Drupal 7 reached end of life on 5 January 2025. After more than a decade of service and several extensions to its support window, the Drupal community no longer provides security releases for Drupal 7 core or its contributed modules.

Plenty of Drupal 7 sites are still running, and many of them work perfectly well on the surface. The problem is what you cannot see. This article explains what end of life means in practice, and walks through the realistic options for moving on, with honest trade-offs for each.

What end of life actually means

Your site does not switch off. Nothing breaks overnight. What changes is that when a security vulnerability is found in Drupal 7 core or a module you use, there is no official fix from the community security team. The vulnerability may be published, which makes it known to attackers, but the patch will not arrive through the normal channels.

There are knock-on effects too:

  • PHP compatibility. Hosts gradually retire older PHP versions. Keeping an unsupported application running on a supported PHP version gets harder over time.
  • Module abandonment. Contributed module maintainers have largely moved on, so bugs and incompatibilities stay unfixed.
  • Compliance. If your organisation works under security policies, insurance terms or procurement rules that require supported software, an end-of-life CMS may already be a problem on paper.
  • Hiring. Fewer developers want to work on Drupal 7, and that pool will keep shrinking.

If you are unsure what you are running, check the site’s status report in the Drupal admin. It lists the core version and every enabled module, which is the starting point for any migration plan.

Option 1: Move to Drupal 10 or 11

The natural path for many organisations is modern Drupal. Drupal 8 onwards is a substantial rewrite, built on Symfony components with a different architecture, so this is a rebuild and migration rather than an upgrade. But it keeps you in the Drupal world, with its strengths in structured content, permissions, multilingual sites and complex integrations.

Drupal includes a Migrate API designed for bringing content across from Drupal 7: content types, fields, taxonomy, users, files and URL aliases. For sites with a fairly standard setup, a lot of content can move with relatively little custom work. Sites with heavy custom modules or unusual data structures need more effort.

Things to plan for:

  • Custom modules need to be rewritten, not ported line by line.
  • Your theme needs rebuilding, as modern Drupal uses Twig templates rather than the PHPTemplate system Drupal 7 used.
  • Some Drupal 7 modules have no direct modern equivalent, so features may need rethinking.
  • Use the move to tidy up. Most long-running sites have content types and fields that nobody uses any more.

Modern Drupal suits organisations with complex content, multiple user roles, strict permissions or large multilingual sites. It is a serious platform and needs serious development skills to run well. You can read more on our Drupal development page.

Option 2: Extended support from a commercial vendor

Several commercial vendors offer paid extended support for Drupal 7, providing security patches for core and selected modules beyond the official end-of-life date. This can be a sensible bridge if you have a firm reason you cannot migrate yet: a major internal project, a funding cycle, or a planned retirement of the site.

Be clear about what this option is and is not:

  • It buys time. It does not fix the underlying age of the platform.
  • Coverage usually depends on which modules you use. Check that every module on your site is included.
  • You are paying to stand still, and that money does not go towards your next site.

For most organisations, extended support makes sense only with a dated migration plan alongside it.

Option 3: Move to a different CMS

End of life is a natural moment to ask whether Drupal is still the right fit. Many Drupal 7 sites were built years ago for needs that have since changed. A marketing site that once needed complex workflows might now be better served by something simpler for the team to run.

Platform Good fit when Consider carefully if
Modern Drupal Complex content, permissions, multilingual, integrations Your team is small and needs are simple
WordPress Marketing and content sites, broad developer pool, familiar editor You rely on very granular permissions or complex workflows
Craft CMS Design-led sites with structured content and a clean admin You need a very large plugin ecosystem
Headless, e.g. Sanity or Contentful Content feeds several channels, or you want a modern front end You lack in-house or partner front-end capacity

Moving platforms means content migration is a custom job. Drupal 7’s database structure is well understood, so content can be extracted and mapped to a new system reliably, but it needs planning. URL redirects, media files and SEO metadata all deserve attention so you do not lose search visibility.

Option 4: Do nothing

It is worth naming because it is what many sites are doing. Running Drupal 7 without patches is a real and growing risk, particularly for sites with logins, forms or personal data. If you choose to wait, at least reduce the exposure: disable unused modules, restrict admin access, keep good backups, put the site behind a web application firewall and set a date to decide properly.

How to plan the move

Whichever route you choose, a migration goes best in this order:

  1. Audit. List content types, fields, modules, custom code, integrations, user roles and traffic to key pages.
  2. Decide what to keep. Old content with no traffic and no value can be archived rather than migrated.
  3. Model the new site. Design the content model for how you work now, not how the old site was set up.
  4. Migrate and test. Run content migrations repeatedly on staging, checking a sample of records each time.
  5. Protect SEO. Map old URLs to new ones and set up redirects before launch.
  6. Train and launch. Editors need time on the new admin before go-live.

Our process page explains how we run each stage on migration projects.

Still running Drupal 7?

If you would like help weighing up your options or scoping a migration, get in touch and we will give you a straight answer.