Example, parking places with QR codes for paying webapps.

Currently a plague in some European countries.

It looks like the real site, and you pay twice, in the fake app, and later the police.

That’s an insecure design. The way we do it here is that you install an app and register your register number and payment card in it. Then when you drive in and out from the parking lot your license plate is scanned and you’re automatically charged. There’s only two providers so it’s not a huge hassle, if there was a single app per garage it would not really work from UX perspective.

No room for hostile social engineering.

Are you sure to install the right app though?

https://www.bbc.com/news/articles/cwyjqg578e1o

And given your German nickname, here isn't safe either in a general way, when folks aren't regularly parking on the same place.

https://www.adac.de/news/verkehr-quishing-parkautomaten