Discovery
Module compatibility matrix, theme rebuild plan, URL/redirect map, and content-type mapping.
Use this checklist if your site still runs Drupal 7 after community end of life. It walks through audit, risk reduction, and a realistic path to Drupal 10 or 11 — without guesswork.
Why this guide exists
Drupal 7 reached end of life on 5 January 2025. Your site may still look fine, but the security model changed: newly discovered issues in core or contrib modules are no longer patched by the community. Hosting providers are also dropping the old PHP versions Drupal 7 depends on.
This checklist is written for site owners, marketing leads, and IT managers who need a clear sequence — what to document first, what can wait, and when migration becomes the only sensible long-term option. For background, see Drupal 7 end of life.
The checklist
Work top to bottom. Each step produces an artifact (a list, a decision, or a date) you can share with stakeholders.
Record Drupal core version, PHP version, web server, hosting provider, and whether you use Composer, Drush, or manual updates. Screenshot the status report at /admin/reports/status.
Export a module list (enabled and disabled). Note custom modules, custom theme code, payment gateways, CRM hooks, SSO, and search. Flag anything unmaintained on drupal.org.
Count content types, languages, media formats, and roles. Identify workflows that must survive migration — approvals, scheduled publishing, webforms, memberships.
Verify database and files backups run daily, are stored off-site, and have been restored successfully in the last 12 months. EOL sites fail during incidents; backups are your last line of defence.
Check WAF/CDN rules, admin URL restrictions, MFA for privileged accounts, and whether unused modules are disabled. Remove old dev/stage copies from public reach.
Insurance, GDPR, PCI, or public-sector policies may require supported software. Document the gap: “Drupal 7 — community security support ended Jan 2025.”
Path A: short-term hardening + monitoring while you plan migration. Path B: migrate to Drupal 10 or 11 on a fixed scope. Most organisations need Path B within 12–18 months.
Get a migration or interim-support plan with a fixed price before work starts. A free assessment should produce module mapping, content scope, and a realistic go-live window.
Quick wins this week
These steps do not replace migration, but they close the obvious gaps while you plan the move.
Migration preview
Module compatibility matrix, theme rebuild plan, URL/redirect map, and content-type mapping.
Fresh Drupal 10/11 build, Migrate API for content and users, rebuilt theme in Twig, contrib replacements.
Regression testing, WCAG checks, performance baseline, and SEO redirect validation.
Staged cut-over, monitoring, and a short hypercare window after launch.
Need detail on any step? Read the full Drupal migration service page or request a free assessment.
Questions
No. Community support ended 5 January 2025. Vendor or custom extended support may exist, but drupal.org no longer ships SA-CORE fixes for Drupal 7.
Treat it as months, not years. Use the time to fund and schedule migration — especially if you handle personal data or payments.
No. Drupal 7 can migrate directly to Drupal 10 or 11 with the Migrate API. Stepping through intermediate major versions is unnecessary.
Related
Why EOL matters and your two main options.
Move to Drupal 10/11 with content and SEO preserved.
For supported versions — or interim hardening advice.
Often required alongside a major Drupal move.
Send your URL — I’ll run the audit and return a fixed-price plan for migration or interim protection.
Request your free assessment