Skip to content
Calixo

QR Code Scam Risk Calculator

Score the situation around a QR code you scanned or received — where it came from and what it asked for — against common 'quishing' scam patterns.

Inputs

Paste this into any page — the widget stays live and updates automatically as this calculator improves. Using WordPress or Notion? See the embed guide.

Saved Scenarios

— select 2+ to compare
Inputs updated · Results recalculated · Just now

QR Code Risk Score

0

QR Code Scam Risk

Safe

SafeSuspiciousLikely ScamHigh RiskCritical

Risk Level

Safe

Recommendation

No major red flags detected in the situation described — still preview the link before entering any information.

Spark says

How it's calculated

What is the QR Code Scam Risk Calculator?

This scores the situational red flags around a QR code — where it came from and what scanning it asks you to do — since no static website can safely decode an actual QR image without a backend service to do that processing. Instead, this focuses on the context, which is where most real quishing (QR phishing) scams are actually caught.

Use this before scanning an unfamiliar QR code, or right after scanning one, before entering any payment or login information at the page it opens.

How to use it

  1. 1 Answer the 5 questions about where the QR code came from and what happened when you scanned or previewed it.
  2. 2 Read the resulting risk score and recommendation.
  3. 3 If your phone shows a link preview before opening a scanned QR code, read it carefully before tapping through — most quishing red flags are visible right there.

Understanding QR Code Scam Risk Calculator

'Quishing' — QR code phishing — has grown as a scam category specifically because it exploits a gap in how people evaluate risk: most of us have learned some caution around clicking suspicious links, but a QR code obscures the destination URL entirely until after you've already scanned it, resetting that caution to zero at exactly the moment it matters most.

The parking meter variant is among the most reported physical-world versions: a scammer prints a sticker matching the visual style of a city's real parking payment QR code and places it directly over the legitimate one. Someone parks, scans what looks like the normal payment code, and enters card details on a fake site designed to look identical to the real payment app or website. Cities including several major US metros have issued public warnings about exactly this pattern, and the giveaway is often physical — a sticker that looks slightly misaligned, a different texture or gloss than the surrounding sign, or simply a QR code somewhere a city's real signage has never had one before.

The unsolicited-message variant works differently: a QR code arrives by text or email — sometimes claiming to be a package delivery issue, a failed payment, or a 'security alert' — precisely because these urgent-sounding contexts discourage the pause that would otherwise prompt someone to check a link carefully. Because QR codes bypass the visual link-preview scrutiny people have learned to apply to typed URLs, this format has become a deliberate way to route around exactly that learned caution.

What makes quishing genuinely different to defend against, compared to a suspicious link in an email, is that the natural moment to catch it — before scanning — offers no visible information at all. The defense has to shift to two other moments instead: evaluating the situation before scanning (does a parking meter usually have a QR code here? did I expect this text?), and reading the link preview your phone shows immediately after scanning, before actually opening the page. Nearly every modern phone camera app shows this preview by default, and it's the single highest-value habit for catching quishing attempts, since it surfaces exactly the information — the actual destination domain — that the QR code was hiding.

None of this requires decoding the image itself in advance; the situational red flags (where it came from, what it's asking you to do) are visible before you ever need to scan anything, which is exactly what this calculator focuses on.

Worked examples

Advantages

  • Covers the situational pattern — public/physical placement, unexpected sender, payment or login request — that distinguishes most reported quishing scams from routine, expected QR code use (menus, event check-in, Wi-Fi).
  • Runs entirely in your browser — nothing you enter is sent anywhere.
  • Doesn't require uploading or scanning an actual QR image, so it works from memory or description just as well as in the moment.

Limitations

  • This can't decode or analyze an actual QR code image — that requires camera or file-upload processing this static tool intentionally doesn't do. Use your phone's built-in camera preview (most show the destination link before opening) as the actual scan step.
  • A low score doesn't guarantee safety — always read the link preview your phone shows before a QR code opens, regardless of the situational score.
  • This is a heuristic screening tool, not a definitive determination.

Common mistakes

  • ⚠️ Scanning a QR code sticker placed over a parking meter's original code without checking whether it looks freshly applied or slightly misaligned — a strong sign it was added later.
  • ⚠️ Entering payment details on the page a QR code opens without checking that the URL matches the venue's actual, known domain.
  • ⚠️ Assuming QR codes are inherently safer than links because 'you can't type them wrong' — the opposite is often true, since a QR code hides the actual URL from casual scrutiny until your phone shows a preview.
  • ⚠️ Scanning a QR code sent unexpectedly by text or email and immediately opening the link without reading the preview URL first.

Tips

  • 💡 Always read your phone's link preview before tapping through on a scanned QR code — this is shown by default on most modern phone cameras.
  • 💡 For parking meters or public payment QR codes, use the venue's official app or a number you look up independently instead, if you have any doubt about the sticker's authenticity.
  • 💡 Never enter a password on a page reached through a QR code unless you're certain of the destination — treat it with the same caution as a link in an unexpected text.
  • 💡 If you find a QR sticker that looks tampered with on a parking meter or public sign, report it to the venue, city, or parking authority.

Real-life uses

  • Checking a QR code sticker on a parking meter before paying
  • Evaluating a QR code included in an unexpected text or email
  • Screening a QR code flyer posted in a public place
  • Deciding whether to scan a QR code handed to you by a stranger at an event

Frequently asked questions

Can this calculator scan or decode an actual QR code image?

No — that requires camera or image processing this static, client-side tool doesn't do. Use your phone's built-in camera, which shows a link preview before opening, as the actual scanning step.

Are QR codes at parking meters actually being used for scams?

Yes — multiple US cities have issued public warnings about fraudulent stickers placed over legitimate parking meter QR codes.

Is it safe to scan a QR code if my phone shows a preview link first?

Reading that preview carefully is one of the best defenses — check that the domain matches what you'd expect before tapping through, especially for any payment or login page.

What should I do if I already entered payment info on a fake QR code site?

Contact your bank or card issuer immediately to dispute the charge and monitor for further unauthorized use.

Why does 'unsolicited text or email' score as risky as a stranger handing you a code?

Both remove your ability to verify who actually created the QR code, which is the core risk factor this checklist scores.

Sources & references