The code is only a delivery method. Every real risk lives at the destination, and your phone shows you that before it opens it.
A QR code is a way of writing text down. The pattern encodes a few hundred characters — nearly always a web address, sometimes a phone number, a WiFi password or contact details. That is the entire contents. There is no program, no attachment and nothing executable inside it.
This sets a hard limit on what any QR code can do to you. A scanner reads the text and hands it to your phone, and what happens next is whatever your phone does with a piece of text of that type. For a web address, that means offering to open it.
The limits below follow directly from that. None of them depend on your phone being up to date, on a security app, or on you being especially careful — they are consequences of the format holding nothing but text.
Modern phones also show you the destination before opening it, which is the single most useful safety feature in the whole system. Reading that preview is most of what safe scanning consists of.
A QR code is a link you cannot read. That is the honest summary. On a screen you can hover over a link and see where it goes, but a printed square tells you nothing until the camera is already pointed at it.
So every risk attached to QR codes is a risk attached to links: a page imitating your bank and asking you to sign in, a fake parking or delivery payment form, a page pushing you toward installing something from outside the app store. The technique has a name now — quishing — but nothing about it is new. The code is the envelope, not the threat.
The one thing the format genuinely adds is trust by placement. A sticker on a parking meter or a restaurant table borrows the credibility of the surface it is stuck to, and that is exactly what makes it work.
The common real-world attack is physical rather than technical. Someone prints a code and sticks it over the legitimate one on a parking meter, a charging point, a poster or a payment terminal. The surface still looks official, because it is official. Only the square changed.
Checking takes a second: run a finger across the code. A sticker applied over a printed surface has an edge you can feel, and often a slight mismatch in colour or gloss. Anywhere money is involved, that check is worth making.
Almost all of it reduces to one habit: look at the destination before you tap it. The rest is knowing which situations deserve more than a glance.
None of this needs a security app. Your phone's own preview and a moment of attention cover the overwhelming majority of it.
You inherit part of the responsibility, because you are training your customers to scan things. Point codes at your own domain rather than a shortener, so the preview shows something recognisable. Print the address in small type beside the code so anyone cautious has a way to reach the page without scanning at all.
Then check your codes physically from time to time. If yours are in public, someone needs to look at them, because a sticker placed over your code becomes your problem in the customer's mind regardless of who put it there.
Printing the destination beside the code in small type costs nothing and lets a cautious customer bypass the code entirely.
A WiFi code contains the network name and password in plain text, so anyone who photographs it has your password. That is fine for a guest network and a bad idea for the network your till runs on.
A contact code contains whatever details you put into it. Printing a personal mobile number on a public poster is a reasonable decision in some situations and a regrettable one in others, but it should be a decision rather than an accident.
QR Code Agent builds the pattern in your browser. What you type never leaves your device, is not sent to a server and is not stored, because there is no account to store it against.
The codes are static, so they carry your address directly with no redirect in the middle that could later be changed or taken over. The trade-off is that we cannot see, edit or disable a code once you have made it — which in security terms falls mostly on the good side, because there is no middle to compromise.
Free, no sign-up, and your code never expires.
Got your code? ☕ Buy me a coffee — it keeps this tool free for everyone.