OpenQR

Security

Last updated: 1 July 2026.

OpenQR is built so there is as little of your data to protect as possible. Every QR code is generated entirely in your browser: the link, text or Wi-Fi password you type never reaches OpenQR's servers. The optional account layer (dynamic codes, the dashboard, the REST API and the MCP server) runs on Cloudflare's edge and is designed to be minimal. The generator is open source, so you can read what it does rather than take these claims on trust.

Reporting a vulnerability

If you believe you've found a security issue, please email security@openqr.uk with enough detail to reproduce it: the affected URL or endpoint, the steps you took, and the impact you believe it has. Please report privately and give us a reasonable chance to fix it before any public disclosure. We aim to acknowledge reports within 72 hours and to keep you updated as we investigate and ship a fix.

There's no paid bug-bounty programme, but we're genuinely grateful for good-faith reports and will happily credit you (with your permission) once an issue is resolved.

Safe harbour

We won't pursue or support legal action against anyone who reports a vulnerability in good faith and in line with this policy. To stay in good faith, please:

  • Only test against your own account, codes and data; never access or modify anyone else's.
  • Stop as soon as you've demonstrated a problem, and don't exfiltrate more data than needed to prove it.
  • Avoid privacy violations, service degradation, data destruction, and disruption to other users.
  • Give us reasonable time to remediate before disclosing publicly.

Out of scope

The following generally aren't things we'll treat as reportable vulnerabilities: volumetric or denial-of-service attacks, spam or social-engineering of our team or users, reports from automated scanners without a demonstrated impact, missing best-practice headers with no concrete exploit, and issues in third-party services we use (report those to the relevant provider). Testing must never involve DoS, mass-mailing, or accessing data that isn't yours.

How OpenQR is secured

  • Static codes never reach a server.They're rendered client-side, so there is no server-side copy of your QR content to leak.
  • No passwords. Accounts use email magic links only, so there is no password database to breach.
  • API keys are stored hashed. OpenQR keeps only a SHA-256 hash of your key, never the raw value, and keys are sent as a Bearer header over HTTPS, never in a URL.
  • Dynamic-code destinations are safety-checked. On create and edit we reject non-public targets (private, internal and loopback hosts, non-http(s) schemes, and short-link self-loops) to keep the redirector from being abused for phishing or SSRF.
  • Rate limits & abuse guards.Code creation is rate-limited per account, and malicious codes can be killed to protect users and the domain's reputation.
  • Edge infrastructure.The account layer runs on Cloudflare Workers with D1 and KV, behind Cloudflare's TLS and network protections (not a home server).
  • Minimal, cookieless analytics. Scan analytics aggregate into counters as each scan happens, so there is no individual scan event to look up: no scanner identifier, no raw IP address, and no town or city named below 5 scans in a window. Raw scan records are pruned after 7 days, and API request logs keep a salted SHA-256 hash of the IP address rather than the address itself. Site analytics run without cookies, which is why there is no consent banner. See our privacy policy.

Open source

The OpenQR generator's code is public. To check exactly how client-side generation works, or to run your own copy, read the source on GitHub. What is and isn't published, and under which licence, is set out on our open source page.