QR Code Scanner
100% privateSee where a QR code really goes before anything opens — with warnings for fake bank sites and UPI scams. Read on this device, never uploaded.
Drop a screenshot of a QR code here
or press Ctrl+V to paste one. Nothing is uploaded, and no link opens until you choose.
It’s too dark to read. Turn on the flash, or move nearer a light.
Nothing opens until you say so. You’ll see where a link really goes, and any warning signs, first.
Pay with
These checks read only what is inside the code. They can’t tell whether a website is a known scam — that would need a lookup that sends the link off your device, which this tool never does.
Scan QR codes often? Put the scanner on your home screen — it opens straight into this page, and works offline.
Recent scans & options
Nothing yet. Codes you scan appear here — Wi-Fi passwords and two-factor keys are never kept.
Checking usage…
Step by step
How to scan a QR code safely
Four steps, no app to install, no account — and no link opens behind your back.
Scan or drop the code
On a phone, press Scan with camera and point it at the code. On a computer, drag a screenshot onto the box, press Ctrl+V to paste one, or choose a picture. Nothing is uploaded when you do.
Read where it really goes
The real website name is picked out in bold, so sbi.co.in.kyc-update.xyz shows up as kyc-update.xyz — which is who you would actually be dealing with.
Check the warnings
Red means a known trick: a fake bank name, lookalike letters, a hidden app download, a UPI code dressed up as a refund. Amber means be careful. Each one says why, in plain words.
Open it, or copy it
Once you have read where it goes, the big button opens the link or your UPI app; a flagged code needs a second press. Copy link sits just below, and Wi-Fi passwords and contacts are copied or saved instead.
Private by design
Why this scanner can’t leak what you scan
A QR code can hold a payment request, a Wi-Fi password or a login key. Most online scanners upload your picture to read it. This one reads it in your browser, and you can check that for yourself.
Zero uploads
The scanner is downloaded to your browser once. Your picture, your camera video and the code’s contents never enter a network request — there is no copy anywhere for us to keep, lose or be asked to hand over.
Camera off the moment it’s read
The camera is only switched on when you press the button, and it is switched off as soon as a code is found — or when you stop, or leave the page. Watch the camera light: it goes out.
History you control
Your last 10 scans are kept in this browser only, so you can find a link again. Wi-Fi passwords and two-factor keys are stripped out before anything is saved, and one tick turns it off.
To be precise about what does leave your device — because “100% private” is easy to say and worth checking. Two things, neither of them your code:
1. When a code is read, this page sends one anonymous message to our counter saying “qr-code-scanner was used”. No picture, no contents, no link, nothing identifying you. It exists so the usage number above is a real one rather than something we invented.
2. Google Analytics records the page view and that a scan happened, along with the type of code (a link, a UPI payment, Wi-Fi…) and whether it raised a warning — never what the code says. You can block it and the scanner works exactly the same.
The history in Recent scans stays in your browser’s own storage and is never sent anywhere. And unlike a promise, the rest is something you can check: turn off your wifi, reload this page and scan a screenshot anyway. It still works.
The safety check
What it looks for — and what it can’t know
Fake QR codes stuck over real ones, sent on WhatsApp or printed on a “parking fine” are now one of the commonest ways into a phishing page. The tricks are few and they repeat, so most of them can be spotted from the code alone.
Fake addresses
- A bank or shop’s name on someone else’s website (hdfc-kyc.example.xyz)
- Lookalike spellings: paypa1, amaz0n, letters from another alphabet
- The “@” trick that hides the real site at the end
- Bare number addresses instead of a name
Hidden destinations
- Link shorteners and QR redirects that only reveal where they go after you open them
- Links that forward you on to a second site — and what that site is
- Free website services a real bank would never use
- Unencrypted http pages
Codes that do more than open a page
- Android app downloads (.apk) — the usual way OTP-stealing malware arrives
- UPI codes that call themselves a refund, prize or cashback
- Phone codes like *401* that forward your calls to a stranger
- Two-factor keys, crypto addresses and premium SMS numbers
What it can’t know. Every check reads only the text inside the code. It does not look the website up in a list of known scams, because doing that means sending the link to someone else’s server — exactly what this tool promises not to do. So a scam site registered yesterday, with an ordinary-looking name, can pass every check. That is why the best result you will see is “No warning signs found”, never “Safe”. Before you type a password, an OTP or a card number anywhere, make sure it is a site you meant to visit.
UPI QR scams
You never scan a QR code to receive money
The “scan to receive” trick costs people across India thousands of rupees every day. A buyer on OLX, a caller promising a refund, a “customer” whose payment supposedly failed — they send a QR code and tell you to scan it to get paid. Scanning a UPI code can only ever send money from your account.
Scanning sends, never receives
To receive money, you share your UPI ID or your QR code. You never enter your UPI PIN to get paid. This scanner shows the payee, the amount and the note before your UPI app ever opens, and flags notes that pretend money is coming to you.
Match the name your app shows
The name written inside a QR code is typed by whoever made it. Your UPI app shows the name the bank has on record for that account. If a shop’s sticker says “Ravi Stores” and your app says somebody else, don’t pay — the sticker may have been swapped.
Already paid? Act within minutes
Call 1930, the national cyber-fraud helpline, or report at cybercrime.gov.in straight away — the sooner it is reported, the better the chance the money can be frozen before it moves. Then tell your bank.
At a glance
Tool specifications
| Reads | QR codes, from a live camera or from a picture |
|---|---|
| Pictures | JPG, PNG, WebP, GIF, BMP, AVIF and iPhone HEIC; screenshots pasted with Ctrl+V; several codes in one picture |
| Understands | Website links, UPI payments, Wi-Fi logins, contact cards (vCard and MECARD), phone, SMS, email, map locations, two-factor setup codes, crypto addresses, plain text |
| Safety checks | Fake bank and brand names, lookalike spellings, hidden destinations, app downloads, UPI scam notes, call-forwarding codes and more — all on your device |
| Low light | Flash button where the camera has one, a screen light where it doesn’t, and automatic contrast boosting in the dark |
| Opens links by itself | Never |
| Where processing happens | In your browser, on your device — nothing is uploaded |
| Works offline | Yes, once the page has loaded, including as an installed app |
| Home screen | Add it like an app on Android, iPhone or a computer: its own “QR Scanner” icon, opening straight into the scanner |
| History | Last 10 scans, on this device only, optional; Wi-Fi passwords and two-factor keys never stored |
| Sign-up | Not required, not offered |
| Price | Free |
Questions
QR code scanning, answered
Is my picture or camera video uploaded?
If it says “No warning signs found”, is the link safe?
Why doesn’t it open the link straight away?
Someone asked me to scan a QR code to receive money. Is that right?
Can it read a QR code from a screenshot or a photo?
Why does it ask for camera permission?
It’s dark and the code won’t scan. What can I do?
What does the scan history keep, and is it free?
Keep it handy
Save it, share it, or tell us what’s missing
Come back to it
Put it on your phone’s home screen like an app — it gets its own QR Scanner icon, opens straight into the scanner and works offline. Or bookmark it. Worth sending to anyone in your family who gets “scan this” messages.
Something not right?
If a code wouldn’t read, a warning was wrong, or a scam got through without one, tell us. The form opens with the tool already filled in, so you only have to describe what happened.
More free tools
Other things you can do here
Every one of these runs the same way — on your device, with nothing uploaded.