QR Code Safety Scanner
See where a QR code leads — and the tricks it uses — before it can do anything.
Scan a code
Camera off
Hold the code steady in good light. Each code is checked as soon as it is read — nothing opens by itself.
What the code would do
Scan a picture, use the camera or paste a code’s text. You will see where it leads and what it would do — it is never opened for you.
Pictures and camera frames are decoded on this device and never uploaded, and links are never opened or fetched. Browsers without a built-in barcode reader download the decoder (zxing-wasm, about 0.9 MB) from this site once.
About the QR Code Safety Scanner
A QR code is a link you cannot read. Scammers use that: they paste their own codes over the real ones on parking meters and shop counters, and send codes by e-mail or text with an urgent excuse — a failed delivery, a locked account, a refund — so that you scan before you think. Security people call it quishing.
This scanner reads the code from a photo, a screenshot or the camera and shows what it would do, without doing it. Links get the full analysis of the Suspicious Link Checker: the real domain, look-alike letters, brand names placed in front of a stranger’s domain, text before an @, shorteners, bare IP addresses, programs disguised as documents. UPI codes are spelled out — who gets paid, how much, and the reminder that a payment code can never put money into your account. Merchant payment codes in the EMV format (Pix and other national schemes) have their checksum verified, so an edited code stands out. Wi-Fi, contact, calendar, SMS, phone and crypto codes are explained with the risks of each, and Android app links (intent:) are unwrapped to show which app they open and what they hand to it — a UPI payment inside one is explained as the payment it is. Invisible characters that reverse the order of text (the right-to-left override) are written out, so an address cannot display as something else. Nothing is uploaded, and nothing is opened.
How to use it
- Choose Photo or screenshot and pick or paste a picture (Ctrl+V / ⌘V), or choose Camera and press Start camera. You can also paste a code’s text under Text.
- Read the verdict and If you use it: what the code would make your phone do.
- Go through the warnings. For links, the real website is shown separately from the full address; for payments, the payee and amount.
- If it is fine, open the link yourself or pay in your own app. To warn others, use Copy report or Copy defanged link.
Examples
upi://pay?pa=refund.helpdesk@okexample&pn=Refund%20Desk&am=4999&cu=INR&tn=Refund%20of%20your%20order
High risk — Promises money, but takes it: the code pays ₹4,999 from your account to refund.helpdesk@okexample.
A UPI payment code only ever sends money. “Scan to receive your refund” is a scam.
https://www.hdfcbank.com.kyc-update.example/login
High risk — the real website is kyc-update.example; the code leads to a sign-in page.
A Pix code whose city was changed after it was generated
High risk — The checksum does not match: the code is damaged or was edited.
Common uses
- Checking the QR code on a parking meter, an EV charger, a restaurant table or a poster before paying or signing in.
- Checking a code that arrived by e-mail or text (“scan to update your account”, “scan to reschedule the delivery”).
- Checking a UPI code before paying a shop, a seller from a marketplace or someone who says they are sending you money.
- Seeing what a Wi-Fi, contact or event code contains before your phone saves or joins it.
Where malicious codes turn up
The US Federal Trade Commission warns about QR codes stuck over real ones on parking meters and sent in e-mails and texts with a story about a failed delivery, an account problem or suspicious activity. The page behind the code is often a perfect copy of a sign-in or payment page. The FTC’s advice: inspect the address before you open it, do not scan a code in an e-mail or text you were not expecting — especially one that urges you to act at once — and contact the company through a phone number or website you know is real.
UPI payment codes
A upi://pay code is a payment request: it opens your UPI app with the payee’s UPI ID (pa), a name (pn) and often an amount (am), a note (tn) and a reference (tr) — the parameters described in Google Pay’s UPI integration guide, which follows NPCI’s UPI linking specification. Whatever the note says, approving it sends money from your account. Before you enter your UPI PIN, your app shows the name registered for that UPI ID; the name in the code can be anything, so compare the registered name with the shop or person you expect. A upi://mandate code sets up repeated payments.
Merchant payment codes (EMV QR)
Many countries’ shop codes use the EMV merchant-presented QR format: numbered fields for the payment account, merchant name and city, currency and amount, ending in a CRC-16 checksum. The scanner reads every field and recomputes the checksum the way Banco Central do Brasil’s Pix manual specifies (polynomial 0x1021, initial value 0xFFFF). A wrong checksum means the code was damaged or edited by hand. A correct one proves only that the code is intact, not who made it — a fraudster’s own code has a valid checksum too.
Wi-Fi codes
A WIFI: code holds a network name, its security type and the password (ZXing’s format, with SAE for WPA3 as Android writes it). The password stays hidden until you press Show. Open networks and old WEP security let others nearby see unencrypted traffic, and a code on a table or a poster can point to a look-alike network set up by someone else, so ask for the exact network name.
Limitations
- The link check reads the address; it does not visit the page, follow redirects or consult blocklists. A clean result is not proof that the site is safe.
- Shortened links stay hidden until they are opened; the scanner says when a code uses one.
- The UPI and payment checks cannot see the registered name your payment app will show — that final check is yours to make.
- Damaged, tiny or glare-covered codes may not be read; try a sharper photo or the thorough search.
Privacy
Everything happens in your browser. What you enter or open here is not uploaded or stored by MySmartCoPilot. Browsers without a built-in barcode reader download the decoder (zxing-wasm, about 0.9 MB) from this site the first time it is needed. Pictures, camera frames and the codes’ contents are never uploaded, and links are never opened.
Frequently asked questions
Is it safe to scan a suspicious code here?
Yes. The code is decoded on your device and its contents are only analysed as text: links are never opened or fetched, payments are never started, and nothing is uploaded. Unlike your phone’s camera app, this page never acts on a code by itself.
Someone says I have to scan a QR code to receive money. Is that right?
No. A UPI QR code — or any payment code — makes you pay the person in the code. Receiving money never needs a scan or your UPI PIN. Anyone who says otherwise is trying to take your money.
Why does a code from a well-known company show “No warning signs” but still a note about checking?
Because a good-looking link proves little: the company’s real address can be pasted under a fake page’s code in seconds. The scanner reports the tricks it can see; where the code came from matters too.
Can a QR code infect my phone just by being scanned?
Reading a code is only reading text. The danger comes from what you do next — opening the link, installing an app it offers, joining a network, entering a password or approving a payment. That is why this page shows the content and never acts on it.
How is this different from the QR Code & Barcode Scanner?
The QR Code & Barcode Scanner reads every kind of code and lets you act on it (open, save, copy). This page is for codes you do not trust: it runs the full Suspicious Link Checker analysis on links, verifies payment-code checksums and explains the risks of each kind of code.
I already paid or entered my password. What now?
Call your bank at once if you paid or shared card or UPI details; in India, also report financial cyber fraud on the helpline 1930 or at cybercrime.gov.in. If you typed a password, change it on the real site (and wherever you reuse it) and turn on two-step sign-in.