The scanning pipeline
SaferScans uses jsQR, a pure-JavaScript QR code reading library, to decode QR codes entirely in your browser. No server, no cloud, no telemetry.
Camera mode
Captures frames from your device camera via the MediaDevices API and processes them through jsQR at ~30fps.
File upload
Draws the image onto an offscreen <canvas>, extracts pixel data, and passes it to jsQR for decoding.
Clipboard paste
Listens for paste events (Ctrl+V / Cmd+V) and processes clipboard images identically to file uploads.
Camera → Canvas → ImageData → jsQR → decode → SafetyEngine → ResultCardThe Safety Preview Engine
Every decoded URL is passed through a multi-step analysis pipeline before being shown to the user. Nothing opens automatically.
Scheme validation
Blocks javascript:, data:, and vbscript: schemes outright. Flags non-HTTPS links as unencrypted. Warns on unusual schemes.
Apex domain extraction
Parses the hostname using the URL API, extracts the apex (eTLD+1) domain, and visually separates it from subdomains and path parameters in the Safety Card.
Homograph detection
Runs a regex check on the hostname for any non-ASCII (code point > 127) characters. Flags Cyrillic look-alikes that imitate Latin letters (e.g., а, е, о).
Link shortener detection
Checks the apex domain against a known list of 20+ link-shortening services (bit.ly, t.co, tinyurl.com, etc.) and warns the user if the true destination is hidden.
IP address detection
Flags URLs using a raw IPv4 address (e.g., http://192.168.1.1/login) — a common pattern in phishing attacks.
Keyword heuristics
Applies lightweight heuristics for suspicious keyword patterns (login, verify, account, etc.) combined with subdomain usage.