Open
Cached
·
just now
19
Headers
Detected Technologies from Headers
AWS CloudFront
YouTube
Microsoft Advertising
Ceros
Cloudflare
Active incidents
Cloudflare CDN
Cloudflare Turnstile
Contentful
Decagon
Facebook
Fullstory
Google Analytics
Google API JS Client
Google DoubleClick
Google Fonts
Google Search
Google Tag Manager
jsDelivr
Maze
Netlify
Next.js
Reddit
Sentry
Simplecast
Snapchat
Statsig
TikTok Analytics
The Trade Desk
Twitter
Typeform
HTTP Security Headers
Status
Strict-Transport-Security
Good
max-age=31536000; includeSubDomains
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Consider adding 'preload' to HSTS for maximum security
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
Performance Headers
Connection
close
Transfer-Encoding
chunked
Vary
rsc, next-router-state-tree, next-router-prefetch, next-router-segment-prefetch, Accept-Encoding
connection: close transfer-encoding: chunked vary: rsc, next-router-state-tree, next-router-prefetch, next-router-segment-prefetch, Accept-Encoding
Caching Headers
Cache-Control
public, max-age=0, must-revalidate
cache-control: public, max-age=0, must-revalidate
Content Headers
Content-Type
text/html; charset=utf-8
content-type: text/html; charset=utf-8
CORS Headers
No CORS headers found
Cookies Headers
Other Headers
Cdn-Cache-Control
no-store
Date
Fri, 01 May 2026 17:54:50 GMT
Link
URL
/en-ca.md
rel=alternate
type=text/markdown
Reporting-Endpoints
csp-endpoint="https://www.wealthsimple.com/api/csp-report"
cdn-cache-control: no-store cf-cache-status: DYNAMIC cf-ray: 9f50a75c4e9db135-IAD date: Fri, 01 May 2026 17:54:50 GMT link: </en-ca.md>; rel="alternate"; type="text/markdown" netlify-vary: cookie=contentful-timeline-token reporting-endpoints: csp-endpoint="https://www.wealthsimple.com/api/csp-report" x-nextjs-cache: HIT x-nextjs-prerender: 1, 1 x-nextjs-stale-time: 300
Recommendations
Enable compression (gzip/brotli) to improve performance