1. Secure & maintain your Drupal 7 site
If you're not ready to migrate, I can harden the site, apply available protections and compatibility fixes, and keep it running safely in the near term.
Drupal 7 stopped receiving community security updates on 5 January 2025. If you are still on D7 in 2026, every new vulnerability stays open unless you protect the site or migrate.
The risk
When Drupal 7 reached EOL, community security support ended. That means no patches for new core or contributed-module vulnerabilities, hosting providers dropping the old PHP versions D7 needs, and compliance or insurance issues for running unsupported software. Attackers actively scan for known, unpatched Drupal 7 holes.
Visually, nothing may have changed on the day support ended. Forms still submit, editors still log in, and the homepage still loads. What changed is the maintenance contract with the community: when a Security Advisory would have closed a hole in Drupal 7, that advisory no longer ships for your version. The longer you wait, the larger the gap between known issues and what your live site can patch.
Hosting pressure compounds the problem. Drupal 7 often sits on PHP 7.4 or older. Those runtimes are themselves end-of-life. Hosts remove them from new images and eventually refuse renewals. Teams then discover they cannot upgrade PHP without breaking Drupal 7 — and cannot stay on Drupal 7 without staying on unsafe PHP. Treating PHP and Drupal as one project is usually cheaper than fighting both separately.
Dates people still search
Searches for “Drupal 7 end of life 2024” are common because planning peaked before the deadline. The official community date was 5 January 2025. In 2026 the useful question is not “when did support end?” — it is whether you are still running unsupported software and which path closes the gap.
“D7 end of life” means the same thing as “Drupal 7 end of life.” Same risk stack, same choices: short-term hardening, migration to Drupal 10/11, or a commercial extended-support bridge while you migrate.
If budget was approved in 2024 but the project never started, treat 2026 as catch-up year: document the site, get a fixed-price plan, and schedule cutover before another annual cycle slips. Compliance reviews, insurance questionnaires, and vendor security forms increasingly ask whether platform software is supported — “we plan to migrate next year” is a weaker answer every quarter.
Your options
If you're not ready to migrate, I can harden the site, apply available protections and compatibility fixes, and keep it running safely in the near term.
The long-term answer for most sites. I audit your modules, theme, and content, then migrate to the current supported line with a clear, fixed-price plan — no surprises. Prefer Drupal 11 for new projects in 2026.
Commercial Drupal 7 extended support / LTS-style cover can buy time for compliance calendars. It does not modernise the architecture — plan the migration in parallel. Details: Drupal 7 extended support.
What path 1 really covers
Hardening buys time. Typical work includes locking down admin paths, confirming MFA for privileged accounts, removing unused modules, tightening file permissions, putting a WAF or CDN ruleset in front of the site, and monitoring for abuse. I also check that backups are real restores, not only nightly archives sitting on the same volume as production.
What hardening cannot do is invent community patches that no longer exist. New Drupal 7 core or contrib CVEs stay open unless a commercial extended-support vendor covers them — and even then, you are still on an architecture the module ecosystem has largely left. Use interim care for a defined window (months, not years) while migration is scoped and funded.
What path 2 really covers
Between Drupal 7 and Drupal 8 the platform changed foundations: Symfony components, configuration management, Twig themes, and a different module API. There is no “run update.php and you are on Drupal 11” path. You install a new Drupal 10 or 11 site and move content, users, files, and as much configuration as maps cleanly via the Migrate API.
Contributed modules need a compatibility matrix. Roughly some of them have maintained Drupal 10/11 releases; others need replacements or custom ports. Themes never port — the front end is rebuilt. That sounds large because it is, but it is also the moment to drop decade-old cruft: unused content types, dead integrations, and fields nobody edits anymore.
For most new projects in 2026 I recommend landing on Drupal 11 so you are not forced into another major upgrade when Drupal 10’s own support window closes. Drupal 7 can go straight to 11 — no forced hop through 8 or 9.
Talk through your site — harden short-term or migrate to Drupal 10/11.
Talk through your siteIn depth
If you are prioritising work this year, start with the Drupal 7 EOL checklist for 2026 — it sequences inventory, backups, compliance review, and migration scoping in an order you can share with leadership.
Bring stakeholders three artifacts from that checklist: (1) a module and integration inventory, (2) a decision between interim harden vs migrate, and (3) a dated go-live window with a fixed-price envelope. Without those, projects stall in “we need to gather information” for another year.
When you are ready for the project shape, see Drupal 7 migration — D7 can go straight to Drupal 10 or 11 (often Drupal 11) with the Migrate API.
Whichever path you choose, insist on a fixed scope and staging before go-live. End-of-life sites fail during rushed changes; a documented plan beats another year of “we will get to it next quarter.”
SEO & content
Migrations lose organic traffic when URL aliases change without redirects, when titles and meta descriptions are dropped, or when thin stub pages replace long-lived content. I include a path map and 301 table before cutover, keep important node IDs or alias patterns where practical, and validate staging against Search Console’s view of what already ranks.
If your Drupal 7 site ranks for “Drupal 7 end of life”-adjacent queries or product/service terms, treat those landing pages as first-class migration items — not afterthoughts. Content that took years to earn links should not be redesigned solely for visual novelty on go-live week.
Questions
5 January 2025. No more official security updates or bug fixes from the community.
Yes. D7 is shorthand for Drupal 7 — same date, same options.
Planning ramped up in 2024; the official community date was 5 January 2025. In 2026 the work is closing remaining exposure.
Not without a plan — new vulnerabilities stay unpatched. Either add extended protection for a defined period or migrate to a supported version.
It depends on your modules and content — see Drupal 7 migration. The free assessment establishes scope before any fixed-price quote.
No. Drupal 7 migrates directly to Drupal 10 or 11 with the Migrate API.
Related Drupal services
Step-by-step audit and migration planning guide.
D7 → 10/11 project shape, process, and fixed-price approach.
LTS / bridge options while you fund the move.
Target Drupal 11 from D7/D8/D9/D10 with an audit-first plan.
Version upgrades and migration options in one place.
Still on Drupal 6? Same migrate-to-modern path.
Harden and patch while you plan the move.
Ongoing care once you're on modern Drupal.
Get a free assessment of your site and a clear plan — secure it or migrate, your call.
Request your free assessment