Guide · updated for 2026

Drupal 7 EOL checklist for 2026

Use this checklist if your site still runs Drupal 7 after community end of life. It walks through audit, risk reduction, and a realistic path to Drupal 10 or 11 — without guesswork.

Why this guide exists

Drupal 7 did not “break overnight” — support did

Drupal 7 reached end of life on 5 January 2025. Your site may still look fine, but the security model changed: newly discovered issues in core or contrib modules are no longer patched by the community. Hosting providers are also dropping the old PHP versions Drupal 7 depends on.

This checklist is written for site owners, marketing leads, and IT managers who need a clear sequence — what to document first, what can wait, and when migration becomes the only sensible long-term option. For background, see Drupal 7 end of life.

The checklist

Eight steps — in order

Work top to bottom. Each step produces an artifact (a list, a decision, or a date) you can share with stakeholders.

  1. Confirm what you are running

    Record Drupal core version, PHP version, web server, hosting provider, and whether you use Composer, Drush, or manual updates. Screenshot the status report at /admin/reports/status.

  2. Inventory modules, theme, and integrations

    Export a module list (enabled and disabled). Note custom modules, custom theme code, payment gateways, CRM hooks, SSO, and search. Flag anything unmaintained on drupal.org.

  3. Map content and editorial workflows

    Count content types, languages, media formats, and roles. Identify workflows that must survive migration — approvals, scheduled publishing, webforms, memberships.

  4. Review backups and recovery

    Verify database and files backups run daily, are stored off-site, and have been restored successfully in the last 12 months. EOL sites fail during incidents; backups are your last line of defence.

  5. Assess security exposure

    Check WAF/CDN rules, admin URL restrictions, MFA for privileged accounts, and whether unused modules are disabled. Remove old dev/stage copies from public reach.

  6. Check compliance and contracts

    Insurance, GDPR, PCI, or public-sector policies may require supported software. Document the gap: “Drupal 7 — community security support ended Jan 2025.”

  7. Choose your path

    Path A: short-term hardening + monitoring while you plan migration. Path B: migrate to Drupal 10 or 11 on a fixed scope. Most organisations need Path B within 12–18 months.

  8. Agree scope, timeline, and budget

    Get a migration or interim-support plan with a fixed price before work starts. A free assessment should produce module mapping, content scope, and a realistic go-live window.

Quick wins this week

Low-effort actions that reduce risk now

  • Disable and uninstall modules you no longer use.
  • Ensure no one shares the admin account — separate roles with least privilege.
  • Turn on HTTPS everywhere and verify HSTS at the edge.
  • Confirm your host’s PHP version and planned EOL date for that runtime.
  • Subscribe to security mailing lists for any integrations (payment, auth) outside Drupal.

These steps do not replace migration, but they close the obvious gaps while you plan the move.

Migration preview

What a Drupal 7 → 10/11 project usually includes

Discovery

Module compatibility matrix, theme rebuild plan, URL/redirect map, and content-type mapping.

Build & migrate

Fresh Drupal 10/11 build, Migrate API for content and users, rebuilt theme in Twig, contrib replacements.

QA & accessibility

Regression testing, WCAG checks, performance baseline, and SEO redirect validation.

Go-live

Staged cut-over, monitoring, and a short hypercare window after launch.

Need detail on any step? Read the full Drupal migration service page or request a free assessment.

Questions

Checklist FAQ

Is Drupal 7 still receiving security updates in 2026?

No. Community support ended 5 January 2025. Vendor or custom extended support may exist, but drupal.org no longer ships SA-CORE fixes for Drupal 7.

How long should interim hardening last?

Treat it as months, not years. Use the time to fund and schedule migration — especially if you handle personal data or payments.

Do I need Drupal 8 or 9 first?

No. Drupal 7 can migrate directly to Drupal 10 or 11 with the Migrate API. Stepping through intermediate major versions is unnecessary.

Related

Services that match this checklist

PHP upgrade

Often required alongside a major Drupal move.

Want this checklist done for your site?

Send your URL — I’ll run the audit and return a fixed-price plan for migration or interim protection.

Request your free assessment