After several extensions, Drupal 7 reaches its final end of life on January 5, 2025. The date will not move again. If your organization still runs a Drupal 7 site, you probably have one of two reactions: worry that something will break on January 6, or a suspicion that nothing will happen at all.
Neither is quite right. Here is what actually changes, what the risks are, and what you can still do in the weeks you have left.
What changes on January 5
Your site will not switch off. Pages will still load, editors will still log in, and forms will still submit. End of life is not a kill switch.
What ends is support from the Drupal community:
- The Drupal Security Team stops reviewing and publishing fixes for Drupal 7 core and Drupal 7 contributed modules.
- Security advisories for newly discovered Drupal 7 vulnerabilities will no longer be published by the Drupal project.
- Contributed module maintainers will no longer be expected to support their Drupal 7 versions, and many have already stopped.
The important point is the second one. Vulnerabilities in Drupal 7 code will still be found after January 5. They simply will not be fixed or announced through the usual channels, and attackers know that.
The real risks
Security
Drupal 7 has had serious vulnerabilities in the past, including ones that were exploited automatically within hours of disclosure. A site that no longer receives fixes is exposed to the next one, and you may not hear about it until something goes wrong.
Compliance and insurance
If your site handles payments, personal data or health information, running unsupported software can put you out of line with standards and contracts you have signed. PCI DSS, for example, expects systems to be protected from known vulnerabilities with vendor-supplied patches. Cyber insurance questionnaires increasingly ask about end-of-life software too.
Hosting and PHP
Drupal 7 sites often run on older PHP versions. As hosting providers retire those versions, you may be forced into an upgrade on someone else's schedule. Not every Drupal 7 contributed module works on current PHP releases.
Hiring and maintenance
Fewer developers want to work on Drupal 7 every year. Routine changes become slower and more expensive as the pool of people who know the platform shrinks.
Your options
Option 1: Stay on Drupal 7 with extended support
The Drupal Association runs a Drupal 7 Extended Security Support program with certified commercial vendors. These companies continue to provide security fixes for Drupal 7 core and selected contributed modules after end of life, for a fee.
This is a legitimate choice if a migration cannot be finished in time, or if the site will be retired within a year or two anyway. It is a bridge, not a destination. You pay to keep the old platform safe while the cost of eventually leaving it keeps rising.
Option 2: Migrate to Drupal 10 or 11
For sites with complex content models, many editors or deep integrations, moving to modern Drupal is usually the right path. Drupal has a built-in migration system for content, users and configuration, but it is a rebuild rather than an upgrade: the theme and custom code have to be redone for the modern architecture.
That sounds like a cost, and it is, but it is also a chance to drop features nobody uses, fix the content model and improve the editing experience. We walk through the main paths in our guide to migrating from Drupal 7.
Option 3: Wait for Drupal CMS
The Drupal project plans to release Drupal CMS, a ready-to-use version of Drupal aimed at marketers and smaller organizations, in January 2025. For simpler Drupal 7 brochure sites it may become an attractive target. It will be new, though, so plan to evaluate it rather than assume it fits.
Option 4: Backdrop CMS
Backdrop is a fork of Drupal 7 with an upgrade path that is much closer to Drupal 7 than modern Drupal is. It can make sense for small sites that want to keep the familiar architecture. The trade-off is a much smaller ecosystem of modules and developers.
Option 5: Leave Drupal
Some Drupal 7 sites are simple enough that a different platform fits better: a static site, a hosted CMS, or a headless setup. This is worth considering honestly, especially if the site is mostly marketing pages with a contact form.
What to do this month
You cannot finish a migration in six weeks, but you can reduce risk and make a decision:
- Make a list of every Drupal 7 site your organization runs, including the forgotten microsites.
- Apply all available Drupal 7 security updates before January 5, so you start from the safest possible state.
- Disable and remove modules you do not use. Every module you remove is code that cannot be exploited.
- Decide, site by site, whether you will retire it, migrate it or cover it with extended support while you migrate.
- If you choose extended support, sign the agreement before the deadline so there is no gap.
Most of the Drupal 7 sites still running at this point are running because they work and nobody wanted to touch them. That is understandable. But the cost of doing nothing changes on January 5, and it is better to choose your path now than have it chosen for you by an incident.
Need help deciding what to do with a Drupal 7 site? Talk to us. We will review it and recommend the cheapest safe option, even if that is not a migration.