End of life since 5 January 2025

Drupal 7 (D7) end of life — what to do now

Drupal 7 stopped receiving community security updates on 5 January 2025. If you are still on D7 in 2026, every new vulnerability stays open unless you protect the site or migrate.

The risk

Why an end-of-life Drupal 7 site is a problem

When Drupal 7 reached EOL, community security support ended. That means no patches for new core or contributed-module vulnerabilities, hosting providers dropping the old PHP versions D7 needs, and compliance or insurance issues for running unsupported software. Attackers actively scan for known, unpatched Drupal 7 holes.

Visually, nothing may have changed on the day support ended. Forms still submit, editors still log in, and the homepage still loads. What changed is the maintenance contract with the community: when a Security Advisory would have closed a hole in Drupal 7, that advisory no longer ships for your version. The longer you wait, the larger the gap between known issues and what your live site can patch.

Hosting pressure compounds the problem. Drupal 7 often sits on PHP 7.4 or older. Those runtimes are themselves end-of-life. Hosts remove them from new images and eventually refuse renewals. Teams then discover they cannot upgrade PHP without breaking Drupal 7 — and cannot stay on Drupal 7 without staying on unsafe PHP. Treating PHP and Drupal as one project is usually cheaper than fighting both separately.

Dates people still search

Drupal 7 end of life 2024 vs the real date

Searches for “Drupal 7 end of life 2024” are common because planning peaked before the deadline. The official community date was 5 January 2025. In 2026 the useful question is not “when did support end?” — it is whether you are still running unsupported software and which path closes the gap.

“D7 end of life” means the same thing as “Drupal 7 end of life.” Same risk stack, same choices: short-term hardening, migration to Drupal 10/11, or a commercial extended-support bridge while you migrate.

If budget was approved in 2024 but the project never started, treat 2026 as catch-up year: document the site, get a fixed-price plan, and schedule cutover before another annual cycle slips. Compliance reviews, insurance questionnaires, and vendor security forms increasingly ask whether platform software is supported — “we plan to migrate next year” is a weaker answer every quarter.

Your options

Three paths forward

1. Secure & maintain your Drupal 7 site

If you're not ready to migrate, I can harden the site, apply available protections and compatibility fixes, and keep it running safely in the near term.

2. Migrate to Drupal 10 or 11

The long-term answer for most sites. I audit your modules, theme, and content, then migrate to the current supported line with a clear, fixed-price plan — no surprises. Prefer Drupal 11 for new projects in 2026.

3. Extended support as a bridge only

Commercial Drupal 7 extended support / LTS-style cover can buy time for compliance calendars. It does not modernise the architecture — plan the migration in parallel. Details: Drupal 7 extended support.

  • Full module & content audit before any work
  • Accessibility (WCAG) preserved or improved during migration
  • Fixed price and agreed scope up front
  • Done by a senior Drupal specialist with 10+ years on Drupal.org

What path 1 really covers

Interim hardening — what “secure Drupal 7” can and cannot do

Hardening buys time. Typical work includes locking down admin paths, confirming MFA for privileged accounts, removing unused modules, tightening file permissions, putting a WAF or CDN ruleset in front of the site, and monitoring for abuse. I also check that backups are real restores, not only nightly archives sitting on the same volume as production.

What hardening cannot do is invent community patches that no longer exist. New Drupal 7 core or contrib CVEs stay open unless a commercial extended-support vendor covers them — and even then, you are still on an architecture the module ecosystem has largely left. Use interim care for a defined window (months, not years) while migration is scoped and funded.

What path 2 really covers

Why Drupal 7 → 10/11 is a migration, not an update

Between Drupal 7 and Drupal 8 the platform changed foundations: Symfony components, configuration management, Twig themes, and a different module API. There is no “run update.php and you are on Drupal 11” path. You install a new Drupal 10 or 11 site and move content, users, files, and as much configuration as maps cleanly via the Migrate API.

Contributed modules need a compatibility matrix. Roughly some of them have maintained Drupal 10/11 releases; others need replacements or custom ports. Themes never port — the front end is rebuilt. That sounds large because it is, but it is also the moment to drop decade-old cruft: unused content types, dead integrations, and fields nobody edits anymore.

For most new projects in 2026 I recommend landing on Drupal 11 so you are not forced into another major upgrade when Drupal 10’s own support window closes. Drupal 7 can go straight to 11 — no forced hop through 8 or 9.

Still on Drupal 7?

Talk through your site — harden short-term or migrate to Drupal 10/11.

Talk through your site

In depth

Planning in 2026: use a checklist, not guesswork

If you are prioritising work this year, start with the Drupal 7 EOL checklist for 2026 — it sequences inventory, backups, compliance review, and migration scoping in an order you can share with leadership.

Bring stakeholders three artifacts from that checklist: (1) a module and integration inventory, (2) a decision between interim harden vs migrate, and (3) a dated go-live window with a fixed-price envelope. Without those, projects stall in “we need to gather information” for another year.

When you are ready for the project shape, see Drupal 7 migration — D7 can go straight to Drupal 10 or 11 (often Drupal 11) with the Migrate API.

Whichever path you choose, insist on a fixed scope and staging before go-live. End-of-life sites fail during rushed changes; a documented plan beats another year of “we will get to it next quarter.”

SEO & content

Protecting rankings when you finally move

Migrations lose organic traffic when URL aliases change without redirects, when titles and meta descriptions are dropped, or when thin stub pages replace long-lived content. I include a path map and 301 table before cutover, keep important node IDs or alias patterns where practical, and validate staging against Search Console’s view of what already ranks.

If your Drupal 7 site ranks for “Drupal 7 end of life”-adjacent queries or product/service terms, treat those landing pages as first-class migration items — not afterthoughts. Content that took years to earn links should not be redesigned solely for visual novelty on go-live week.

Questions

Drupal 7 EOL — FAQ

When did Drupal 7 reach end of life?

5 January 2025. No more official security updates or bug fixes from the community.

Is “D7 end of life” the same as Drupal 7 EOL?

Yes. D7 is shorthand for Drupal 7 — same date, same options.

What about “Drupal 7 end of life 2024” searches?

Planning ramped up in 2024; the official community date was 5 January 2025. In 2026 the work is closing remaining exposure.

Is it safe to keep running Drupal 7?

Not without a plan — new vulnerabilities stay unpatched. Either add extended protection for a defined period or migrate to a supported version.

How long does a Drupal 7 migration take?

It depends on your modules and content — see Drupal 7 migration. The free assessment establishes scope before any fixed-price quote.

Do I need to upgrade through Drupal 8 and 9 first?

No. Drupal 7 migrates directly to Drupal 10 or 11 with the Migrate API.

Related Drupal services

Where to go next

Still on Drupal 7? Let's fix that.

Get a free assessment of your site and a clear plan — secure it or migrate, your call.

Request your free assessment