Camera + Image Upload · Free

Free QR Code Scanner with AI Safety Check

Upload a screenshot or use your camera to decode any QR code. Every scan is automatically checked for phishing links, lookalike domains, and other scam patterns before you open it.

What this QR scanner reads — and where the scan happens

This free QR code scanner (a QR code reader, if you prefer the term) works two ways: upload an image or screenshot that already contains a code, or switch to Camera Scan and point your device’s rear camera at one. Either way it decodes the code and shows the content in plain, labelled fields — so you can read a QR code online from an image on your computer, or read a QR from an image you just took, without installing an app.

It recognizes the eight formats a QR code can carry — a website URL, a Wi-Fi login (SSID, password, encryption), a vCard contact, an email, a phone number, an SMS, GPS coordinates, or plain text — and parses each into readable fields instead of one raw string. That covers the codes you meet every day: restaurant menus, event tickets, product packaging, app-download links, and Wi-Fi cards.

The QR image itself is decoded inside your browser and is never uploaded. The decoded text is then handed to the built-in safety check described below; only actionable content — links, Wi-Fi, payment, phone, email and SMS entries — is forwarded to the AI classifier, while plain text, contact cards, and map locations are not.

How phishing QR codes (“quishing”) actually work

Quishing is phishing delivered through a QR code. It works because a printed square hides its destination until you scan it — you can’t hover over it or eyeball the address the way you can with a normal link. Attackers lean on that blind spot in a few well-documented ways:

  • A sticker over a real code. On parking meters, restaurant tables, EV chargers, and public posters, someone prints their own QR on a sticker and pastes it over the legitimate one, so your payment or menu link quietly lands on their page.
  • A code inside an email or PDF. Because the link is an image, many filters that scan text URLs never see it — and opening it on a phone can route you around the protections on your work computer.
  • A convincing fake destination. The page mimics a bank, wallet, parcel courier, or brand login and harvests your password, card number, or one-time code.

Decoding the code first — on a screen where you can read the full address before you act — is the single most useful defence. That is exactly what this scanner is for.

How to read a decoded URL before you open it

When the scanner decodes a link it shows the full URL and checks it against the patterns below. Read the address left to right and stop at the first thing that feels off. A classic trap is a lookalike domain such as аpple.com — where the first letter is a Cyrillic “а”, not a Latin “a” — which is a different site entirely from apple.com.

Red flag in the linkWhy scammers use itWhat the scanner does
Punycode / xn-- domainRenders as a lookalike of a real brand using non-Latin lettersFlags it as an internationalized domain that can mimic brand names
URL shortener (bit.ly, t.co, tinyurl and similar)Hides the true destination behind a redirectFlags that the actual destination is hidden
Embedded credentials (user:pass@host)The text before the @ tricks you into trusting a fake hostFlags it as almost always malicious
Numeric IP address instead of a domainNo brand name to recognize; typical of throwaway serversFlags the numeric IP host
Uncommon TLD (.tk, .xyz, .top, .click, .loan and others)Cheap or free endings abused for short-lived scamsFlags a frequently-abused TLD
Plain http instead of httpsTraffic can be read or altered in transitFlags that the connection is not secure
login / verify / account wording plus many subdomainsManufactures urgency and impersonates a real sign-inFlags phishing-adjacent keywords

These signals stack. One on its own might only earn a Caution, but several together push the verdict toward Suspicious or Dangerous.

What the built-in AI Safety Check does — and what it can’t

Every scan is checked automatically; you don’t press anything. A set of local rules first scores the decoded content against the red flags above. Then, for link-type content, a Google Gemma model gives a second opinion and writes the one-sentence explanation you see. The two are combined so the result can only get more cautious, never less — if either the rules or the model think something is wrong, the verdict reflects the more careful of the two.

You get one of four colour-coded verdicts — Safe, Caution, Suspicious, or Dangerous. When a link is rated Dangerous, the normal Open button is replaced by a red “Open Anyway” control that makes you confirm first, and the panel reminds you not to enter passwords, card details, or one-time codes.

It is a filter, not a guarantee — the tool says as much in its own footnote: “Not a substitute for your own judgment.” A brand-new phishing page on a clean, ordinary-looking domain can score as Safe simply because none of the tell-tale patterns are present yet. Read a Safe verdict as “no obvious red flags,” not “verified trustworthy,” and treat Suspicious or Dangerous as a strong reason to stop.

What each decoded field means

A QR code is just text with a prefix that tells the scanner how to read it. Here is what the parsed fields represent for each type:

Wi-Fi network (WIFI:)
SSID is the network name, Password is the key, and Encryption is the security type (WPA/WPA2, or None for an open network). This is how you scan a Wi-Fi QR code to get the password without typing it — but note that anyone who scans the same code can read that password in the clear.
Contact card (BEGIN:VCARD)
Pulls the name, phone number, and email out of the vCard block and lays them out ready to copy, instead of showing the raw contact string.
Website (https://)
Shows the destination in full and runs it through the safety check before you open it — the one type where reading the address first matters most.
Location (geo:)
Splits out latitude and longitude and gives you a one-tap link to open the exact spot in Google Maps.
Phone and SMS (tel: / smsto:)
A number ready to dial, or a number plus a pre-filled message. Be wary of a pre-filled SMS — one trick is a code that texts a premium-rate number on your bill.
Email (mailto:)
The recipient address plus any pre-filled subject the code carries, so you can see what a “tap to email” code would actually send.

What to do if you already scanned a suspicious QR code

Decoding a code is not the dangerous part — reading its content is safe. The risk begins when you act on it: open the link, sign in, join the Wi-Fi, or pay. If something you scanned now looks wrong, work through these steps:

  1. 1. Don’t enter anything. Close the page without typing a password, card number, or one-time code.
  2. 2. If you already entered a password, change it on the real site — reached by typing the address yourself, not via the QR — and turn on two-factor authentication.
  3. 3. If you shared card or payment details, contact your bank or card issuer to flag or freeze the card and watch for unexpected charges.
  4. 4. If the page asked you to install an app or profile, don’t — and remove it if you already did.
  5. 5. On a work device, tell your IT or security team; the same sticker or email may be reaching colleagues.

When you want a code you can trust, make your own instead: you can create a QR code for a URL, Wi-Fi network, or contact card, or generate many codes at once from a list — and know exactly where each one points.

Frequently asked questions

Open the Upload Image mode, then drag and drop the photo or screenshot that contains the QR code, or click to pick a file (JPG, PNG, WEBP, and other common image formats). The code is read from the image right in your browser and the decoded content appears instantly — no app to install and nothing uploaded.

Yes. Switch to Camera Scan, allow camera access, and point the rear camera at the code. It decodes in real time and then runs the safety check automatically. It works in modern mobile browsers on both iPhone and Android, so there is nothing to download.

Upload a photo or screenshot of the Wi-Fi QR code, or scan it with your camera. The scanner detects the Wi-Fi format and shows the network name (SSID), password, and encryption type as separate fields you can copy. Keep in mind that anyone who scans that code can read the password.

Yes. Take a screenshot of the page that shows the QR code and upload that image in Upload Image mode. The scanner reads the code from the screenshot the same way it reads any other image.

Make sure the code is sharp, well lit, and fills a good part of the frame. Crop the image tighter around the code, avoid glare and steep angles, and for camera scanning hold the device steady. Very small, damaged, or low-resolution codes can fail to decode.

It is free with no signup and no scan limit. The image is decoded in your browser and never uploaded. The decoded text is passed to the safety check, where only link-type content (URLs, Wi-Fi, payment, phone, email, and SMS) is forwarded to the AI classifier — plain text, contact cards, and map locations are not.

From Our Blog

Related Tools