HomeLearnAre QR codes safe? What a scan can and cannot do
Basics

Are QR codes safe? What a scan can and cannot do

The code is only a delivery method. Every real risk lives at the destination, and your phone shows you that before it opens it.

7 min read · Updated July 2026

What a QR code actually contains

A QR code is a way of writing text down. The pattern encodes a few hundred characters — nearly always a web address, sometimes a phone number, a WiFi password or contact details. That is the entire contents. There is no program, no attachment and nothing executable inside it.

This sets a hard limit on what any QR code can do to you. A scanner reads the text and hands it to your phone, and what happens next is whatever your phone does with a piece of text of that type. For a web address, that means offering to open it.

What a scan cannot do

The limits below follow directly from that. None of them depend on your phone being up to date, on a security app, or on you being especially careful — they are consequences of the format holding nothing but text.

  • It cannot install an app. Installing requires the app store and your confirmation.
  • It cannot run a program. There is nothing executable to run.
  • It cannot read your contacts, photos or messages. The scanner is a camera reading a picture.
  • It cannot take a payment. That needs your banking app and your authentication.
  • It cannot tell the person who printed it who you are. A static code has no idea it was scanned at all.

Modern phones also show you the destination before opening it, which is the single most useful safety feature in the whole system. Reading that preview is most of what safe scanning consists of.

The real risk is the destination

A QR code is a link you cannot read. That is the honest summary. On a screen you can hover over a link and see where it goes, but a printed square tells you nothing until the camera is already pointed at it.

So every risk attached to QR codes is a risk attached to links: a page imitating your bank and asking you to sign in, a fake parking or delivery payment form, a page pushing you toward installing something from outside the app store. The technique has a name now — quishing — but nothing about it is new. The code is the envelope, not the threat.

The one thing the format genuinely adds is trust by placement. A sticker on a parking meter or a restaurant table borrows the credibility of the surface it is stuck to, and that is exactly what makes it work.

Stickers over stickers

The common real-world attack is physical rather than technical. Someone prints a code and sticks it over the legitimate one on a parking meter, a charging point, a poster or a payment terminal. The surface still looks official, because it is official. Only the square changed.

Checking takes a second: run a finger across the code. A sticker applied over a printed surface has an edge you can feel, and often a slight mismatch in colour or gloss. Anywhere money is involved, that check is worth making.

Scanning safely

Almost all of it reduces to one habit: look at the destination before you tap it. The rest is knowing which situations deserve more than a glance.

  • Read the preview before opening it. If the domain is not the one you expected, stop there.
  • Never enter card details, passwords or a bank login on a page you reached from a printed code. Go to the site or app yourself instead.
  • Treat urgency as a warning sign. Fines, failed deliveries and expiring offers exist to stop you checking.
  • On anything public, especially payment terminals and parking machines, look for a sticker layered over the original.
  • Do not install anything a scanned page suggests. Go to the app store and search for it.
  • Be wary of shortened links inside codes, which hide the destination a second time.

None of this needs a security app. Your phone's own preview and a moment of attention cover the overwhelming majority of it.

If you are the one printing codes

You inherit part of the responsibility, because you are training your customers to scan things. Point codes at your own domain rather than a shortener, so the preview shows something recognisable. Print the address in small type beside the code so anyone cautious has a way to reach the page without scanning at all.

Then check your codes physically from time to time. If yours are in public, someone needs to look at them, because a sticker placed over your code becomes your problem in the customer's mind regardless of who put it there.

Printing the destination beside the code in small type costs nothing and lets a cautious customer bypass the code entirely.

Two cases worth thinking about

A WiFi code contains the network name and password in plain text, so anyone who photographs it has your password. That is fine for a guest network and a bad idea for the network your till runs on.

A contact code contains whatever details you put into it. Printing a personal mobile number on a public poster is a reasonable decision in some situations and a regrettable one in others, but it should be a decision rather than an accident.

What happens when you make a code here

QR Code Agent builds the pattern in your browser. What you type never leaves your device, is not sent to a server and is not stored, because there is no account to store it against.

The codes are static, so they carry your address directly with no redirect in the middle that could later be changed or taken over. The trade-off is that we cannot see, edit or disable a code once you have made it — which in security terms falls mostly on the good side, because there is no middle to compromise.

Make one now

Free, no sign-up, and your code never expires.

OPEN THE GENERATOR →
Related guides

Are QR codes safe? What a scan can and cannot do FAQ

Can scanning a QR code give my phone a virus?
Not by itself. The code holds text and the scan opens a link. Malware would still need you to install something, which takes several deliberate confirmations.
Can someone track me through a QR code?
A static code cannot — it has no idea it was scanned. A dynamic code passes through the provider's server, which can log the time, rough location and device type, though not who you are.
What is quishing?
Phishing delivered by QR code: a printed code leading to a page that imitates a real one to collect your login or card details. The defence is the same as for email phishing — check the domain, and never sign in from a link you did not go looking for.
How do I check where a QR code goes before opening it?
Your phone shows the destination as a banner or notification after it reads the code. Read it before tapping. If the domain is unfamiliar, or the code was stuck on a payment terminal, do not open it.
Are the codes made here safe to use?
They are generated in your browser and contain exactly the address you typed, with no redirect and no tracking. The safety of what people find at the other end still depends on the page you point them at.

Got your code? ☕ Buy me a coffee — it keeps this tool free for everyone.