Threat console
QR code
Investigate in seconds.
Check a QR code photo before scanning to avoid quishing, fake parking meters, fake menu codes and payment scams.
What would you like to analyze?
AI-poweredBacked by our threat intelligence datasets for sharper accuracy.
Upload a photo of the QR code before scanning it.
Step 02 · Results
Awaiting inputAnalysis verdict
Run an analysis to surface the live verdict and evidence here.
Ready when you are.
Drop in a URL, message, or file above to populate your analysis verdict here.
- Risk score with confidence band
- Key signals and evidence summary
- Recommended next steps to stay safe
ThreatSnaps analyses are AI-assisted guidance, not legal or financial advice. Always verify through official channels.
About this checker
QR codes hide the destination URL until you scan, which is exactly why attackers love them. Fake parking meters, restaurant-menu overlays, package-tracking stickers and donation QRs all redirect to phishing or payment-capture pages. Upload a photo of the code and ThreatSnaps decodes the URL, inspects the destination and tells you if it is safe to follow.
Red flags to watch for
- Sticker is pasted on top of an existing QR code on a meter, menu, sign or invoice.
- Decoded URL is a shortener, a freshly registered domain, or does not match the brand on the surrounding material.
- Destination page asks for a card number, OTP or bank login immediately.
What to do if you were targeted
- Do not scan the code with your phone. Use the analyzer to inspect the destination first.
- If you are at a real-world surface (parking, restaurant), report the sticker to the venue or operator.
- If you already paid, dispute the charge and warn anyone else who may have used the same code.
Frequently asked questions
What is quishing?
Quishing is QR-code phishing - using a QR code to deliver a phishing link without showing the URL in plain text.
Does the scanner read printed and on-screen codes?
Yes, as long as the photo is in focus.
Will scanning the photo expose my phone?
No. We decode the QR server-side - your device never visits the URL.