sniffQR: Scan Smart, Stay Safe автор Apogaeum Labs
Know what is in a QR code before you act on it. Private by design.
Метадані розширення
Знімки екрана
Про це розширення
sniffQR shows you what is really inside a QR code before you act on it,
and tells you honestly when it cannot be sure.
SNIP IT, UPLOAD IT, OR PASTE IT
Drag a box around any QR code on a page. If your selection catches more
than one code, sniffQR highlights the one nearest the center and waits
for your tap. It also takes an uploaded image, a copied image, or a
copied link or text. No camera needed.
NOTHING IS CHECKED UNTIL YOU SAY SO
Every local check runs first, with zero traffic to any threat service.
Then sniffQR shows you the URLs and asks which ones may be checked.
Nothing reaches a third-party service until you have seen it and ticked
it.
PRIVATE BY DESIGN
No accounts, no servers, no analytics, no ads. The extension keeps no
history at all: one result, read and gone. Your API key stays in your
browser's local storage and is never synced by us or sent to us.
THE LOCAL DETECTION ENGINE RUNS RIGHT HERE
No key, no account, no network needed. sniffQR reads the payload and its
URLs for look-alike characters, brand impersonation, hidden characters,
harmful file types, shell commands and the user@host trick, among
others. Then it names what it found, in plain English.
SOME OF THOSE LETTERS ARE LYING TO YOU
A Cyrillic "а" looks exactly like a Latin "a". sniffQR detects
look-alike characters across six scripts, names each finding down to the
exact Unicode character, and shows you the real punycode address next to
what you saw.
IT WOULD RATHER SAY IT DOES NOT KNOW
Four verdicts: Safe, Potentially Suspicious, Likely Malicious, and
Unknown. A Safe verdict requires a threat-intelligence service to have
actually said so. No check means Unknown, never Safe. Every non-Safe
verdict explains itself in plain English.
REDIRECTS, HONESTLY
Following redirects is on by default and can be turned off in the
options page. A browser shows an extension only the entry and final URL
of a chain, so sniffQR says "via redirect chain" rather than claiming
hop counts it cannot know. The sniffQR apps show every hop.
THREAT INTELLIGENCE, WITH YOUR KEY
Google Web Risk works with your own API key, off by default. VirusTotal,
custom threat feeds and the offline database are app features: a browser
extension cannot hold an offline threat database, and it says so instead
of pretending.
ELEVEN PAYLOAD TYPES
URLs, Wi-Fi, contacts, email, phone, SMS, geo, crypto, 2FA, calendar and
plain text, each with its own result card - including Open in Wallet for
bare crypto addresses. The extension does what a browser can do and does
not pretend to do the rest; the apps add the native actions.
THE APPS
The Android and iOS apps add the camera, scan history, offline scanning,
VirusTotal, custom threat feeds and more, for one payment, never a
subscription.
Requires Firefox 115 or newer. Also available for Chrome and Edge.
and tells you honestly when it cannot be sure.
SNIP IT, UPLOAD IT, OR PASTE IT
Drag a box around any QR code on a page. If your selection catches more
than one code, sniffQR highlights the one nearest the center and waits
for your tap. It also takes an uploaded image, a copied image, or a
copied link or text. No camera needed.
NOTHING IS CHECKED UNTIL YOU SAY SO
Every local check runs first, with zero traffic to any threat service.
Then sniffQR shows you the URLs and asks which ones may be checked.
Nothing reaches a third-party service until you have seen it and ticked
it.
PRIVATE BY DESIGN
No accounts, no servers, no analytics, no ads. The extension keeps no
history at all: one result, read and gone. Your API key stays in your
browser's local storage and is never synced by us or sent to us.
THE LOCAL DETECTION ENGINE RUNS RIGHT HERE
No key, no account, no network needed. sniffQR reads the payload and its
URLs for look-alike characters, brand impersonation, hidden characters,
harmful file types, shell commands and the user@host trick, among
others. Then it names what it found, in plain English.
SOME OF THOSE LETTERS ARE LYING TO YOU
A Cyrillic "а" looks exactly like a Latin "a". sniffQR detects
look-alike characters across six scripts, names each finding down to the
exact Unicode character, and shows you the real punycode address next to
what you saw.
IT WOULD RATHER SAY IT DOES NOT KNOW
Four verdicts: Safe, Potentially Suspicious, Likely Malicious, and
Unknown. A Safe verdict requires a threat-intelligence service to have
actually said so. No check means Unknown, never Safe. Every non-Safe
verdict explains itself in plain English.
REDIRECTS, HONESTLY
Following redirects is on by default and can be turned off in the
options page. A browser shows an extension only the entry and final URL
of a chain, so sniffQR says "via redirect chain" rather than claiming
hop counts it cannot know. The sniffQR apps show every hop.
THREAT INTELLIGENCE, WITH YOUR KEY
Google Web Risk works with your own API key, off by default. VirusTotal,
custom threat feeds and the offline database are app features: a browser
extension cannot hold an offline threat database, and it says so instead
of pretending.
ELEVEN PAYLOAD TYPES
URLs, Wi-Fi, contacts, email, phone, SMS, geo, crypto, 2FA, calendar and
plain text, each with its own result card - including Open in Wallet for
bare crypto addresses. The extension does what a browser can do and does
not pretend to do the rest; the apps add the native actions.
THE APPS
The Android and iOS apps add the camera, scan history, offline scanning,
VirusTotal, custom threat feeds and more, for one payment, never a
subscription.
Requires Firefox 115 or newer. Also available for Chrome and Edge.
Rated 0 by 0 reviewers
Permissions and data
Необхідні дозволи:
- Отримувати дані з буфера обміну
Необов'язкові дозволи:
- Отримувати доступ до ваших даних для всіх вебсайтів
Data collection:
- The developer says this extension doesn't require data collection.
Більше інформації
- Версія
- 1.0.0
- Розмір
- 369,57 КБ
- Востаннє оновлено
- 4 дні тому (3 жовт 2026 р.)
- Пов'язані категорії
- Ліцензія
- Усі права захищені
- Політика приватності
- Ознайомитись з політикою приватності для цього додатка
- Історія версій
- Додати до збірки