Perhaps he hadn't read the source code for his QR code scanner yet.
Until you know what the code does, you just have to take it on faith that it is doing what it says it is doing. Lots of people think "oh, someone else will have checked, it must be ok because it's open source". If you haven't actually read the source yourself you don't know. Also if you didn't build it yourself from that source then you don't know if the program really was built from the source it claims to, or whether a man in the middle changed something before building.