Last checked: September 2026 · Every claim below comes from the maker's own documentation or app listing, linked at the bottom. Vendors change things — tell us if something here is out of date.
The short version
| Tool | What it is | Best for |
|---|---|---|
| susQR | Free web checker, no account | A code you didn't expect, especially in email or on a computer |
| Phone camera | A decoder, not a checker | Codes you already trust |
| Trend Micro QR Scanner | Free phone app | Checking every scan automatically on your phone |
| Kaspersky Secure QR Scanner | Feature of Kaspersky for Android, in the free tier | People already running Kaspersky on Android |
| Bitdefender Scamio | Free scam-advice chatbot, account needed | Talking through a whole suspicious message |
| Is This QR Safe? | Free web checker, no account | The same job as susQR; our closest match |
| VirusTotal | Free URL and file analysis service | Technical users who already have the link |
Feature by feature
Scroll sideways on a phone to see every column.
| What matters | susQR | Phone camera | Trend Micro | Kaspersky | Scamio | Is This QR Safe? |
|---|---|---|---|---|---|---|
| Works with no install | Yes | Built in | App required | App required | Yes | Yes |
| Works with no account | Yes | Yes | Yes | Yes | Sign-in needed | Yes |
| Cost | Free | Free | Free | Free tier | Free | Free |
| Works on a computer | Yes | No | Phone only | Android only | Yes | Yes |
| Checks a code in a screenshot or PDF | Yes | No | Varies | Varies | Yes | Yes |
| Checks the link before you visit | Yes | No | Yes | Yes | Yes | Yes |
| Number of opinions consulted | 90+ vendors, plus 6 other sources | None | Trend Micro's own | Kaspersky's own | Bitdefender's own | 70+ vendors |
| Shows every redirect hop | Yes | No | Not shown | Not shown | Not shown | Follows them |
| Opens the page in a sandbox first | Yes, with a screenshot | No | No | No | No | Not stated |
| Checks how old the domain is | Yes | No | Not stated | Not stated | Part of its advice | Yes |
| Plain-language verdict | Yes, details on request | n/a | Safe / dangerous / unverified | Warns on bad links | Conversational | Shows engine verdicts |
| Checks every scan automatically | No, you bring the code | Nothing to check | Yes | Yes | No | No |
| Protects the rest of the device | No | No | Scanner only | Yes, full mobile suite | No | No |
"Not stated" means the maker doesn't describe that feature in its own documentation, not that it definitely doesn't exist. "Varies" means it depends on the version and platform.
What each one actually does
Your phone's camera
It decodes the code and shows the address, usually shortened, then opens it when you tap. Nothing is checked at the moment you scan. Safari's Fraudulent Website Warning and Chrome's Safe Browsing can stop a page that is already on a block list, but that happens after the browser starts loading it, and a scam page registered this morning is usually on no list yet. This is the gap every tool below exists to fill. We go through it in more detail in susQR vs your phone camera.
Trend Micro QR Scanner
A free standalone app for Android and iOS that scans with the camera and checks the address against Trend Micro's website reputation database, then labels it safe, dangerous or unverified and blocks the dangerous ones. It is free, has no ads, and the check happens on every scan with no extra step. The trade-offs: you have to install it and remember to use it instead of the camera, it is one company's verdict rather than several, and "unverified" — which is what a brand-new scam page usually gets — leaves the decision back with you.
Kaspersky Secure QR Scanner
Not a separate app but a feature inside Kaspersky for Android, included in the limited free version. It decodes QR codes and barcodes, checks links against the Kaspersky Security Network cloud service, marks dangerous ones in red, and handles other code types too: contact cards, Wi-Fi joining details, phone numbers. It will refuse to save a contact card whose fields contain phishing links, which is a genuinely good touch. Same trade-offs as Trend Micro, plus it is Android-only, and you are installing a full security suite to get it. If you already run Kaspersky on Android, this is free and already there — use it.
Bitdefender Scamio
A free chatbot you can reach on the web, WhatsApp, Messenger or Discord. You paste a message, a link, or a screenshot — including one with a QR code in it — and it tells you whether it looks like a scam and what to do. It is the most flexible of the group, because it handles the whole message rather than just the link, and it explains its reasoning in conversation. It asks you to sign in with a Bitdefender account first, it is a general scam adviser rather than a purpose-built QR pipeline, and it does not show you a redirect chain or a list of which security vendors flagged what.
Is This QR Safe?
The closest thing to susQR: a free web checker with no sign-up that takes a camera scan, an upload or a pasted image, follows the shorteners and redirects, and reports VirusTotal verdicts from more than 70 reputation engines, flagging newly registered domains and pages that trigger downloads or payments. It is a good tool and it does the core job well. The differences are in how many independent sources get asked, whether the page is visited in a sandbox, and how the answer is written — covered below.
VirusTotal
The service behind the "90+ vendors" figure that susQR and others quote. You can paste a URL and get every vendor's verdict, free. But it will not decode a QR code for you — uploading a photo of one analyses the image file, not the link inside it — so you need the address first, which is the hard part. The output is built for analysts: dozens of vendor names, no plain-language answer.
Where susQR wins
- Several independent opinions, not one. Every scan asks VirusTotal's 90-plus vendors, Google Safe Browsing, the Cloudflare and Quad9 DNS filters, URLhaus, PhishTank's verified-phish feed, and public domain registration records for the site's age. Vendors disagree, and a scam page that one has never seen is often already known to another.
- We visit the page so you don't have to. susQR can open the destination inside urlscan.io's sandbox and show you a screenshot of what is actually there. No other tool in this comparison advertises that.
- You see the whole journey. Most scam links travel through a shortener or two. susQR shows each hop and names the domain you would actually land on — the difference between "w-mt.co" and "walmart.com" is the entire point.
- The answer is written for a person, not an analyst. One sentence at the top: open it, or don't. The vendor counts, the DNS results, and the score breakdown are there when you want them, one tap away, not in your face.
- It works where the codes actually arrive. Over two-thirds of business QR phishing lands in email, read on a computer. A phone app cannot help with a code sitting in your inbox; susQR takes a screenshot upload on any device.
- Nothing to install, no account, no phone number. Useful on a work laptop where you cannot install software, and on someone else's phone when they ask you to look at something.
- We show our working. Every score comes with the reasons that produced it, and the scoring method is published.
- Local context. The scam map and the city pages show where malicious codes are turning up, built from sourced incidents and reports from people who found them.
Where the others win
If this section were empty you should not trust the rest of the page.
- They check every scan; we check the ones you bring us. Trend Micro and Kaspersky sit between the camera and the browser on every single scan. susQR asks you to take a picture and come to the site, and a tool you have to remember is a tool you will sometimes forget.
- An app protects the whole phone. Kaspersky's suite also handles malware, dodgy Wi-Fi, nuisance calls and permissions. susQR checks links. It is not antivirus and will not replace it.
- They work offline; we need a connection. Every check we run is a live lookup. A phone app's cached verdicts still work on a plane.
- Scamio handles the whole story. A QR code is often only part of a scam message. Scamio reads the whole thing, asks questions, and gives advice. We only answer for the link.
- Your camera is faster. For the menu at a restaurant you have been to fifty times, the camera is the right tool. Checking everything is not the goal; checking the unexpected is.
- We carry ads and affiliate links. Trend Micro's scanner has neither. Ours keep the scanner free with no account and no data selling — our privacy page is explicit about the trade — but it is a real difference.
Which should you use?
- A QR code in an email, a text, or a PDF → a web checker. Screenshot it and upload; never scan it with the phone you read it on. See QR phishing emails.
- A sticker on a parking meter, menu, or poster → check it before paying, and look at whether the sticker sits on top of another code first.
- You scan codes constantly for work → install a checking app so it happens without thinking, and keep a web checker for the odd ones.
- You already run a mobile security suite → turn its QR scanner on. It costs nothing extra.
- Something feels wrong but it's more than a link → a scam-advice chatbot, or our guide to QR scam texts.
Try it against whatever you use now
Take a picture of a QR code and run it through susQR. You will see the real destination, every redirect on the way, and what each check found — in about a second, with nothing to install.
Sources
- Kaspersky: Secure QR Scanner and what the limited free version includes
- Trend Micro: QR Scanner — Safe QR Code Reader listing
- Bitdefender: Scamio
- Is This QR Safe?: isthisqrsafe.com
- VirusTotal: virustotal.com
- susQR: how our scoring works and what we run on every scan