About to scan a menu code? ScanLikely shows you the destination first, so a swapped sticker cannot catch you out.

Check that menu code (iPhone) Check that menu code (Android)

Most restaurant QR menus are exactly what they claim to be. The risk is not that QR menus are inherently dangerous, it is that the code sits on a table at arm's height where anyone who sits down can cover it with a sticker. That takes seconds and nobody notices, because a QR code on a restaurant table is the least suspicious object in the room.

So the useful question is not "are QR menus safe" but "is this particular code the one the restaurant put there." Here is how to answer that quickly, plus what a menu code should and should not ask you for.

The quick check

  1. Feel the edges. Most table codes are printed on a laminated card, a table tent, or directly onto the table. A paper sticker applied on top usually has a lip you can catch with a fingernail. That is the single most reliable tell.
  2. Compare with the next table. Restaurants print these in batches. If your code is a different size, a different shade, or the only one with a sticker on it, ask a member of staff.
  3. Read the link before it opens. It should go to the restaurant's own site, or to a menu platform whose name you can see plainly. A link shortener or a domain that has nothing to do with the restaurant is a reason to stop.
  4. Just ask for a paper menu. No explanation required, and it takes less time than any of the above.

What a menu code should never ask for

This is the clearest line, and it is worth knowing before you sit down. A menu is a document. Reading it requires nothing from you.

  • A login or an account. You should never need to sign in to read what is for dinner.
  • Card details up front. Payment happens at the end, through the restaurant's own system or a member of staff. A menu that wants a card before you have ordered is not a menu.
  • An app install. Especially one offered as a direct download rather than through the App Store or Google Play. Decline it.
  • Permissions. A menu page has no reason to want your location, your camera, or your contacts.
  • Personal details to "unlock" the menu. Name, email, and phone number in exchange for a PDF is at best aggressive marketing and at worst harvesting.

Paying at the table through a code the server brings you is normal and generally fine. The distinction is that a payment code arrives with a person at the end of the meal, rather than sitting unattended on the table all day.

What the scam actually looks like

Two versions are common. In the first, the sticker leads to a page that imitates a payment or ordering system and asks for card details to "start your order," which is simply theft. In the second, it leads to a page that mimics a popular delivery or loyalty service and asks you to log in, which harvests an account that can then be used to place orders on your card.

A third, less common version pushes an app install outside the official stores. That is the only variant with any real chance of affecting the phone itself, and it still requires you to approve the install and override a warning to do it.

What to do if you already scanned one

Scanning does not hurt you. What you did next might.

  • You looked at a menu and closed it. Nothing to do.
  • You entered card details. Call your bank or card issuer, report fraud, and have the card frozen or reissued. Then tell the restaurant, so they can find and remove the sticker.
  • You logged into a delivery or loyalty account. Change that password, sign out all sessions, and check the account for saved cards, new delivery addresses, or recent orders you did not place.
  • You installed something. Remove it and restart the phone.
  • Tell the staff either way. They usually have no idea, and they are the only ones who can take the sticker off before the next table sits down.

How restaurants can reduce the risk

If you run the place rather than eat in it, a few cheap changes remove most of the exposure: print codes directly onto laminated menus or table surfaces rather than using stickers, use a domain customers can recognize as yours, check the tables during setup the same way you check for cleanliness, and make sure staff know that a menu code should never ask a guest to log in or pay before ordering. A short line on the menu telling customers what your real domain looks like also helps.

Frequently asked questions

Are restaurant QR code menus safe?

Generally yes. The realistic risk is a sticker placed over the genuine code, not the concept itself. Check for a raised edge and confirm the link matches the restaurant.

Should a QR menu ask me to log in?

No. Reading a menu should require nothing from you. A login request is the clearest sign you are not looking at a menu.

Is it safe to pay through a QR code at a restaurant?

Paying through a code a member of staff hands you is normally fine. Be more careful with a code that has been sitting unattended on the table, since that is the one anyone could have covered.

What if the menu asks me to download an app?

Decline. If a restaurant genuinely has an app, find it in the App Store or Google Play yourself rather than through a link on a table.

How do I know the link is the real restaurant?

The domain should be recognizably the restaurant's, or a menu platform named plainly. Read the last part of the domain before the first single slash, since that is the part that determines where you actually go. Our guide to checking any QR code covers this in more detail.

Not sure if a QR code is safe? Check it before you tap.

ScanLikely scans the code and warns you before it opens anything sketchy, links, fake payment pages, rogue WiFi, and more. Free on iPhone and Android.

Check a QR code
before you tap it

Get the app Get the app