Is this QR code safe?
A QR code is just a picture of a link. It cannot hurt your phone on its own, and nothing happens until you open the address inside it. The risk is that you cannot read that address before your camera does, so a code printed on a sticker can send you anywhere at all.
Scammers rely on exactly that gap. The practice has a name,
quishing, short for QR phishing, and it works because a square of dots gives you nothing to judge. A misspelled domain in an email is visible. The same domain inside a QR code is not.
Where fake codes turn up
Almost always somewhere you already expected to pay or sign in, because the scam only needs to look ordinary.
Stickers over real codes. Parking meters, EV chargers, and restaurant tables are common targets. The genuine code is covered with a printed sticker, and the payment page that opens belongs to someone else.
Parcel and delivery notices. A card through the door saying a delivery failed, with a code to reschedule or pay a small customs fee. The fee is small on purpose, because a card number is the real target.
Codes inside emails and documents. A QR code in an attachment moves the victim from a filtered work inbox to a personal phone, which is usually the least protected device available.
Posters and flyers. Free Wi-Fi, prize draws, crypto giveaways, or a charity appeal after a disaster. Anything urgent enough that scanning feels reasonable.
How to check a code before you open it
Look at the code itself. If it is a sticker sitting on top of another code, do not scan it. Peel a corner if you can. Genuine codes on machines are usually printed or engraved into the surface, not stuck on.
Read the address, not the page. Check the part just before the first single slash. In
pay-parking.example.com/city the real domain is
example.com, not
pay-parking. Everything to the left is chosen by whoever owns the domain.
Be suspicious of a login or payment you did not expect. Scanning a poster should not lead to a password prompt. If it does, stop and reach the service the way you normally would.
Type the address yourself when money is involved. For parking, deliveries, or anything from your bank, open the app or type the address into your browser. It takes a few seconds longer and removes the entire risk.
What our scanner checks
The
Nev QR code scanner reads the code on your device and never uploads the image. Once it has the address, it checks it before showing you anything:
Known threats. The address is matched against continuously updated records of reported phishing and malware hosts. A match is blocked outright and cannot be opened from the result screen.
Structural checks. Addresses are also examined for the patterns phishing pages tend to share, including impersonated brand names and characters chosen to imitate ordinary letters.
Shortened links. Where a code hides one shortened link inside another, the destination is checked as well, so a redirect cannot be used to hide a flagged address.
Anything that fails these checks is shown with a warning before you can continue, and safe links are never opened automatically unless you turn that on yourself.
No automated check catches everything. Treat a warning as a reason to stop, but treat a clean result as a reason to stay normally careful, not a guarantee.
If you already scanned one
Opening the page alone is rarely the damaging step. What matters is what you did next.
If you entered a password, change it now on the real site, and change it anywhere else you reused it. Turn on two-factor authentication if the service offers it.
If you entered card details, contact your bank and tell them the number is compromised. Most banks can freeze and reissue a card immediately.
If you installed something, remove it, and on Android check that no app has been granted accessibility or device administrator permissions it does not need.
If you only looked, close the page. Visiting a phishing page does not by itself give anyone access to your accounts.
Report the code where you found it. Parking operators, councils, and delivery firms generally want to know, because the sticker is usually still there for the next person.