7967c36a11fc66c757dea2bdbfb16163b6bc53d8
editUser() let a super user submit any type for any target, including themselves - accidentally downgrading your own account could lock you out of admin functions. Self-edits now keep the existing type regardless of what was submitted; the type radios are disabled in the UI for that case with an explanatory note. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Fo3DiRRpmz2DXjD7Uzhc8u
Self-hosted, open-source QR code generator.
QRForge creates and manages static and dynamic QR codes from a clean, responsive control panel. It's a security-hardened, actively maintained fork of the original PHP Dynamic Qr code project by Giandonato Inverso, built on AdminLTE.
- Try it free: qr.ensembia.com - fully functional OSS test
instance. Self-service signup isn't live yet, so log in with the temporary shared demo
account
admin/adminin the meantime. - Commercial VIP edition (self-service create-rights, logo-embedded QR codes): www.qrforge.eu.
- Self-host it yourself: this repository, MIT-licensed.
Features
- Dynamic QR codes with a database-backed URL shortener
- Create, edit, delete, enable/disable the redirect
- Download any time, bulk download/delete
- Batch-generate from a CSV file
- 16 static QR code types: Text, Email, Phone, SMS, WhatsApp, Skype, Location, vCard, Event/calendar, Bookmark, WiFi (incl. WPA3), PayPal, Bitcoin, 2FA, App Link (Android intent / universal links), Bluetooth
- QR code styling: 6 export formats, foreground/background color, 4 precision levels, 10 sizes, optional label text below the code (custom font + size), optional icon shown above the code, save/load your own style presets
- Address search (OpenStreetMap Nominatim) for Location QR codes
- Built-in QR scanner (camera or image upload, decodes entirely client-side)
- Installable as a PWA
- Role-based access:
super(full access + user management),admin(scoped to their own codes and sub-users),user(read-only, with optional per-account create rights and view toggles set by an admin) - Dashboard with QR/scan statistics and a 7-day activity chart
- CSRF protection, login rate limiting, session hardening, audit log
- Docker Compose setup, both a dev image and a production Nginx + PHP-FPM image
What is included
- PHP 8.4 application source
- Database schema + migrations
- Docker Compose files (dev and production)
- CSS/JS assets
Setup with Docker Compose
- Clone this repository.
- Copy
.env.exampleto.envand set a realDATABASE_PASSWORD/MYSQL_ROOT_PASSWORD. - Start the stack:
docker compose up -d --build - Open
http://localhostand log in withsuperadmin/superadmin. You'll be required to set a new password on first login.
For a production deployment behind a reverse proxy, use
docker-compose.prod.yml (Nginx + PHP-FPM) instead of the dev stack.
Credits
- Originally forked from PHP Dynamic Qr code by Giandonato Inverso.
- QR code rendering powered by chillerlan/php-qrcode.
- Admin panel UI built on AdminLTE.
License
MIT - see LICENSE.
Languages
JavaScript
79.3%
PHP
12.3%
CSS
5.1%
HTML
3.2%
Dockerfile
0.1%