Nev.lt - Free and Secure URL Shortener

Is this QR code safe?

A QR code is just a picture of a link. It cannot hurt your phone on its own, and nothing happens until you open the address inside it. The risk is that you cannot read that address before your camera does, so a code printed on a sticker can send you anywhere at all.
Scammers rely on exactly that gap. The practice has a name, quishing, short for QR phishing, and it works because a square of dots gives you nothing to judge. A misspelled domain in an email is visible. The same domain inside a QR code is not.

Where fake codes turn up

Almost always somewhere you already expected to pay or sign in, because the scam only needs to look ordinary.
Stickers over real codes. Parking meters, EV chargers, and restaurant tables are common targets. The genuine code is covered with a printed sticker, and the payment page that opens belongs to someone else.
Parcel and delivery notices. A card through the door saying a delivery failed, with a code to reschedule or pay a small customs fee. The fee is small on purpose, because a card number is the real target.
Codes inside emails and documents. A QR code in an attachment moves the victim from a filtered work inbox to a personal phone, which is usually the least protected device available.
Posters and flyers. Free Wi-Fi, prize draws, crypto giveaways, or a charity appeal after a disaster. Anything urgent enough that scanning feels reasonable.

How to check a code before you open it

Look at the code itself. If it is a sticker sitting on top of another code, do not scan it. Peel a corner if you can. Genuine codes on machines are usually printed or engraved into the surface, not stuck on.
Read the address, not the page. Check the part just before the first single slash. In pay-parking.example.com/city the real domain is example.com, not pay-parking. Everything to the left is chosen by whoever owns the domain.
Be suspicious of a login or payment you did not expect. Scanning a poster should not lead to a password prompt. If it does, stop and reach the service the way you normally would.
Type the address yourself when money is involved. For parking, deliveries, or anything from your bank, open the app or type the address into your browser. It takes a few seconds longer and removes the entire risk.

What our scanner checks

The Nev QR code scanner reads the code on your device and never uploads the image. Once it has the address, it checks it before showing you anything:
Known threats. The address is matched against continuously updated records of reported phishing and malware hosts. A match is blocked outright and cannot be opened from the result screen.
Structural checks. Addresses are also examined for the patterns phishing pages tend to share, including impersonated brand names and characters chosen to imitate ordinary letters.
Shortened links. Where a code hides one shortened link inside another, the destination is checked as well, so a redirect cannot be used to hide a flagged address.
Anything that fails these checks is shown with a warning before you can continue, and safe links are never opened automatically unless you turn that on yourself.
No automated check catches everything. Treat a warning as a reason to stop, but treat a clean result as a reason to stay normally careful, not a guarantee.

If you already scanned one

Opening the page alone is rarely the damaging step. What matters is what you did next.
If you entered a password, change it now on the real site, and change it anywhere else you reused it. Turn on two-factor authentication if the service offers it.
If you entered card details, contact your bank and tell them the number is compromised. Most banks can freeze and reissue a card immediately.
If you installed something, remove it, and on Android check that no app has been granted accessibility or device administrator permissions it does not need.
If you only looked, close the page. Visiting a phishing page does not by itself give anyone access to your accounts.
Report the code where you found it. Parking operators, councils, and delivery firms generally want to know, because the sticker is usually still there for the next person.

Frequently Asked Questions

Can a QR code give my phone a virus? expand_more

Not by itself. A QR code only stores text, usually a web address, and your phone does nothing until that address is opened. The danger comes from the page it leads to, which may ask for a password or payment details, or offer a file to install.

How can I see where a QR code goes before opening it? expand_more

Use a scanner that shows you the decoded address instead of opening it straight away. Nev shows the full address, checks it against known threat lists, and warns you if it looks unsafe before you decide to continue.

Are QR codes on parking meters safe? expand_more

Usually, but they are one of the most commonly tampered with places. Check whether the code is a sticker placed over another code or a surface that was printed or engraved.

When paying for parking, the safest option is your provider’s own app.

What is quishing? expand_more

Quishing is phishing carried out with a QR code. Because a QR code hides the address until it is scanned, it removes the main clue people use to spot a fake link, and it moves the victim onto a phone where addresses are harder to inspect.

I scanned a suspicious QR code. What should I do? expand_more

If you only opened the page, close it. If you entered a password, change it on the real site and anywhere you reused it.

If you entered card details, contact your bank. If you installed anything, remove it and check which permissions it was granted.