Docuboxer

Scan QR Codes Safely

Read a QR code and analyze its link before you ever open it.

100% local — your files are never uploaded to any serverNo signupFree

You can also paste a screenshot directly (Ctrl+V / Cmd+V)

or

The QR code is decoded and analyzed entirely in your browser: nothing is uploaded anywhere, and its content is never opened automatically.

The QR code analysis will appear here

Is it safe to scan a QR code you don't recognize?

An unfamiliar QR code isn't safe by default — it can lead to a phishing link, a dangerous URL scheme, or try to steal your WiFi password. This tool decodes the QR code from your camera or an image and, if the content is a link, runs it through the same local heuristics engine as /url-inspect, without ever opening it. Non-link payloads — a WiFi network, a vCard contact, a phone number, an SMS — are shown in plain text so you can decide what to do with them. It's free, no signup required, and everything happens in your browser: the image or camera feed never leaves your device. There's no cloud blocklist behind it — that keeps your input private, but also means a very new malicious link might not trigger any signal at all. Use it before scanning a QR code on a poster, a restaurant table, or an email.

How to use Scan QR Codes Safely

  1. Upload an image with the QR code (drag it, click to browse, or paste a screenshot with Ctrl+V) or tap "Scan with camera".
  2. The tool decodes the QR code locally and classifies its content: link, WiFi network, contact, phone, SMS, or plain text.
  3. If it's a link, it gets broken down and analyzed with the same heuristics as /url-inspect — scheme, homographs, literal IPs, shorteners, entropy — without ever opening it.
  4. Review the signals found and their explanation before deciding whether to copy the link and paste it into your browser yourself.
  5. For non-link payloads (WiFi, contact, SMS), review the fields shown in plain text and copy them if you need to — nothing runs automatically here either.

Common use cases

Scanning a QR code stuck on a parking meter or street sign

Fake QR stickers placed over real ones ("quishing") are a common scam at parking meters and restaurants. Check the real domain before entering any payment details.

Verifying a WiFi QR code in a public space

Before joining the network a QR code promises at a café or airport, check the SSID and whether it really needs no password, instead of connecting blind.

Checking a QR code received by email or message

QR codes embedded in PDFs or screenshots dodge the link filters many email clients rely on. Analyze the image here before scanning it with your phone.

Checking a QR code on a business card or event flyer

Pull out the vCard contact or link without scanning it with your personal phone or exposing your camera to a QR code from an unknown source.

Frequently asked questions

What is "quishing"?

It's QR-code phishing: an attacker sticks a fake QR code over a legitimate one — parking meters, menus, posters — or sends one by email, and it leads to a phishing page or a dangerous URL scheme. Since you can't read a QR code's destination before scanning it with your phone, it's harder to spot at a glance than a plain text link.

Does my camera image or video feed get uploaded anywhere?

No. QR decoding — via the jsqr library — and the link analysis both run entirely in your browser. Neither the image nor the camera stream ever leaves your device.

Why doesn't this tool ever open the link automatically?

That's the deliberate difference from /qr-read: the goal here is to analyze before you decide, not to make clicking easier. You can only copy the content — opening it, if you choose to, is a conscious action you take yourself in your browser.

What happens if the QR code contains a WiFi network?

The SSID, password, and encryption type are shown in plain text so you can decide whether to connect manually. Nothing is saved or connected automatically.

Does it work for QR codes that aren't links?

Yes. It also recognizes and explains WiFi network, contact (vCard), phone, and SMS QR codes. Only links go through the extra security analysis, since they're the payload type with real phishing risk.

How is this different from /qr-read?

/qr-read is the general-purpose reader: it decodes any QR code and lets you open the result directly. /qr-scan-safe is built for when you don't trust the QR code's source: it analyzes the link with security heuristics before you decide what to do.