🔍 QR Safety Scanner & Malicious Pattern Detector
Point at any QR code
📸 How the scanner looks (preview)
📷 Camera view
✅ Safe result
⚠️ Warning example
⚙️ How the scam detection works
The tool scans QR content for three danger signals:
- URL shorteners – bit.ly, tinyurl, etc. Attackers hide the real link.
- Raw IP addresses – e.g., 192.168.1.1 – bypass domain filters.
- Risky keywords – "login", "verify", "password", "OTP" inside the link path.
If any appear, you'll see a yellow warning. Always double‑check the link before entering personal data.
📊 QR code security trends & research (2026)
🔹 The rise of quishing (QR phishing)
Security researchers have observed a sharp increase in QR‑based phishing attacks. According to the FBI Internet Crime Complaint Center (IC3), reported QR phishing incidents increased by over 200% between 2021 and 2023, with losses exceeding $50 million in the US alone (IC3 Annual Report 2023). The FTC warns that malicious QR codes can steal login credentials and payment information. In India, CERT‑In has issued multiple advisories about UPI QR fraud, emphasising the need to verify payee names before transferring money.
🔹 How QR codes actually work
A QR (Quick Response) code is a two‑dimensional barcode that stores data using black and white squares. When scanned, the pattern is decoded using error‑correction algorithms – even if part of the code is damaged, it can still be read. This reliability makes QR codes popular for URLs, WiFi passwords, vCards, and UPI payments.
🔹 Common quishing tactics
Attackers use sticker overlays on real codes, embed QR codes in phishing emails to bypass filters, and replace legitimate UPI stickers with fake ones. The tool flags these risks by analyzing shortened links and suspicious keywords.
⚠️ Real‑world QR scam patterns
📌 Common examples
📋 Illustrative case studies
🕵️ How attackers modify QR stickers in public places
- Sticker overlays: Thin sticker placed directly over the real code.
- Replacement of whole signs: New signs with malicious QR codes.
- Tampered QR on delivery packages: Fake "rate your delivery" codes.
- QR in unexpected places: Charging stations, notice boards, windows.
💡 How to protect yourself: Look for misaligned or raised stickers. When in doubt, type the website address manually.
📊 How this QR safety tool compares to other QR readers
| Feature | Our scanner | Most QR apps |
|---|---|---|
| Phishing warnings | ✅ Yes (short links, IPs, keywords) | ❌ No or basic |
| Privacy & data handling | ✅ Browser‑only, no uploads | ⚠️ Often sends data to servers |
| Scan from image upload | ✅ Yes | ⚠️ Sometimes |
| Free & no ads | ✅ Yes | ⚠️ Often ad‑supported |
📖 Quick start guide
- Activate camera: Press "Back" or "Front" and allow access.
- Frame the code: Hold your device steady. Scanning stops automatically.
- Examine the result: Check for any warning badge (e.g., "⚠️ Pattern alert").
- Choose wisely: Green badge = likely safe; yellow warning = be cautious.
- Alternative – upload: Click "Upload Image" to scan a QR from your gallery.
- Revisit scans: Tap any entry in "Recent scans" to review again.
💡 Safety reminder: A warning doesn't always mean a scam, but always verify the link before entering passwords or payment info.
📖 The story behind this QR safety scanner
I'm Buli Goswami, a developer focused on building privacy‑first web tools. I created this QR scanner after seeing how easily fake QR codes can trick people – from parking meter stickers to phishing emails. The tool was built using public QR code specifications and tested against hundreds of real‑world QR samples, including URL, WiFi, vCard, UPI, and email formats. Its detection logic is based on pattern analysis (shortened links, raw IPs, and suspicious keywords) and runs entirely in the browser – no data is sent to any server.
This tool is part of Digital Tools 111, a collection of free, client‑side utilities. All privacy information is in the Privacy tab.
🚀 Mission & roadmap
Mission: Make QR scanning safer by providing transparent warnings before users click on hidden links.
Roadmap (next 6 months):
- ✅ Live QR scanner with phishing pattern detection – released.
- 🔜 Batch scan (upload multiple QR images at once).
- 🔜 Custom keyword lists for advanced users.
- 🔜 Browser extension version.
Tool version: 2.8.0 | Offline: Yes (after first visit)
🔒 Privacy & data handling policy
Last updated: June 2026
We do not collect any personal data. Camera feeds, uploaded images, and scan history stay inside your browser. No information is sent to any server. The only external code is the HTML5‑QRCode library loaded from a CDN.
📌 Scan history storage
Your last 5 scans are saved in your browser's local storage. You can clear it anytime by clearing your browser data.
🛡️ Security protections
- All QR decoding happens locally – no API calls.
- We validate URLs and only allow safe schemes (http, https, mailto, tel, sms, upi).
- No eval() and no execution of QR content as code – XSS protection is built in.
Disclaimer: Pattern detection is not 100% foolproof. Always verify suspicious links manually.
📧 Contact us
Have questions, bug reports, or scam examples to share? Fill out the form. We reply within 2–3 days. For security issues, please use the direct email below.
📧 Direct email for security reports: buli.goswami99@gmail.com
❓ Frequently asked questions
✅ Tip: Always check the URL that appears before opening it.
✅ Tip: You can upload a screenshot of a QR code to check it later.
✅ Tip: If a link looks suspicious, manually type the known website address in your browser.
✅ Tip: You can verify this by disconnecting from the internet after first load – scanning still works.
✅ Tip: Use this feature to safely inspect a QR code you saw in a public place without pointing your camera at it.
✅ Tip: Install the page to your home screen for the best offline experience.
✅ Tip: If a payment QR asks for unusual permissions, do not proceed.
✅ Tip: Report suspicious QR codes to the platform or business where you found them.
0 Comments