Good effort, but you should go for sanitizing the user input before you go ahead and use it.
For example, if you enter "'/> Hellooooo!" into your textarea, you can see the result shows the text "Helloooo!'/>" being shown next to the QR code for "'/>".
This is hugely important when writing web applications - you can read a bit more from this stack overflow question: http://stackoverflow.com/questions/2794137/sanitizing-user-i...
You may also want to read up about XSS: http://en.wikipedia.org/wiki/Cross-site_scripting
EDIT: I realise this was just a small, simple, learning project, but it's important to learn and be mindful of these considerations.