Blog

Still running Drupal 7? Here’s what you need to know right now.

As of January 5, 2025, your Drupal 7 website no longer receives security updates. 

New vulnerabilities will remain unpatched, 
significantly increasing the risk of data breaches, GDPR fines and reputational damage.


Drupal 7 EOL

TL;DR

  • Drupal 7 stopped receiving security updates on January 5, 2025.
  • New vulnerabilities remain open and will not be patched.
  • This means risk of data breaches, GDPR fines and reputational damage.
  • Delaying makes migration more expensive: complexity grows month by month.

The problem: your website is exposed to attackers

The Drupal Security Team has not published security updates for Drupal 7 since 5 January 2025. 
New vulnerabilities remain open. 
Hackers can exploit vulnerabilities without a patch ever coming.
 

For your business this means:
 

  • Data breaches: customer data, login credentials and contact info are left unprotected.
  • GDPR risk: an outdated system doesn't meet the required appropriate technical measures.
  • Reputational damage: customers trust you less after a data breach.
     
Kantelende websiteblokken met gebarsten schild en open slot

Simply explained: what is end-of-life?

End-of-life means that the makers of Drupal 7 no longer release security patches. 
If a major vulnerability is discovered tomorrow, it stays open. 
No update, no solution. 

Anyone who knows about the vulnerability can exploit it.

Why this matters in 2026

Drupal 7 has been without support for over a year now. Every month that passes:
 

  • Known vulnerabilities grow.
  • Your site becomes an easier target for automated attacks.
  • Custom code and integrations become harder to migrate.
     

What is still a manageable migration today will become a complex and expensive project later.

Know where you stand in 30 minutes

You don't need to create a full migration plan right away. 
Start with a quick scan:
 

  • Which version is currently running?
  • How much custom code and integrations are there?
  • Which functionality is business-critical?
  • What is a realistic timeline?
     

Such a scan gives you an estimate of costs, time and risks. 
Then you can make an informed decision.

5 quick wins to reduce risk

  1. Make a full backup now: if something goes wrong tomorrow, you'll otherwise lose data.
  2. Check your firewall: a good firewall blocks many attacks, but doesn't solve the underlying problem.
  3. Disable unused components: less code means less attack surface.
  4. Monitor suspicious activity: get alerts for unusual login attempts or file changes.
  5. Discuss this internally: make sure everyone knows this risk exists and that it has priority.

What to ask your developer

  • Which Drupal 7 components are we using and are they still maintained?
  • How complex is our custom code and how much time does it take to rewrite it?
  • What does extended support cost and how long can we continue with it?
  • What are the total costs for migration to Drupal 10 versus another system?
  • Do we have an emergency plan if the site gets hacked tomorrow?

Pitfalls

  • "We'll wait a bit until things calm down": every month of delay makes migration more expensive and riskier.
  • "We've never had problems before": data breaches don't announce themselves.
  • "Extended support solves this": that buys you time, but doesn't solve the problem structurally.
     

Solution: schedule a scan now and establish a realistic timeline. That way you stay in control.

Ready for the next step?

Want to know what a migration means for your site? I offer a free migration scan: 30 minutes, in which you get a cost and time estimate, without obligations.

Frequently asked questions

Since when has Drupal 7 stopped receiving security updates?

Since 5 January 2025. New vulnerabilities since then stay open and are no longer patched.

What is the risk if I do nothing now?

Risk of data breaches, GDPR fines and reputational damage. On top of that, migrating gets more expensive the longer you wait, complexity grows every month.

How do I quickly find out how urgent my situation is?

With a 30-minute quick scan: which version is running, how much custom code and integrations exist, what is business-critical, and what a realistic timeline looks like.

What can I do now without migrating right away?

Five quick wins: make a full backup, check your firewall, disable unused components, monitor for suspicious activity, and discuss the risk internally.

Does extended support structurally solve the problem?

No, it buys you time, but the underlying vulnerabilities of an outdated platform remain.

A question about this topic?

Briefly describe your situation, and I'll let you know what's going on and what it would cost. No sales pitch.

Privacy policy

Who we are

This policy applies to David Porschmann (freelance web developer).
Contact: support@porschmann.be.

What data we process

Name, email address, company name (optional), and your message or enquiry. When you visit our website, we also process limited technical data (such as IP address and browser type) for security and analytics purposes.

Why we process your data (legal basis)

  • To respond to your enquiry or provide a quotation (consent or pre-contractual necessity).
  • For administration and invoicing during collaboration (contractual necessity).
  • For security and troubleshooting (legitimate interest).

Retention periods

Contact form submissions: maximum of 24 months.
Client records and invoicing: according to legal retention periods.

Sharing with third parties

We do not share your data with third parties, except with processors who help us host the website, send emails, or handle administration. Data processing agreements have been concluded with these partners.

Your rights

Right of access, rectification, erasure, restriction, data portability, and withdrawal of consent.
Email us at support@porschmann.be.

Security

We take appropriate technical and organisational measures to protect your data.

Cookies and analytics

Brief explanation of the tools used (e.g. Matomo, Clarity, GA) and a link to the cookie policy, if applicable.

Contact

Questions about this policy?
support@porschmann.be

More to read