Is a QR code generator safe?

The one thing a QR code can do

A QR code is just a picture of text. Scanning it reads the text out of the picture and hands it to whatever handles that kind of text: a URL opens a browser, a phone number opens the dialer, a WiFi payload opens a join-network prompt. That is the entire list. A code cannot install software, read your contacts, or move money by itself — the risk was always in the destination a code points at, not in the encoding.

Which is why "is a generator safe" is really two questions: what does this site do with what I type, and what does the resulting code point at. The first is a question about architecture. The second is a question about your own judgement about the link.

Six things worth checking

1

Does it ask you to create an account?

Not a hard rule, but a strong signal. An account means a server, a database, and a record of what you typed. For generating a code, none of that is necessary — which is why a tool that does it without an account is doing less with your data.

2

Does anything leave your browser?

Open the page and watch the network tab while you type a WiFi password. A generator that works entirely client-side makes no request containing what you typed. That is the whole architecture, not a policy promise.

3

What can a QR code actually make a phone do?

Three things: open a URL, dial a number, or join a WiFi network. A code cannot install an app, read your contacts, or move money. Scanners cannot execute arbitrary code — they hand the decoded text to the relevant app.

4

Is it asking for a payment card?

Never, for generating a code. If a "free QR generator" wants card details before showing you a code, it is not a generator.

5

Where does the destination lead?

The generator is only half the question. A perfectly safe generator can produce a code pointing at anything you were convinced to type. The real risk is always the destination, not the encoder.

6

Does it hide what the code contains?

A good generator shows you the encoded text and offers a preview before download. Ours shows the exact payload as it goes into the pattern — you can read it and confirm it says what you typed.

How this site handles it: there is no account, no server-side code path, and no network request containing your input. The generator, the encoder, and the image exporter all run in your browser tab. The privacy page says the same thing in more detail, and it is checkable — open the network tab and look.

Warnings worth refusing outright

Some things are not judgement calls. A QR code sticker pasted over a parking meter asking you to scan and "pay the fine" is fraud, full stop. So is a code on an email attachment that asks you to "confirm your delivery". Both use the format's innocence to borrow its credibility.

The pattern to notice: the code is unexpected. It appeared where an address should be, or in a channel nobody sends links through. A code printed on the menu at the cafe you are sitting in is not surprising; a code in an invoice email is.

What about the codes you did not make

Scanning is always a decision about a destination. Before you act on a scanned code, look at the URL that appeared in your browser's address bar rather than tapping straight through. Look for the real domain, not a lookalike with one character swapped, and be suspicious of anything asking for a password on a page you reached by scanning rather than by typing.

Phone cameras show a preview of the link before opening it. That preview is the cheapest safety tool you have — and most people skip it, which is exactly what these attacks rely on.

A note on what "safe" can mean here

We can tell you precisely what this site does with your input: nothing. We cannot tell you that the code you are about to print points somewhere good — that depends entirely on the URL you type into the form. Generating the code safely and scanning the right destination are two separate problems, and conflating them is how people talk themselves into bad clicks.

Try it and check

Type something, then open your browser's network tab — you will see no request carrying it.

Open the generator

Questions about QR generator safety

Can a QR code install a virus on my phone?

Not directly. A code carries text, and text cannot execute. A code that leads to a download page is a different question — that is the page asking, not the code. Never sideload an app from a link.

Are free QR generators less safe than paid ones?

Not inherently. Safety follows architecture: does your input leave the browser, and is anything collected? Plenty of paid tools ask for an account and store your codes; plenty of free ones do neither.

Is it safe to scan a QR code at a restaurant?

Generally yes. Check that it is part of the printed material you were given rather than a loose sticker over someone else's code, and glance at the URL that appears before opening it.

Does this site store the codes I make?

No. There is no database and no upload. Closing the tab discards everything the page was holding.

Why is a WiFi password in a QR code considered risky?

Because it is readable by anyone who photographs the card. The risk is the printed artifact, not the generator — and it is why the password belongs on a guest network.