Blog
As of January 5, 2025, your Drupal 7 website no longer receives security updates.
New vulnerabilities will remain unpatched,
significantly increasing the risk of data breaches, GDPR fines and reputational damage.
TL;DR
- Drupal 7 stopped receiving security updates on January 5, 2025.
- New vulnerabilities remain open and will not be patched.
- This means risk of data breaches, GDPR fines and reputational damage.
- Delaying makes migration more expensive: complexity grows month by month.
The problem: your website is exposed to attackers
The Drupal Security Team has not published security updates for Drupal 7 since 5 January 2025.
New vulnerabilities remain open.
Hackers can exploit vulnerabilities without a patch ever coming.
For your business this means:
- Data breaches: customer data, login credentials and contact info are left unprotected.
- GDPR risk: an outdated system doesn't meet the required appropriate technical measures.
- Reputational damage: customers trust you less after a data breach.
Simply explained: what is end-of-life?
End-of-life means that the makers of Drupal 7 no longer release security patches.
If a major vulnerability is discovered tomorrow, it stays open.
No update, no solution.
Anyone who knows about the vulnerability can exploit it.
Why this matters in 2026
Drupal 7 has been without support for over a year now. Every month that passes:
- Known vulnerabilities grow.
- Your site becomes an easier target for automated attacks.
- Custom code and integrations become harder to migrate.
What is still a manageable migration today will become a complex and expensive project later.
Know where you stand in 30 minutes
You don't need to create a full migration plan right away.
Start with a quick scan:
- Which version is currently running?
- How much custom code and integrations are there?
- Which functionality is business-critical?
- What is a realistic timeline?
Such a scan gives you an estimate of costs, time and risks.
Then you can make an informed decision.
5 quick wins to reduce risk
- Make a full backup now: if something goes wrong tomorrow, you'll otherwise lose data.
- Check your firewall: a good firewall blocks many attacks, but doesn't solve the underlying problem.
- Disable unused components: less code means less attack surface.
- Monitor suspicious activity: get alerts for unusual login attempts or file changes.
- Discuss this internally: make sure everyone knows this risk exists and that it has priority.
What to ask your developer
- Which Drupal 7 components are we using and are they still maintained?
- How complex is our custom code and how much time does it take to rewrite it?
- What does extended support cost and how long can we continue with it?
- What are the total costs for migration to Drupal 10 versus another system?
- Do we have an emergency plan if the site gets hacked tomorrow?
Pitfalls
- "We'll wait a bit until things calm down": every month of delay makes migration more expensive and riskier.
- "We've never had problems before": data breaches don't announce themselves.
- "Extended support solves this": that buys you time, but doesn't solve the problem structurally.
Solution: schedule a scan now and establish a realistic timeline. That way you stay in control.
Ready for the next step?
Want to know what a migration means for your site? I offer a free migration scan: 30 minutes, in which you get a cost and time estimate, without obligations.
Frequently asked questions
Since when has Drupal 7 stopped receiving security updates?
Since 5 January 2025. New vulnerabilities since then stay open and are no longer patched.
What is the risk if I do nothing now?
Risk of data breaches, GDPR fines and reputational damage. On top of that, migrating gets more expensive the longer you wait, complexity grows every month.
How do I quickly find out how urgent my situation is?
With a 30-minute quick scan: which version is running, how much custom code and integrations exist, what is business-critical, and what a realistic timeline looks like.
What can I do now without migrating right away?
Five quick wins: make a full backup, check your firewall, disable unused components, monitor for suspicious activity, and discuss the risk internally.
Does extended support structurally solve the problem?
No, it buys you time, but the underlying vulnerabilities of an outdated platform remain.
A question about this topic?
Briefly describe your situation, and I'll let you know what's going on and what it would cost. No sales pitch.