A QR code is unreadable to a human, which is exactly what makes it useful to fraudsters. How to scan safely, and what to think about before you print one.
This is the whole problem in one sentence. A link written out can be inspected before you click it. A QR code is an opaque pattern: the only way to find out where it goes is to point a camera at it, by which time your phone may already be loading the page.
Fraud that exploits this has its own name now — "quishing" — and it is effective precisely because a printed code carries an air of officialdom. The commonest form could not be simpler: a sticker with a malicious code placed over the legitimate one on a parking meter, a restaurant table, an EV charger or a posted notice.
None of this means avoiding QR codes. It means treating a code the way you would treat a link in an unexpected email.
A Wi-Fi QR code contains the network name and the password in plain text. Anyone who can photograph it can join the network, and they can do it from across the room or from a photo someone else posted.
That is fine for a guest network that is isolated from everything that matters. It is not fine for the network your till, your NAS or your work laptops sit on. If you are printing a Wi-Fi code for customers, put it on a guest network with client isolation enabled, and change the password on a schedule you actually keep.
Bear in mind that a printed code in a public space is readable by everyone who passes, not only by customers.
A vCard QR code embeds every field you filled in — name, phone number, email, postal address, notes — in plain text, permanently, in an image you may hand out widely. There is no way to revoke it once printed.
Put your business contact details in it, not your home address. And remember that a conference badge photographed by a stranger is a contact card they now keep.
Many QR generators route your code through their own domain so they can count scans, change the destination later, or show you an upgrade prompt. That means a third party sits between your code and its destination, sees everyone who scans it, and can break every code you have printed by going out of business or changing their terms.
This tool encodes the exact value shown in the payload box, and that is the only thing the code contains. There is no redirect, no shortener, no scan counter and no analytics. The trade-off is real and worth stating: you cannot change the destination after printing, and you will not get scan statistics. In exchange, your codes keep working regardless of what happens to us, and nobody is logging the people who scan them.
Nothing you type reaches a server. The code is generated in your browser, and you can verify that by watching your browser’s network panel while you use the tool.
Print the destination in readable text next to the code. It costs a line of space and lets people verify the code before scanning — and it is the single most effective defence against sticker-over-code fraud.
Prefer a domain you control and that people recognise. Use https. Keep the destination stable, because printed codes outlive websites.
Check your codes in place, periodically. If someone has covered one with a sticker, you want to be the one who notices.