Current Doc

QR URL Extractor

Use Browse Docs to switch sections and search the full docs list.

Documentation

Blue Lantern Security Docs

Learn how to use the marketplace, run security tools, and integrate via the API.

QR URL Extractor

Decode QR codes from images entirely in your browser, with a one-click handoff to the URL Threat Analyzer.

The QR URL Extractor extracts the embedded text or link from a QR code image. The image never leaves your device, decoding happens locally in the browser. If the decoded value looks like a URL, you can send it straight to the URL Threat Analyzer to render the page in a sandbox before clicking.

Why It Exists

Mobile-first phishing is increasingly delivered via QR codes ("quishing") in printed materials, email attachments, and chat screenshots. Pointing a phone camera at the code is exactly what attackers want you to do. This tool lets analysts and end users decode the QR safely from a screenshot, see the underlying URL in plain text, and then optionally detonate it in our sandbox before any device renders it.

What It Does

  • Local Decoding - The image is decoded entirely in the browser using the zxing library, with the browser's built-in BarcodeDetector (when supported) used to accelerate detection. Nothing is uploaded to Blue Lantern Security or any other server.
  • Smart Scan - Automatically retries multiple upscales and a sliding-window grid of crops, which dramatically improves decode rates on phone-camera photos taken in the wild where the QR is small, off-axis, or has glare.
  • Standard and Inverted QRs - Handles both light-on-dark and dark-on-light QR codes.
  • URL Detection - Recognizes when the decoded payload is a URL (or a bare domain) and offers a direct handoff to the URL Threat Analyzer.
  • Copy to Clipboard - One-click copy of the decoded text for pasting into other tools or tickets.

File Requirements - Image formats: PNG, JPG, GIF, WEBP, BMP. Maximum file size: 10 MB. Images stay on your device.

How to Use

  1. Navigate to the QR URL Extractor page.
  2. Provide the QR image in any of three ways:
    • Drag and drop an image onto the upload area.
    • Paste an image from your clipboard (useful for screenshots).
    • Click "Select Image" to browse for a file.
  3. The scanner decodes the image in your browser. If a QR is found, the decoded text appears in a code block below the preview.
  4. If the decoded value is a URL, click Analyze with URL Threat Analyzer to send it directly to the URL Threat Analyzer for sandboxed rendering and phishing checks. The URL will be pre-filled on the next page, so you can review it before submitting.
  5. Otherwise, use Copy to grab the decoded text, or Scan another to start over.

Trouble decoding? For wild photos, try cropping closer to the QR, reducing glare, or holding the camera parallel to the code before re-uploading. The smart-scan grid will handle most cases, but extremely low resolution, heavy motion blur, or partially obscured codes will still fail.

Cost

This tool is free. There is no API integration because the decoding runs entirely on your device, no Blue Lantern Security infrastructure is involved until you choose to detonate a decoded URL.

Need Help?

Can't find what you're looking for? Reach out and we'll get back to you.

Contact Support