Skip to navigation Skip to main content

Free Grow sales & stop fraud — Smart Cycle Discounts + TrustLens, free on WordPress.org Two free WooCommerce plugins

Explore both

Free Grow sales & stop fraud — Smart Cycle Discounts + TrustLens, free on WordPress.org Two free WooCommerce plugins

Explore both
  • WordPress
    WordPress Plugins
    View all
    Smart Cycle Discounts logo

    Smart Cycle Discounts

    Automate discount campaigns with scheduling, analytics, and smart product targeting.

    7 Discount Types Cycle AI
    Free Pro from $59
    TrustLens logo

    TrustLens

    Customer trust intelligence for WooCommerce. Score customers, spot abuse, protect revenue.

    Trust Scores Abuse Detection
    Free Pro from $79

    New Plugin

    Coming Soon

    Something exciting is in the works. Join the waitlist to be first to know.

    Get Notified
    Notify Me
    Secure Checkout
    WordPress.org
    14-Day Refund
    Resources
    Documentation Guides & tutorials
    Discount Calculator Plan your strategy
    Support Get help
    SCD Changelog Discount plugin updates
    TrustLens Changelog Trust intelligence updates
    Get notified on new releases
  • Affiliate
    Program
    Overview How the program works
    How It Works 4 steps from apply to earn
    Commission Details 30% · 60-day cookie · recurring
    Get Started
    Apply Now Open
    Takes ~2 minutes
    Earnings Calculator Estimate your monthly income
    FAQ Payouts, cookies, renewals
    Resources
    Brand Kit Logos, banners, copy, social
    Playbook Tactics that actually convert
    FTC Disclosure How to disclose properly
    Affiliate Terms Full program agreement
    Contact Team Open the contact form
    Earn 30% recurring on every sale Free to join · 60-day cookie · monthly PayPal payouts
    Apply Now
  • Blog
  • DOCS
    Docs & Resources

    Guides, references, and answers for every Webstepper plugin.

    Smart Cycle Discounts Automated WooCommerce discount campaigns
    Getting started › Discount types › Cycle AI ›
    TrustLens Customer trust & fraud intelligence
    Trust scoring › Detection modules › Card-testing defense ›
    Docs Home Guides FAQ Pricing Support
    WordPress tools that solve real problems
  • Contact Us
  • About
    Company

    Our Story

    Founded 2020

    Built by store owners, for store owners. We create WordPress tools that solve real problems.

    Learn more
    Built from Experience Real solutions we use ourselves
    Time is Precious Simple, intuitive tools
    Real Support Talk to the founders
    Legal & Contact
    Contact Us Privacy Policy Terms of Service Refund Policy
    14-Day Money-Back Guarantee No questions asked
Popular requests
  • smart cycle discounts
  • trustlens
  • chargeback protection
GET STARTED

Glossary

1
  • TrustLens Glossary

Detection Modules

9
  • Card Testing Defense
  • Chargeback Tracking
  • Shipping Anomalies
  • Linked Accounts Detection
  • Category Aware Risk
  • Coupon Abuse Detection
  • Order Pattern Analysis
  • Return Abuse Detection
  • Modules Overview

Card Testing Defense

9
  • Attack History
  • Allowlists
  • Geo Diversity
  • Auto Escalation
  • Fingerprinting
  • VIP Bypass
  • Panic Button
  • Velocity Thresholds
  • Overview

Chargeback Monitor

7
  • Ratio Email Alerts
  • Dispute Evidence Report
  • Chargeback Monitor
  • Manual Dispute Entry
  • Stripe WooPayments Ingestion
  • Card Network Thresholds
  • Chargeback Ratio Speedometer

Customer Management

7
  • Admin Notes
  • Checkout Enforcement
  • Order Trust Column
  • Bulk Actions
  • Blocking and Allowlisting
  • Customer Detail Profile
  • Customer List

Automation

7
  • Async Dispatch Retries
  • Webhooks and HMAC
  • Rule Inspector
  • Actions Reference
  • Conditions Reference
  • Triggers Reference
  • Automation Overview

Trust Scoring

5
  • Account Age Loyalty Bonus
  • Signals Explained
  • Six Customer Segments
  • The 0–100 Score
  • How Trust Scoring Works
View Categories
  • Home
  • Docs
  • Trustlens
  • Card Testing Defense
  • Overview

Overview

2 min read

Card-Testing Defense is TrustLens’s real-time checkout protection layer. While the other detection modules analyze customer behavior after the fact, Card-Testing Defense operates at request time — intercepting checkout attempts as they happen and blocking the fingerprints behind automated card-testing attacks before the payment gateway is ever called. This page is the orientation document for the feature; the rest of this section covers each component in detail.


What a Card-Testing Attack Looks Like #

A card-testing attack is an automated probe of stolen card data. Fraudsters with lists of credit card numbers run them through your checkout in batches — usually small dollar amounts ($1–$5) — to identify which cards are still valid. Successful tests get resold or used elsewhere. The damage to your store:

  • Gateway fees — every decline costs you
  • Conversion metrics — your decline rate skews your analytics
  • Downstream chargebacks — real cardholders dispute the test charges weeks later
  • Card-network monitoring exposure — high decline rates and disputes push you toward VDMP/VFMP/ECP thresholds

Attacks typically run for 10 minutes to several hours, generating anywhere from dozens to thousands of authorization attempts.


The Defense Architecture #

TrustLens defends in layers, each catching different attack patterns:

Layer Catches Free / Pro
Velocity detection per fingerprint Bursts and sustained attacks from a single device Free
Fingerprint lockouts Stops further attempts for 60 seconds after threshold breach Free
VIP customer bypass Prevents legitimate VIPs from being false-positived Free
Panic Freeze Manual emergency stop — halts all checkouts for 15 minutes Free
Auto-escalation Automatic Panic Freeze when attack spreads across fingerprints Pro
Geo-diversity safeguard Prevents auto-escalation on legitimate viral / flash-sale traffic Pro
Fingerprint / IP allowlists Excludes QA, integration partners, known-good traffic Pro
Advanced fingerprint (12-font) Harder to spoof across botnet nodes Pro
Attack History tab Forensic data after an attack Pro
Slack + email alerts Notification on attack_detected / auto_escalated / panic_button_activated Pro

What’s Enabled Out of the Box #

Card-Testing Defense ships enabled with sensible defaults:

  • 60-second decline threshold: 3 declines per fingerprint
  • 60-second submission threshold: 10 submissions per fingerprint
  • Lockout duration: 60 seconds
  • VIP customer bypass: on

No setup is required to start protecting checkout. From activation onward, every authorization attempt passes through the velocity check.


The Request Gate #

Card-Testing Defense plugs into TrustLens’s unified Request Gate — a single rule-registration surface that intercepts both Classic and Blocks / Store API checkout. The gate runs:

  1. Pre-checkout: fingerprint capture, velocity check, lockout check, Panic Freeze check, blocked-customer check
  2. If any rule rejects: returns a generic error before the payment gateway is called
  3. If all rules pass: request proceeds to the gateway as normal

The gate’s design means a single code path handles all checkout enforcement — blocked customers and card-testing lockouts use the same mechanism, and adding rules (custom or future) is a plugin-level extension point.


When to Read Each Detail Page #

Read This Page If You Want To
Velocity Thresholds Understand or tune the 60s / 10m thresholds
Panic Button Know when and how to use the emergency stop
VIP Bypass Understand the false-positive prevention
Fingerprinting Know what TrustLens uses to identify devices
Auto-Escalation (Pro) Configure automated Panic Freeze triggers
Geo-Diversity Safeguard (Pro) Avoid false-escalating on legitimate viral traffic
Allowlists (Pro) Exclude QA, partners, known devices
Attack History (Pro) Review forensic data after an attack

If You’re Reading This During an Active Attack #

If you’re investigating an active attack right now:

  1. Hit Panic Freeze. Go to TrustLens → Card Testing and click the red button. You have 15 minutes to investigate without further damage.
  2. Check the Card Testing page for recent decline events and top fingerprints.
  3. If you’re on Pro, the Attack History tab gives you 24-hour data and decline-code breakdown.
  4. Tune velocity thresholds down if appropriate — e.g. 3 declines / 60s if the attack is using a slow pattern.
  5. Cancel the freeze when you’re ready to resume checkout.
Updated on June 4, 2026

What are your Feelings

  • Happy
  • Normal
  • Sad

Share This Article :

  • Facebook
  • X
  • LinkedIn
  • Pinterest
Velocity ThresholdsAttack History
Table of Contents
  • What a Card-Testing Attack Looks Like
  • The Defense Architecture
  • What's Enabled Out of the Box
  • The Request Gate
  • When to Read Each Detail Page
  • If You're Reading This During an Active Attack
Newsletter

Insights that grow your business

Join thousands of WooCommerce store owners who get actionable tips, plugin updates, and industry news every week.

We respect your privacy. Unsubscribe at any time.

Weekly updates — Fresh content every Tuesday
Exclusive content — Tips you won't find on our blog
Early access — Be first to know about new plugins
Webstepper
Weekly WooCommerce Tips
Just now
This week: 5 proven strategies to boost your average order value using smart discount campaigns...
New issue!
Webstepper

Tools for store owners who'd rather grow than grind.

Simple, powerful plugins that help WooCommerce store owners sell more — without the learning curve.

500+ happy stores

Products

  • Smart Cycle Discounts
  • TrustLens
  • Discount Calculator
  • Sale Calendar

Company

  • About Us
  • Blog
  • Contact
  • Affiliates

Resources

  • Help Center
  • Guides
  • Affiliate Program
  • Become a Partner

Questions? We actually answer.

Real humans, real help. No bots, no runaround. Usually within a few hours.

Get in touch
Operated by Setmood LLC · 7901 4th St N, St Petersburg, FL 33702 · United States

© 2026 Webstepper. All rights reserved.

Privacy Terms Refunds
Visa Mastercard PayPal Apple Pay Google Pay & more
Limited Time Offer

Save 15% on
SCD, TrustLens & the Bundle

Smart Cycle Discounts and TrustLens — buy either plugin or grab both in the bundle. Use code at checkout.

WELCOME15
23 hours
:
59 minutes
:
59 seconds
Claim My Discount

Just want one? Smart Cycle Discounts · TrustLens

  • WordPress
    Back
    WordPress Plugins
    View all
    Smart Cycle Discounts logo

    Smart Cycle Discounts

    Automate discount campaigns with scheduling, analytics, and smart product targeting.

    7 Discount Types Cycle AI
    Free Pro from $59
    TrustLens logo

    TrustLens

    Customer trust intelligence for WooCommerce. Score customers, spot abuse, protect revenue.

    Trust Scores Abuse Detection
    Free Pro from $79

    New Plugin

    Coming Soon

    Something exciting is in the works. Join the waitlist to be first to know.

    Get Notified
    Notify Me
    Secure Checkout
    WordPress.org
    14-Day Refund
    Resources
    Documentation Guides & tutorials
    Discount Calculator Plan your strategy
    Support Get help
    SCD Changelog Discount plugin updates
    TrustLens Changelog Trust intelligence updates
    Get notified on new releases
  • Affiliate
    Back
    Program
    Overview How the program works
    How It Works 4 steps from apply to earn
    Commission Details 30% · 60-day cookie · recurring
    Get Started
    Apply Now Open
    Takes ~2 minutes
    Earnings Calculator Estimate your monthly income
    FAQ Payouts, cookies, renewals
    Resources
    Brand Kit Logos, banners, copy, social
    Playbook Tactics that actually convert
    FTC Disclosure How to disclose properly
    Affiliate Terms Full program agreement
    Contact Team Open the contact form
    Earn 30% recurring on every sale Free to join · 60-day cookie · monthly PayPal payouts
    Apply Now
  • Blog
  • DOCS
    Back
    Docs & Resources

    Guides, references, and answers for every Webstepper plugin.

    Smart Cycle Discounts Automated WooCommerce discount campaigns
    Getting started › Discount types › Cycle AI ›
    TrustLens Customer trust & fraud intelligence
    Trust scoring › Detection modules › Card-testing defense ›
    Docs Home Guides FAQ Pricing Support
    WordPress tools that solve real problems
  • Contact Us
  • About
    Back
    Company

    Our Story

    Founded 2020

    Built by store owners, for store owners. We create WordPress tools that solve real problems.

    Learn more
    Built from Experience Real solutions we use ourselves
    Time is Precious Simple, intuitive tools
    Real Support Talk to the founders
    Legal & Contact
    Contact Us Privacy Policy Terms of Service Refund Policy
    14-Day Money-Back Guarantee No questions asked
We use cookies to improve your experience on our website. By browsing this website, you agree to our use of cookies.
More info More info Accept