Skip to navigation Skip to main content

Free Grow sales & stop fraud — Smart Cycle Discounts + TrustLens, free on WordPress.org Two free WooCommerce plugins

Explore both

Free Grow sales & stop fraud — Smart Cycle Discounts + TrustLens, free on WordPress.org Two free WooCommerce plugins

Explore both
  • WordPress
    WordPress Plugins
    View all
    Smart Cycle Discounts logo

    Smart Cycle Discounts

    Automate discount campaigns with scheduling, analytics, and smart product targeting.

    7 Discount Types Cycle AI
    Free Pro from $59
    TrustLens logo

    TrustLens

    Customer trust intelligence for WooCommerce. Score customers, spot abuse, protect revenue.

    Trust Scores Abuse Detection
    Free Pro from $79

    New Plugin

    Coming Soon

    Something exciting is in the works. Join the waitlist to be first to know.

    Get Notified
    Notify Me
    Secure Checkout
    WordPress.org
    14-Day Refund
    Resources
    Documentation Guides & tutorials
    Discount Calculator Plan your strategy
    Support Get help
    SCD Changelog Discount plugin updates
    TrustLens Changelog Trust intelligence updates
    Get notified on new releases
  • Affiliate
    Program
    Overview How the program works
    How It Works 4 steps from apply to earn
    Commission Details 30% · 60-day cookie · recurring
    Get Started
    Apply Now Open
    Takes ~2 minutes
    Earnings Calculator Estimate your monthly income
    FAQ Payouts, cookies, renewals
    Resources
    Brand Kit Logos, banners, copy, social
    Playbook Tactics that actually convert
    FTC Disclosure How to disclose properly
    Affiliate Terms Full program agreement
    Contact Team Open the contact form
    Earn 30% recurring on every sale Free to join · 60-day cookie · monthly PayPal payouts
    Apply Now
  • Blog
  • DOCS
    Docs & Resources

    Guides, references, and answers for every Webstepper plugin.

    Smart Cycle Discounts Automated WooCommerce discount campaigns
    Getting started › Discount types › Cycle AI ›
    TrustLens Customer trust & fraud intelligence
    Trust scoring › Detection modules › Card-testing defense ›
    Docs Home Guides FAQ Pricing Support
    WordPress tools that solve real problems
  • Contact Us
  • About
    Company

    Our Story

    Founded 2020

    Built by store owners, for store owners. We create WordPress tools that solve real problems.

    Learn more
    Built from Experience Real solutions we use ourselves
    Time is Precious Simple, intuitive tools
    Real Support Talk to the founders
    Legal & Contact
    Contact Us Privacy Policy Terms of Service Refund Policy
    14-Day Money-Back Guarantee No questions asked
Popular requests
  • smart cycle discounts
  • trustlens
  • chargeback protection
GET STARTED

Glossary

1
  • TrustLens Glossary

Detection Modules

9
  • Card Testing Defense
  • Chargeback Tracking
  • Shipping Anomalies
  • Linked Accounts Detection
  • Category Aware Risk
  • Coupon Abuse Detection
  • Order Pattern Analysis
  • Return Abuse Detection
  • Modules Overview

Card Testing Defense

9
  • Attack History
  • Allowlists
  • Geo Diversity
  • Auto Escalation
  • Fingerprinting
  • VIP Bypass
  • Panic Button
  • Velocity Thresholds
  • Overview

Chargeback Monitor

7
  • Ratio Email Alerts
  • Dispute Evidence Report
  • Chargeback Monitor
  • Manual Dispute Entry
  • Stripe WooPayments Ingestion
  • Card Network Thresholds
  • Chargeback Ratio Speedometer

Customer Management

7
  • Admin Notes
  • Checkout Enforcement
  • Order Trust Column
  • Bulk Actions
  • Blocking and Allowlisting
  • Customer Detail Profile
  • Customer List

Automation

7
  • Async Dispatch Retries
  • Webhooks and HMAC
  • Rule Inspector
  • Actions Reference
  • Conditions Reference
  • Triggers Reference
  • Automation Overview

Trust Scoring

5
  • Account Age Loyalty Bonus
  • Signals Explained
  • Six Customer Segments
  • The 0–100 Score
  • How Trust Scoring Works
View Categories
  • Home
  • Docs
  • Trustlens
  • Card Testing Defense
  • Allowlists

Allowlists

4 min read

Pro adds explicit allowlists for Card-Testing Defense — surfaces for telling TrustLens “this fingerprint or this IP range is known-good, don’t apply velocity rules to it.” Allowlists complement the VIP customer bypass: VIP bypass is automatic per-customer, while allowlists are explicit per-device or per-network. This page covers both fingerprint allowlists and IP CIDR allowlists, including per-fingerprint threshold overrides.


Why Allowlists Exist #

Some traffic legitimately produces high velocity that velocity rules would otherwise treat as attack:

  • QA testing. Your team runs automated checkout tests with various card scenarios. Each run hammers velocity counters.
  • Integration partners. Marketplaces, ERP systems, or order-import tools that make many sequential requests.
  • Internal tools. Subscription renewals, admin-side order creation, custom scripts.
  • Known-good monitoring traffic. Uptime checkers, synthetic transaction monitors.

Without allowlists, you’d have to either tune velocity thresholds high enough to never catch these (which weakens defense against real attacks), or accept that these legitimate use cases get periodically locked out.


Fingerprint Allowlist #

Located at TrustLens → Card Testing → Allowlists → Fingerprints. Stores explicit fingerprint hashes that should bypass velocity rules entirely.

Adding a Fingerprint #

  1. Find the fingerprint hash in the Card Testing event log or Attack History tab (top-attacking fingerprints often turn out to be legitimate QA bots)
  2. Copy the hash
  3. Open the allowlist UI and click “Add Fingerprint”
  4. Paste the hash, add an optional label (e.g. “QA bot — automated tests”), and save

Behavior #

  • Allowlisted fingerprints skip velocity checks
  • They’re not subject to per-fingerprint lockouts
  • They’re still recorded in the event log for auditing
  • They do contribute to the auto-escalation distinct-fingerprint count? — No. Allowlisted fingerprints are excluded from auto-escalation counters.

Limits #

No hard limit on number of fingerprints. Each entry is one row in a database table — performance is fine into the thousands. Keep the list reviewed; orphaned QA fingerprints from years ago should be removed periodically.


IP CIDR Allowlist #

Located at TrustLens → Card Testing → Allowlists → IP Ranges. Stores IPv4 and IPv6 CIDR ranges that should bypass velocity rules.

Format #

Example Meaning
192.0.2.42/32 Single IPv4 address
192.0.2.0/24 IPv4 range of 256 addresses
10.0.0.0/8 Large private IPv4 range
2001:db8::/32 IPv6 range
2001:db8::1/128 Single IPv6 address

Common Use Cases #

  • Office IP ranges where QA and dev work happens
  • CI/CD runners that test checkout
  • Integration partner static IP ranges
  • Internal admin IPs for testing

What Not to Add #

  • Cloudflare / Cloudfront / proxy IPs. Allowlisting your CDN’s IPs allowlists effectively all traffic, defeating the defense. If you’re behind a proxy, configure TrustLens to use the forwarded client IP instead.
  • Mobile carrier IPs. Way too broad — would allowlist millions of customers and attackers.
  • Country-wide CIDRs. Same issue, too broad.

Per-Fingerprint Threshold Overrides #

For fingerprints that need different thresholds rather than full bypass, Pro adds per-fingerprint overrides. Located in the same allowlists UI.

Override Example Use
Tighter than default A specific device you trust less; force 2 declines / 60s
Looser than default An integration partner; raise to 20 declines / 60s without full bypass

Overrides preserve the velocity tracking — you still see counts and events — but with custom thresholds. This is useful when full bypass is too permissive but you need tolerance for a specific device.


How Allowlists Are Evaluated #

At the Request Gate, the evaluation order for Card-Testing checks:

  1. VIP customer bypass (if enabled and customer is VIP) — skip all checks
  2. IP CIDR allowlist — skip velocity checks
  3. Fingerprint allowlist — skip velocity checks
  4. Per-fingerprint override — apply custom thresholds
  5. Standard velocity rules — apply defaults

The first match wins. A customer who is both VIP and on the IP allowlist gets bypassed via the VIP path; the IP allowlist isn’t consulted.


Audit Trail #

Every allowlist match is recorded in the event log with the allowlist source (IP / fingerprint / override) and the entry label. This makes it easy to audit:

  • Whether allowlists are being hit (validating they’re configured correctly)
  • Whether allowlists are being abused (a once-legitimate fingerprint now showing attack patterns)
  • Operational health of integration partners

Removing Entries #

Entries can be removed at any time. When removed, the next request from that fingerprint or IP is subject to normal velocity rules. Existing velocity counters for the fingerprint aren’t reset — if a partner had been hammering counters under bypass, removing the allowlist may produce an immediate lockout.


Allowlist vs Block List #

TrustLens’s allowlists are for known-good entities. Block lists (the inverse — explicit “always block this” entries) are not a built-in feature; the blocking surface for customers operates at the customer level, not at fingerprint or IP level. If you need IP-level blocking, do it at the web server / firewall layer above WordPress.


Security of the Allowlist UI #

Modifying allowlists requires the manage_woocommerce capability. All UI submissions are nonce-protected and capability-checked. Allowlist changes are logged in the WordPress action log for audit purposes.

Updated on June 4, 2026

What are your Feelings

  • Happy
  • Normal
  • Sad

Share This Article :

  • Facebook
  • X
  • LinkedIn
  • Pinterest
Attack HistoryGeo Diversity
Table of Contents
  • Why Allowlists Exist
  • Fingerprint Allowlist
    • Adding a Fingerprint
    • Behavior
    • Limits
  • IP CIDR Allowlist
    • Format
    • Common Use Cases
    • What Not to Add
  • Per-Fingerprint Threshold Overrides
  • How Allowlists Are Evaluated
  • Audit Trail
  • Removing Entries
  • Allowlist vs Block List
  • Security of the Allowlist UI
Newsletter

Insights that grow your business

Join thousands of WooCommerce store owners who get actionable tips, plugin updates, and industry news every week.

We respect your privacy. Unsubscribe at any time.

Weekly updates — Fresh content every Tuesday
Exclusive content — Tips you won't find on our blog
Early access — Be first to know about new plugins
Webstepper
Weekly WooCommerce Tips
Just now
This week: 5 proven strategies to boost your average order value using smart discount campaigns...
New issue!
Webstepper

Tools for store owners who'd rather grow than grind.

Simple, powerful plugins that help WooCommerce store owners sell more — without the learning curve.

500+ happy stores

Products

  • Smart Cycle Discounts
  • TrustLens
  • Discount Calculator
  • Sale Calendar

Company

  • About Us
  • Blog
  • Contact
  • Affiliates

Resources

  • Help Center
  • Guides
  • Affiliate Program
  • Become a Partner

Questions? We actually answer.

Real humans, real help. No bots, no runaround. Usually within a few hours.

Get in touch
Operated by Setmood LLC · 7901 4th St N, St Petersburg, FL 33702 · United States

© 2026 Webstepper. All rights reserved.

Privacy Terms Refunds
Visa Mastercard PayPal Apple Pay Google Pay & more
Limited Time Offer

Save 15% on
SCD, TrustLens & the Bundle

Smart Cycle Discounts and TrustLens — buy either plugin or grab both in the bundle. Use code at checkout.

WELCOME15
23 hours
:
59 minutes
:
59 seconds
Claim My Discount

Just want one? Smart Cycle Discounts · TrustLens

  • WordPress
    Back
    WordPress Plugins
    View all
    Smart Cycle Discounts logo

    Smart Cycle Discounts

    Automate discount campaigns with scheduling, analytics, and smart product targeting.

    7 Discount Types Cycle AI
    Free Pro from $59
    TrustLens logo

    TrustLens

    Customer trust intelligence for WooCommerce. Score customers, spot abuse, protect revenue.

    Trust Scores Abuse Detection
    Free Pro from $79

    New Plugin

    Coming Soon

    Something exciting is in the works. Join the waitlist to be first to know.

    Get Notified
    Notify Me
    Secure Checkout
    WordPress.org
    14-Day Refund
    Resources
    Documentation Guides & tutorials
    Discount Calculator Plan your strategy
    Support Get help
    SCD Changelog Discount plugin updates
    TrustLens Changelog Trust intelligence updates
    Get notified on new releases
  • Affiliate
    Back
    Program
    Overview How the program works
    How It Works 4 steps from apply to earn
    Commission Details 30% · 60-day cookie · recurring
    Get Started
    Apply Now Open
    Takes ~2 minutes
    Earnings Calculator Estimate your monthly income
    FAQ Payouts, cookies, renewals
    Resources
    Brand Kit Logos, banners, copy, social
    Playbook Tactics that actually convert
    FTC Disclosure How to disclose properly
    Affiliate Terms Full program agreement
    Contact Team Open the contact form
    Earn 30% recurring on every sale Free to join · 60-day cookie · monthly PayPal payouts
    Apply Now
  • Blog
  • DOCS
    Back
    Docs & Resources

    Guides, references, and answers for every Webstepper plugin.

    Smart Cycle Discounts Automated WooCommerce discount campaigns
    Getting started › Discount types › Cycle AI ›
    TrustLens Customer trust & fraud intelligence
    Trust scoring › Detection modules › Card-testing defense ›
    Docs Home Guides FAQ Pricing Support
    WordPress tools that solve real problems
  • Contact Us
  • About
    Back
    Company

    Our Story

    Founded 2020

    Built by store owners, for store owners. We create WordPress tools that solve real problems.

    Learn more
    Built from Experience Real solutions we use ourselves
    Time is Precious Simple, intuitive tools
    Real Support Talk to the founders
    Legal & Contact
    Contact Us Privacy Policy Terms of Service Refund Policy
    14-Day Money-Back Guarantee No questions asked
We use cookies to improve your experience on our website. By browsing this website, you agree to our use of cookies.
More info More info Accept