FREE TOOL · RUNS ON YOUR DEVICE

QR Code Safety Checker

Upload a QR code image or paste a link, and check it for common scam warning signs before you visit it.


VERIFIED SAFE

Your QR image and link are never uploaded anywhere. This tool decodes and analyses everything locally in your browser. You can disconnect from the internet after the page loads and it will keep working — proof that nothing is being transmitted. No accounts, no cookies, no analytics tracking what you scan.

Upload a QR image
Upload a photo or screenshot containing a QR code
📷

Click to choose a file or drag a QR code image here

Uploaded QR code preview
Decoded content
Risk assessment
—

How this checker works

When you upload an image, the QR code is decoded entirely on your device — the image file is never uploaded to a server. The decoded link (or a link you paste directly) is then checked against common patterns used in "quishing" (QR phishing) scams: link shorteners, IP addresses instead of real domains, brand names combined with suspicious extra words, unusual domain endings, and other red flags. It's a pattern-based heuristic, not a guarantee — always think twice before scanning QR codes in public places like parking meters, posters, or restaurant tables, since these are common spots for scammers to stick fake codes over real ones.

Frequently asked questions

Is my photo uploaded anywhere when I use this tool?

No. The image is decoded entirely in your browser using JavaScript. It's never sent to a server, logged, or stored. You can disconnect your internet after the page loads and the tool still works.

What is "quishing"?

Quishing is phishing carried out through QR codes — scammers place a fake QR code sticker over a real one (on parking meters, posters, or menus) or send one by email, hoping you'll scan it without checking where it actually leads.

What should I do before scanning a QR code in public?

Check that the code isn't a sticker placed over another one. Most phone cameras show a preview of the link before opening it — read it carefully before tapping. If it looks unfamiliar, shortened, or unrelated to where you found the code, don't open it.

Why QR Codes Are a Scammer’s Shortcut

A QR code hides its destination completely. You cannot hover over it, you cannot read the domain, and your phone’s camera will follow it without question. Attackers exploit this with stickers placed over legitimate parking meters and restaurant menus, “quishing” emails, and codes that lead to convincing phishing pages designed to harvest card details or install apps.

What to Check Before You Scan

A Safer Scanning Habit

Before scanning anything in public, give it a gentle scratch — attacker stickers peel; printed codes do not. And never enter payment details on a page you reached via a code you did not verify. Two seconds of checking defeats this entire scam category.

Why QR codes became a scam tool

A QR code is just a link you cannot read. That single property is what makes it attractive to fraudsters. All the advice about inspecting a web address before clicking is useless when the address is a pattern of squares, and the habit most people have built over the last few years is to point the camera and tap whatever appears.

The practice even has a name in security circles: quishing. It has grown quickly because the attack requires no technical skill. Printing a sticker costs almost nothing, and physical placement carries an implied endorsement — a code stuck on a parking meter looks like it belongs to the council.

Where the fakes turn up

Scanning safely

  1. Check the physical code first. Feel the edges. A sticker over the original often has a raised lip, a slightly different colour, or sits crooked against the printing around it. In a car park, compare several machines — if one code looks different from the rest, that is your answer.
  2. Read the address before you tap. Every modern phone camera shows the destination as a preview. Read it. That preview is the only defence the format allows you, and it is the step almost everyone skips.
  3. Be suspicious of shorteners. A legitimate business code usually points at its own domain. A bit.ly link on a parking meter is a red flag.
  4. Never enter payment details from a code you did not expect. Use the official app or type the known address instead. Every genuine parking operator has an app and a phone number.
  5. Treat printed codes in unsolicited mail as hostile. If a letter says you owe money, contact the organisation through a number you look up independently.

What the checker on this page does

Paste the address a QR code resolves to and this tool examines it for the same structural warning signs as a typed link: brand names in the wrong position, excessive subdomains, raw IP addresses, shortener services, character substitutions and high-risk domain endings. The analysis happens in your browser and the address is not transmitted anywhere.

It works on the address, not the image, so you need your phone's preview or a scanner that shows the target without opening it. That is deliberate — it keeps the whole process on your own device.

If you already scanned and paid

Contact your bank immediately and report the transaction as fraudulent. Card payments made to a fraudulent merchant can often be reversed if you move quickly, and speed genuinely matters. Then report it: our scam reporting page lists the right agency for your country. If the payment was in cryptocurrency, recovery is effectively impossible, but reporting still helps investigators map the networks involved.


Frequently asked questions

Can a QR code itself contain a virus?

Not really. A QR code holds text, usually a web address. The risk is in what that address leads to and what you do when you get there, not in the code itself.

How can I see where a code goes before opening it?

Every modern phone camera app shows a preview of the destination address before you tap. Read it and check the domain. Some scanner apps also have a setting to show the full address rather than opening it straight away.

Are QR codes on restaurant tables safe?

Usually, but check whether the code is a sticker sitting on top of printing. A genuine menu code normally points to the restaurant's own domain or a well-known ordering platform, and never needs card details just to display the menu.

What should I do if I scanned a fake parking code and paid?

Call your bank straight away and report it as fraud. Card payments to fraudulent merchants can often be reversed if reported quickly. Then report it to your country's fraud agency and let the parking operator know so they can remove the sticker.

Does this tool scan the QR image itself?

No. You paste the address the code resolves to, and the tool analyses that address in your browser. Keeping it address-based means nothing you scan is ever uploaded.

Made in New Zealand 🇳🇿 — sharing good cyber hygiene habits with friends everywhere.
About UsContact UsPrivacy PolicyTerms
👀 … site visits