by store owners, for store owners. We create WordPress tools that solve real problems.

    Learn more
    Built from Experience Real solutions we use ourselves
    Time is Precious Simple, intuitive tools
    Real Support Talk to the founders
    Legal & Contact
    Contact Us Privacy Policy Terms of Service Refund Policy
    14-Day Money-Back Guarantee No questions asked
We use cookies to improve your experience on our website. By browsing this website, you agree to our use of cookies.
More info More info Accept