TECHNICAL SPECIFICATION

How SaferScans Works

A deep dive into our client-side scanning pipeline, security inspection engine, and privacy model.

The scanning pipeline

SaferScans uses jsQR, a pure-JavaScript QR code reading library, to decode QR codes entirely in your browser. No server, no cloud, no telemetry.

Camera mode

Captures frames from your device camera via the MediaDevices API and processes them through jsQR at ~30fps.

File upload

Draws the image onto an offscreen <canvas>, extracts pixel data, and passes it to jsQR for decoding.

Clipboard paste

Listens for paste events (Ctrl+V / Cmd+V) and processes clipboard images identically to file uploads.

Camera → Canvas → ImageData → jsQR → decode → SafetyEngine → ResultCard

The Safety Preview Engine

Every decoded URL is passed through a multi-step analysis pipeline before being shown to the user. Nothing opens automatically.

  1. Scheme validation

    Blocks javascript:, data:, and vbscript: schemes outright. Flags non-HTTPS links as unencrypted. Warns on unusual schemes.

  2. Apex domain extraction

    Parses the hostname using the URL API, extracts the apex (eTLD+1) domain, and visually separates it from subdomains and path parameters in the Safety Card.

  3. Homograph detection

    Runs a regex check on the hostname for any non-ASCII (code point > 127) characters. Flags Cyrillic look-alikes that imitate Latin letters (e.g., а, е, о).

  4. Link shortener detection

    Checks the apex domain against a known list of 20+ link-shortening services (bit.ly, t.co, tinyurl.com, etc.) and warns the user if the true destination is hidden.

  5. IP address detection

    Flags URLs using a raw IPv4 address (e.g., http://192.168.1.1/login) — a common pattern in phishing attacks.

  6. Keyword heuristics

    Applies lightweight heuristics for suspicious keyword patterns (login, verify, account, etc.) combined with subdomain usage.