Quishing
A blend of "QR" and "phishing" — a scam that hides a malicious link inside a QR code instead of sending it as plain text. See our full explainer on quishing.
Phishing
The broader category quishing belongs to: any attempt to trick someone into giving up credentials, payment details, or personal information by impersonating a trustworthy source. Traditional phishing arrives as email or text links; quishing hides the same tactic inside a QR code.
Smishing
Phishing delivered via SMS text message. Often overlaps with quishing when the text includes a QR code image rather than a plain link.
Threat intelligence
Data collected and maintained by security organizations about known-malicious websites, domains, and files — things like phishing pages, malware distribution sites, and scam infrastructure that's already been identified and confirmed. When CheckThisQR checks a destination, it's comparing that link against this kind of data, not making a judgment call from scratch.
Typosquatting
Registering a domain name that's a slight misspelling or visual near-match of a real one — like "paypa1.com" instead of "paypal.com" — hoping people won't notice the difference at a glance. A common tactic in both quishing and ordinary phishing.
Redirect chain
A sequence of automatic forwards a link goes through before landing on its final destination. Some scams use a redirect chain specifically to obscure the real destination from both automated scanners and a quick human glance at the first URL.
URL shortener
A service (like bit.ly or tinyurl) that turns a long web address into a short one. Legitimate and widely used, but a shortened link hides the real destination completely — you can't tell where it leads just by looking at it, which makes shortened links inside QR codes worth extra caution.
Social engineering
Manipulating someone's trust, urgency, or habits rather than exploiting a technical vulnerability. Quishing is fundamentally a social engineering tactic — it exploits the fact that scanning a QR code feels like a low-stakes physical action rather than a decision worth pausing over.
Threat types (MALWARE, SOCIAL_ENGINEERING, UNWANTED_SOFTWARE)
The specific categories threat-intelligence databases use to classify a flagged destination. "SOCIAL_ENGINEERING" generally corresponds to phishing pages, "MALWARE" to sites that distribute malicious software, and "UNWANTED_SOFTWARE" to sites pushing software that's deceptive or harmful without being outright malware. CheckThisQR checks against all three.
False positive / false negative
A false positive is a safe destination incorrectly flagged as risky. A false negative is a genuinely malicious destination that isn't yet flagged — usually because it's brand new and threat-intelligence databases haven't caught up yet. This is exactly why a "Clear to Scan" result is a strong signal, not an absolute guarantee — see our FAQ for more.
Reach out via our About page and we'll add it.