// Security Scanner

QR Code Security Scanner

Scan a physical QR code or upload an image to check if the destination link is safe from malware and phishing.

3Scan Methods
GoogleSafe Browsing
100%Client-Side Decode
0Account Required
Drag & Drop QR Code Image

or click to browse your files

Scan a QR Code with Camera

We will ask for permission to access your device's camera.

Check a URL Manually

Paste any link to verify it's safe before you open it.

Loading...

Analyzing link with Threat Intelligence API...

Status

Decoded Payload:

Forensic Threat Analysis
// 4-Step Safety Check

How to Scan a QR Code Safely

Upload
Camera
Manual
01

Choose a Method

On-Device
02

Decode In-Browser

Safe Browsing
03

Automatic Threat Check

https://example.com
Looks Safe
04

Review & Decide

// Use Cases

When to Use This

QuickQRC
Risk Scenarios · No. 0002
Public Posters & Stickers High Risk
Codes on parking meters or lamp posts can be tampered with.
Restaurant Menus Verify First
Check a table code before entering payment details.
Unsolicited Mail or Email Always Check
Verify a code before acting on an urgent "account issue."
Any Unfamiliar Code When in Doubt
Preview it before your camera app opens it automatically.
QuickQRC
Technical Brief · No. 0003

articles/security-scanner.html

// FAQ

Frequently Asked Questions

The square pattern itself cannot. The risk is where it sends you: a page that tries to exploit the browser, trick you into installing something, or hand over a password. Previewing the URL with this scanner before you open it removes the surprise.

No. It means Google Safe Browsing has no current threat report for that exact URL and the local checks passed. New phishing pages are often not listed yet, and a trusted domain can host a bad page. Read it as 'no known threat', and never enter passwords or card details on an unfamiliar site.

They flag risk signals, not confirmed threats: an unencrypted HTTP link, a punycode lookalike domain, a raw IP address, a URL shortener hiding the destination, or a TLD often abused for spam. One WARN on an expected link may be fine; several on a code you did not expect is a reason to stop.

No. It checks the exact URL you give it. A shortener is flagged because it hides the real destination, but the scanner does not follow the redirect. Expand the short link with a separate tool first if you need to see the endpoint.

No. A browser tool that decodes the code and shows the raw URL is the effective defense against QR phishing. Avoid scanner apps that ask for contacts or location access, since reading a QR code needs neither.

If you only opened the page, close it. If you entered a password, change it everywhere you reused it and enable two-factor authentication. If you entered card details, contact your bank. Report the tampered code to the venue and to your national fraud body.