Unsupported

Support status · Drupal 7

Is Drupal 7 still supported?

Drupal 7 reached end of life on 5 January 2025.

If you already know it has to move

Talk to the engineer, not a form

Two fields and one question. The reply comes from the person who would read the code.

How much bespoke code is in it?

One reply, written by a person who has read your answers. Nothing else is ever sent.

The date had already been extended more than once, and that was the last one. The security team no longer issues advisories or patches for Drupal 7 core or its contributed modules, and the module ecosystem stopped receiving maintenance long before the core date. Commercial vendors sell extended support, which genuinely works as a holding position. It does not change the module situation: a contributed module whose maintainer left in 2018 was already unmaintained while Drupal 7 was still supported.

Support ended
5 January 2025
Community security patches
None
Contributed modules
Unmaintained, mostly for longer
Extended support
Commercial vendors only

Source: Drupal.org: Drupal 7 end of life. Check it. We would rather you did.

  • Dates from Drupal.org, linked
  • No email needed to read them
  • Sometimes the answer is another CMS

What that actually means

The position most estates are in

  1. The site works, and the module holding it together has no maintainer

    Nothing about a Drupal 7 site degrades on its own. The exposure is in the contributed modules: a dozen or more, each an independent project, several abandoned years before core reached its own date, some patched locally in ways nobody recorded.

  2. The upgrade quote came back as a rebuild, and it was not wrong

    Drupal 8 broke the API completely. Content can be migrated with real tooling, and that part is genuinely solved. Every custom module and every theme hook has to be rewritten against a framework that shares a name and almost nothing else, which is why the quote surprised you.

  3. Compliance found it before you did

    Unsupported software is not a judgement call in an assessment. Under Cyber Essentials, software in scope that no longer receives vendor security updates is an automatic failure, which turns a deferred technical decision into a blocked certification and, often, a blocked contract.

Exposure

What breaks, how likely, what it costs

Stated generically here because it is generic until someone looks at your estate. These are the scenarios that actually land, in the columns your risk register already has.

ScenarioLikelihoodImpact
A vulnerability is found in Drupal 7 core or a contributed module you runCertain over timeNo community patch will be issued. Mitigation is yours to build or buy
A Cyber Essentials or ISO assessment reaches the web estateAnnual, if you certifyUnsupported software in scope is an automatic failure, not a finding to argue
The PHP version underneath reaches end of lifeOn a published dateDrupal 7 constrains how far PHP can be upgraded, so two clocks run at once
You need a change to a module whose maintainer disappearedAlready true for most estatesA routine request becomes bespoke development against unfamiliar code

What we do about it

The work itself

An honest read on which kind of site you have

Whether the Drupal is a content management system with a theme on it, or an application that grew inside one. The first should go to a current CMS and we will tell you so. Only the second is worth rebuilding, and we would rather establish that early than sell you the wrong thing.

What the custom code actually does

Bespoke modules, hook implementations, custom entities and the form alters read at volume and written down as business rules. In an estate this age these are where the actual product lives, and they are almost never documented.

Behaviour pinned before anything moves

Characterisation tests through HTTP against the running site, covering the editorial workflows and the logged-in paths that a content migration will not tell you about.

Content and application, treated separately

Nodes, taxonomy, users and files are a data migration with mature tooling and should be run as one. The custom behaviour is a rebuild. Conflating the two is what makes these projects unpredictable.

What decides the cost

The three things worth knowing before anyone quotes

Custom modules
The count and the depth of your bespoke modules is the estimate. Contributed modules mostly have equivalents; your own code does not.
Patched contrib
Locally patched contributed modules are the most dangerous thing in a Drupal 7 estate, because the patch is undocumented behaviour that a migration silently drops.
Authenticated paths
A site that only publishes content is a different job from one where logged-in users complete work. The second is where a rebuild is justified.

The engagement

How the work runs

  1. You tell us what you have

    Roughly how many custom modules, whether there are logged-in users doing real work, and what would hurt most if it broke.

  2. We read the code

    Custom modules, patched contrib, the hooks in the theme, and how much of the site is content versus behaviour.

  3. You get the split, plainly

    Which parts are a content migration, which parts are a rebuild, and whether the honest recommendation is a current CMS rather than us.

  4. The rebuild runs in pieces

    Content migrated as one job, behaviour moved section by section with the old site serving what has not moved yet.

Questions

Frequently asked

Is Drupal 7 still supported?

No. Drupal 7 reached end of life on 5 January 2025, after several extensions. The Drupal Security Team no longer issues advisories or patches for it, and contributed modules stopped being maintained well before that. If your site is still on 7, it is running unsupported software today.

Can we buy extended support and leave it?

You can, and for a site with a real constraint this year it is a sensible holding position. Commercial vendors provide backported security fixes for Drupal 7. Understand its limit: they cover core and popular contrib, not the module nobody has maintained since 2018 and not the local patch someone applied without recording it. It removes the compliance finding and buys a year. It does not make the site supportable.

Should we go to Drupal 11, or to something else entirely?

It depends which kind of site you have, and this is the question worth answering before you get a quote for anything. If it is content with a theme, staying in Drupal is often cheapest, because the content migration path is mature and your editors keep the tool they know. If the Drupal is really an application, its custom modules have to be rewritten regardless of destination, at which point staying in Drupal is a choice rather than a saving, and frequently the wrong one.

What happens to our content?

It moves, and this is the reassuring part. Nodes, fields, taxonomy, users and files migrate with mature tooling and the mapping is a known problem. What does not come across automatically is behaviour: form alters, custom entity logic, access rules and anything a bespoke module was doing. Those get rebuilt, which is why the two should be scoped separately.

Will Drupal 7 fail a Cyber Essentials assessment?

If it is in scope, yes. The requirement is that software receives vendor security updates, and end-of-life software in scope is an automatic failure rather than an observation. Commercial extended support is the usual way estates answer this while they plan, and it is worth confirming with your assessor rather than assuming either way.

Our agency disappeared and nobody here knows what the custom modules do. Is that a problem?

It is the normal starting position, and it is the part we are actually good at. Reading unfamiliar code at volume and writing down what it does is the first phase of every engagement here. You do not need to be able to explain the estate before talking to us; if you could, you would not need us.

Have you migrated Drupal specifically?

Our deepest delivery experience is ColdFusion, not Drupal. The method is language-independent, recovering the behaviour, pinning it with tests and moving it in pieces, and the custom-module work is ordinary PHP comprehension. For a site that is mostly content, a Drupal specialist is probably a better fit than us and we will say so.

Talk to someone who would read the code

A name, an email, and three optional questions. What comes back is a reply from the engineer who would read the code, and it is either a conversation about replacing it or an honest reason why someone else is the better fit.

One reply, written by a person who has read your answers. Nothing else is ever sent.

Other platforms

Something else in the estate on borrowed time?