Migration Drupal Security

Drupal 7 in 2026: what to do with an old site

🎧 Listen to every article back to back

A Drupal 7 website can still look fine in 2026, but official security support has ended and every new change is becoming harder to control.

Why this is no longer a normal update

Drupal 7's official lifecycle (opens in a new tab) has ended. That means an old site does not only need module updates. It needs a decision: continue with known risk, buy temporary support or move to a newer platform.

Module updates have stopped. If a new security vulnerability is found in a Drupal 7 module, no automatic fix will arrive — someone must patch it manually or accept the risk.

What the real risks are

Most Drupal 7 sites are still running without any visible problem. The risk does not appear immediately — it grows over time:

  • Security vulnerabilities — newly found weaknesses in modules are no longer patched automatically.
  • Hosting requirements — PHP 8.x does not support Drupal 7 well. A hosting provider may force an upgrade.
  • New integrations — a module that needs to connect to a new external service may no longer be developed for Drupal 7.
  • Developer availability — finding a new developer who knows Drupal 7 well is becoming increasingly difficult.

Three options

Option 1 — known risk. The site continues running, the risk is documented, no critical changes are made. Only suitable for a short period when migration is already planned.

Option 2 — extended support. Some partners offer Drupal 7 long-term security support (LTSC). This buys time, but it is expensive and does not solve the underlying problem.

Option 3 — migration. The most reliable path. Waiting longer does not make the work cheaper — outdated code complexity and unmade changes accumulate.

Where to start

Before estimating the work, map:

  • which modules are critical;
  • whether custom code is documented;
  • how much content must be migrated;
  • which integrations and forms must keep working;
  • whether design and accessibility should be fixed at the same time.

The practical first step is a Drupal audit, not immediate development. An audit shows whether a controlled migration is enough or whether parts of the solution need redesign.

If the site is business-critical, agree on Drupal maintenance while the migration is planned. The end goal should still be moving to a secure and supported version. The Drupal migration service covers risk mapping, data migration and testing before release.

Kaido Toomingas, WebPro technical leadWebPro Company OÜ Technical lead: Kaido Toomingas

Need Drupal help?

If the article describes your situation, you do not have to read everything first. A real person will help you choose the next step.