Keep checkout reassurance within what the payment setup supports
Keep a trust statement only when you can identify what it promises and evidence that the promise applies to the store’s current payment path. Compare the wording or badge with the installed integration, enabled methods, applicable technical requirements and any actual protection terms. Correct statements inherited from an old setup and remove unsupported assurances. A padlock, provider logo or working wallet does not establish comprehensive security, buyer protection, legal compliance or merchant-category approval.
For: A research-only merchant reviewing security and trust messages on the checkout it currently operates.
Inventory the text and graphics next to payment entry and the payment action, including shields, padlocks, wallet logos, provider names and linked explanations. Preserve the exact phrase and location. A decorative image can carry a claim just as text can, particularly when its label suggests a certification, guarantee or protection.
For each item, write what the visitor is being told: that a payment method is available, that a named company handles payment, that a particular control protects information or that a buyer can obtain a remedy. Those claims need different evidence. A plugin setting may support the first; it cannot, by itself, support the terms of a protection program.
The FTC’s truth-in-advertising guidance requires truthful, non-misleading and appropriately substantiated advertising across media, including the web. It does not certify any particular reassurance phrase. Use the claim inventory to locate unsupported wording rather than assuming that familiar checkout badges are acceptable wherever a theme places them.
Match the statement to the integration and payment path
Name the integration actually in use, its installed version and the page that collects payment. Record which company supplies that integration and which payment methods are enabled for the account and checkout. Use authorized settings and records without copying credentials. A theme asset naming a provider is not evidence that the provider is connected to the current payment flow.
WooCommerce’s Stripe express-checkout guide illustrates why the details matter. It requires a valid SSL certificate and sitewide HTTPS. For Apple Pay in that extension, it also names port 443, TLS 1.2 or later and an enabled domain in Stripe’s payment-method domain settings. These are technical requirements for that documented integration. Listing them here does not establish that your store meets them, and meeting them would not substantiate every security claim on the page.
The same guide documents differences between product, cart and checkout-page express paths. Additional fields described in the guide are not shown on product or cart express paths; required fields can block the payment after wallet approval. Supported field values can be saved from the checkout page. Thus, a claim that every payment path collects the same required acknowledgment needs evidence for every path actually offered. A wallet approval screen alone does not establish that the store’s required controls were completed.
The guide also describes visibility and compatibility limits and generally requires card payments to remain enabled, with a documented Link exception under the Optimized Checkout Suite. Use the observed payment path and applicable documentation when describing availability. Do not infer universal availability from a static wallet logo or use a missing wallet button as evidence that the merchant has been declined.
Separate a technical observation from a broad promise
For secure-checkout wording, specify which control the business intends the phrase to describe and which record supports it. For an encryption claim, identify the part of the flow covered and obtain evidence for that precise statement from the integration or hosting owner. A certificate or padlock does not support claims about every stored record, every connected service or the absence of all security risks. Remove absolute assurances that the available evidence cannot establish.
For provider and wallet logos, distinguish availability from endorsement. Confirm that the named method belongs to the current setup and that any accompanying wording describes its actual availability. Do not label a store as approved by a provider merely because its software can show a payment button. Account and catalog decisions remain separate from integration functionality.
For buyer-protection wording, identify the actual program or merchant promise, its issuer, covered payment method and applicable terms. If there is no documented protection behind the phrase, a payment plugin cannot supply the missing promise. If the statement really describes the merchant’s refund policy, compare it with that policy and the procedure the business can perform; do not present it as a guarantee from an unrelated provider.
Keep, narrow or remove the claim and record why
Keep wording when its defined meaning is supported for the current setup. Narrow it when evidence establishes only part of the promise. Remove it when it names a retired integration or a protection the business cannot identify. When evidence is missing, mark the claim unresolved and avoid continuing a broad assurance merely because no one has yet disproved it.
Assign each change to the owner of its actual surface: theme image, checkout text, payment component or linked explanation. After an authorized edit, inspect those affected surfaces together. Retain the old wording, reason and correction date in the business’s internal content record, and identify any payment paths that remain unexamined.
Prism’s published review scope covers marketing claims in images, banners and linked content. A scoped website-review consultation can address the exact reassurance wording and its evidence. Agree separately on any requested technical investigation or implementation. A content review does not itself constitute a security assessment, compliance certificate, underwriting decision or guarantee of protection.
Trust-statement-to-setup check
Copy each actual claim and identify the payment path where it appears. In the last column record the supporting document or observation, its scope and date, and a keep, narrow, remove or unresolved decision. Do not enter secrets, customer records or payment details.
Worksheet entries are not submitted by Prism’s worksheet and are not saved by the site. Use record types, availability, anonymized observations, or match/mismatch results. Do not enter government identifiers, customer names or addresses, customer messages, receipt-access links, card or bank details, passwords, or keys. Send sensitive documents only through the provider’s verified secure channel.
Trust-statement-to-setup check. The last column is for temporary notes.
Statement or graphic
Evidence to seek
Limit to preserve
Your evidence and decision
Secure checkout wording
Evidence to seekThe exact phrase, its intended technical meaning and evidence for that control in the installed integration.
Limit to preserveA broad assurance cannot be justified by the word secure appearing in a theme setting.
Padlock or shield badge
Evidence to seekThe badge label, linked explanation and any real certification or assessment it claims to represent.
Limit to preserveA graphic or certificate for a connection is not a comprehensive security review or account approval.
Wallet or provider logos
Evidence to seekThe live integration, enabled method, relevant configuration and observed payment path.
Limit to preserveAvailability can be conditional; a logo or working button does not establish endorsement or category eligibility.
Encryption claims
Evidence to seekThe exact part of the flow and type of information the claim covers, with evidence from the responsible technical owner.
Limit to preserveDo not extend evidence for one connection to all stored data or connected services.
Buyer-protection wording
Evidence to seekThe named issuer or merchant, applicable terms, payment-method scope and actual remedy described.
Limit to preserveIf no applicable protection can be identified, do not infer one from a gateway, wallet or provider name.
Required-control reassurance
Evidence to seekThe claimed acknowledgment or check and evidence from each standard or express path actually offered.
Limit to preserveThe documented WooCommerce product/cart express paths can omit additional fields; wallet approval does not prove the control completed.
Inherited theme or old-integration statement
Evidence to seekThe current payment arrangement compared with the provider names and assurances still published.
Limit to preserveRetain only claims supported now; an old implementation record does not establish today’s setup.
These are temporary notes. Leaving or reloading this page may clear them. Worksheet entries are not sent automatically. If you copy notes into the consultation message and submit the form, Prism receives them as part of your request.
Limits
Technical functionality does not establish merchant eligibility, legal compliance, buyer-protection coverage or provider endorsement.
WooCommerce Stripe requirements describe that extension and its documented paths. Do not transfer them to a different provider or bypass required controls to make a badge appear justified.
A Prism website review is informational. Technical assessment, implementation and any other deliverables require an agreed scope; payment secrets and private customer records stay outside the public inquiry.
WooCommerce Stripe express checkouts — checked 2026-09-29. Documents HTTPS and Apple Pay configuration requirements, express-path field differences, compatibility limits and the general card-method requirement with a Link exception. These describe functionality, not security certification or merchant approval.
FTC truth in advertising — checked 2026-09-28. Advertising across media including the web must be truthful, non-misleading and appropriately substantiated. The guidance does not certify a specific trust phrase or badge.
Prism features — checked 2026-09-21. Published review scope includes marketing claims in banners, images and linked content; findings are informational rather than legal opinions or compliance certification.