Drupal 7 is end-of-life

Drupal 7 support, LTS & security support

Need to keep a Drupal 7 site alive while migration is scoped? I harden, monitor, and stabilise D7 sites for a defined bridge period — with a clear path to Drupal 10 or 11.

The honest answer

Drupal 7 support is a bridge, not a destination

Drupal 7 reached end of life on 5 January 2025. The site can still run, but new community security fixes no longer arrive for Drupal 7 core and many contributed modules. That changes the support model.

Short-term Drupal 7 support makes sense when a migration needs budget approval, procurement, stakeholder sign-off, or content inventory. The goal is to reduce avoidable risk while creating the migration plan, not to pretend D7 is fully supported again.

If you are still deciding whether the problem is EOL, PHP, or migration scope, start with the overview at Drupal 7 end of life.

Support scope

What a Drupal 7 support bridge covers

Security hardening

Lock down admin access, review privileged accounts, remove unused modules, tighten file permissions, and confirm HTTPS/HSTS at the edge.

Module and PHP risk review

Inventory contrib and custom modules, flag known exposure, and document PHP runtime constraints before hosts remove old versions.

Backups and monitoring

Verify database and files backups, test restore assumptions, and monitor uptime or obvious failures during the bridge period.

Migration plan

Produce a practical route to Drupal 10 or 11 with content scope, module replacements, SEO redirects, and a fixed-price option.

Terms people use

Drupal 7 LTS, long-term support, and security support

“Drupal 7 LTS”, “Drupal 7 long term support”, and “Drupal 7 security support” are often used interchangeably by site owners. The useful distinction is whether you need temporary risk reduction or a full migration project.

Temporary support can include hardening, monitoring, and compatibility fixes. It cannot make every future Drupal 7 vulnerability disappear, and it cannot solve the ecosystem problem: newer PHP versions, modern modules, and current hosting patterns are built around supported Drupal.

For most sites, the right engagement is support plus migration planning. If the current site handles forms, payments, memberships, or personal data, set a dated migration window rather than leaving Drupal 7 open-ended.

Questions

Drupal 7 support — FAQ

Can Drupal 7 still be supported?

Yes, temporarily. I can harden and maintain a Drupal 7 site while migration is planned, but community support ended on 5 January 2025.

What does Drupal 7 security support include?

Access lockdown, module and custom-code review, backup restore checks, WAF/CDN recommendations, monitoring, PHP runtime review, and a migration plan.

Is Drupal 7 LTS enough?

It can buy time, but it is not a permanent substitute for moving to supported Drupal. Treat it as a bridge with a defined end date.

Should I migrate to Drupal 10 or 11?

For new migration work in 2026, Drupal 11 is usually the better target after an audit confirms module and hosting compatibility. See Drupal 11 migration.

Related Drupal services

Plan the next move

Need Drupal 7 support now?

Send your URL. I’ll identify the immediate risks and give you a bridge plan or migration path.

Request your free assessment