Skip to content
Client-Side Security Scanner

QR Code Safety & Anti-Quishing Inspector

Decode any QR code from an image or inspect a suspicious URL before scanning. Detect homograph spoofing, IP redirects, hidden short links, and phishing patterns client-side.

Upload QR Code Image to Inspect

Click to upload or drag & drop image
PNG, JPG, WebP, or screenshots (Decoded 100% in browser)
Or Paste Target URL / Text
Safety Inspection Verdict

No QR code analyzed yet.

Upload an image or enter a URL on the left to inspect security heuristics.

Understanding QR Code Security Threats and Quishing Attacks

Because QR codes are visually unintelligible to the human eye, consumers cannot preview where a link leads before scanning. Cybercriminals actively exploit this optical blind spot through Quishing (QR Phishing), embedding weaponized links inside printed physical stickers, PDF attachments, and invoice fraud emails.

Top 4 Red Flags Detected by Our Scanner

  1. Punycode and Homograph Impersonation: Attackers register internationalized domain names using Cyrillic or Greek characters that look visually identical to Latin letters (for example, replacing the Latin letter 'a' with the Cyrillic 'а'). Our tool checks for underlying xn-- encodings to detect spoofed brand domains.
  2. Numerical IP Hostnames: Legitimate commercial organizations rarely route users to raw IP addresses (e.g., http://192.241.168.10/auth). This is a frequent indicator of short-lived malicious command-and-control servers.
  3. Hidden Intermediate Short Links: URL shortening domains (bit.ly, tinyurl, t.co) prevent consumers from observing the actual destination domain. Legitimate brand campaigns should use branded domain links or clear, direct URLs.
  4. Non-HTTP Protocol Handlers: Malicious QR codes can encode data:text/html or javascript: strings designed to trigger cross-site scripting or download zero-day browser exploits immediately upon scanning.

Physical Tampering Defense Protocol

In municipal spaces such as parking meters, EV charging kiosks, and outdoor restaurant patios, attackers paste high-resolution paper stickers over legitimate payment codes. Before scanning any payment code in public, always conduct a brief tactile check: run your thumb across the sign surface. If the QR code feels elevated or reveals a peeling adhesive edge, do not proceed with payment.

Frequently Asked Questions About QR Safety

What is "Quishing" (QR phishing)?

Quishing is a social engineering cyberattack where criminals embed phishing links inside QR codes. Because traditional email filters cannot easily inspect image pixels, the QR code reaches the victim, who scans it with a mobile device that lacks enterprise firewall protection.

How can I tell if a physical QR code on a parking meter or restaurant table has been tampered with?

Inspect the code with your fingers. Fraudsters frequently print adhesive stickers and paste them directly on top of genuine signs. If you feel a raised sticker edge or see corners peeling off, do not scan it.

Why are shortened URLs in QR codes risky?

Short URLs (such as bit.ly or tinyurl) mask the true destination domain. Attackers use shorteners to hide malicious hostnames and evade basic inspection until the browser executes the redirect chain.

Is my data uploaded to any server when I test a QR code here?

No. All image decoding and security heuristics run 100% locally inside your browser client using Web APIs. Nothing is ever sent to or stored on any server.