A QR code hides the boring part
A QR code can contain a website address, plain text, Wi-Fi details, a contact card, or a payment request. It is not automatically dangerous. It is just a compact way to move information from a sign into your phone.
The catch is that the information is hard to read with your eyes. A printed link lets you inspect the website before you open it. A QR code asks you to trust the person who placed it there, or to rely on your phone’s preview of the destination.
The sticker-over-the-real-code trick
A scammer can print a QR code and place it over a real one. Parking meters, restaurant tables, posters, parcel lockers and donation boxes are all plausible targets. The new sticker may look close enough that people scan before they notice it is not part of the original sign.
The replacement can lead to a fake payment page or a page that asks for a login. It does not need a technical hack. It only needs one rushed scan. If a code is on something important, look for a damaged sticker, a mismatched domain, or another way to reach the service yourself.
The QR code that goes through someone else first
Some QR generators do not put your final web address in the code. They put their own address there first, then forward each scan to your destination. That lets the company count scans. It also means your printed code depends on its account and servers.
The awkward version appears later: the service says you need to pay for a plan, renew a subscription, or accept a redirect page to keep a code you already printed working. That is not a property of QR codes. It is a business choice made by the generator.
Payment is where a pause matters most
A payment QR can open a bank page, wallet app, or web form with a recipient and amount. Treat it like a payment request sent by a stranger. Check who receives the money and do not enter card or login details just because the code sits on a familiar object.
For a bill, ticket, or parking session, use the provider’s app or type the known website yourself when you can. If a scan asks for a surprising fee, a password, or an urgent download, close it and start from a route you already trust.
Make codes that do not depend on a middleman
When you make a code, encode the final destination directly. Test it with a second phone before printing it. That keeps the code useful even if the generator disappears, and it avoids handing scan data to an unrelated redirect company.
Sealby’s QR code generator creates direct codes locally in your browser. It does not add a Sealby redirect or tracking layer. That does not make a destination safe by itself; it just means the QR code says exactly what you intended it to say.