Spam QR in comment sections
QR codes posted as comment images bypass URL filters that only scan text.

Every QR code in an uploaded image is detected and decoded. The extracted URL is checked against your rules: allowed domains pass, blocked domains are rejected, anything else routed by your policy.
ML detection and URL extraction in a single pass. Multiple QR codes per image handled. Output: a list of URLs to check against your rules.
See Lasso in action
Custom rules applied to every extracted URL. Exact URL match, full-domain match, or pattern match. Your team controls the list.
See Lasso in action
Not every URL fits a rule. AI Moderator reviews the grey area. Combines the URL with account signals and content context to make a smart decision.
See Lasso in action
Human review for the small remainder. Full context: image, URL, AI Moderator notes. Decisions feed back into the system. Recurring patterns become new rules automatically.
See Lasso in action
Lasso finds codes tucked in corners, on stickers, behind watermarks, and several codes in a single frame.
Decoding happens automatically. Every QR code read, URL pulled out, passed to the rule engine. Full content also available for custom workflows.
You define which domains pass, which get blocked, and where everything else routes. Lasso applies the rules to every decoded URL automatically.
Three layers of AI handle the volume, your rules, and the grey areas. Your team only sees what needs them, and every decision they make sharpens the system.
Customizable moderation that lets you find the right balance between safety and user experience. So you protect your community without suppressing the culture that makes it worth joining.
One API. Clear dashboards. A moderation pipeline built around one-click actions and the right context, right where you need it.



QR code moderation detects and decodes QR codes hidden inside uploaded images, then checks the URL each code carries against your rules. It catches links that text filters never see, because the destination is baked into an image rather than typed as text. Allowed domains pass, blocked domains are rejected, and anything in between routes by your policy.
Content moves through four layers. ML detection finds and decodes every QR code in the image and extracts its URL. Custom rules match that URL against the allow, block, and route lists your team controls. The AI Moderator weighs grey-area URLs against account and content signals, and the small remainder reaches a human reviewer with the image, the URL, and the AI Moderator's notes. Roughly 99.9% of decisions are automated, and recurring patterns become new rules.
Detection holds up on codes placed in corners, covered by stickers or watermarks, and on several codes in one frame. The layered pipeline automates around 99.9% of decisions and routes the genuinely unclear cases to human review, so a borderline read is checked rather than guessed. Specific detection-rate figures should be confirmed against current product data before publishing.
Text URL filters only scan the text a user types, so a link encoded in an image slips past them entirely. QR code moderation reads the image itself, decodes the embedded URL, and runs it through the same domain rules you apply elsewhere. That closes the gap users exploit to push contacts, payments, and phishing links off-platform.
QR codes encode URLs rather than language, so detection and URL extraction work the same regardless of the surrounding content's language, and the rules engine runs across Lasso's 200+ supported languages for any accompanying text. It runs through the API and dashboard as part of the four-layer pipeline, so it scales with the rest of your moderation rather than as a separate tool.
Four steps. First, every QR code and its URL are detected. Second, the URL is checked against your rules. Match an allowed domain, it passes. Match a blocked domain, it is rejected or flagged. Edge cases pass to layer three, the AI Moderator. If the AI Moderator is unsure, the QR is passed to layer four, the human moderator.
Lasso extracts the URL and applies your rules. It does not follow the URL to scan the destination. This is deliberate. Your rules are predictable and under your control. Third-party destination categorization can change silently when a vendor updates a model.
Rules are built and edited in the dashboard by your team in minutes. Add URLs or full domains, set the action for each, and they apply automatically. Change a rule, and every subsequent QR code is checked against the new rule.
Yes. For video, see the video moderation feature, which applies the same QR detection and the same URL rules to video frames.
Three verticals get the most value today. Dating: prevent profile-photo QR codes that move conversations off-platform. Marketplaces: prevent listing images from routing buyers to competitor sites. Social: block phishing and spam QR codes that bypass text-based URL filters.
Every QR code in every uploaded image gets decoded and checked against your policy. Connect your first image source through one API.
Book a demo© 2026. All rights reserved.