Drupal 7 End of Life: What It Means and What to Do Now
Drupal 7 has been end-of-life since January 2025, with new module vulnerabilities still surfacing every month.

Drupal 7 reached end of life on January 5, 2025, fourteen years after its release. The Drupal Security Team no longer issues security advisories or patches for Drupal 7 core or contributed modules. Sites still on Drupal 7 receive no upstream fixes.
What does end of life mean for Drupal 7?
After January 5, 2025, the Drupal community no longer provides new features, bug fixes, or security updates for Drupal 7. All Drupal 7 branches are marked unsupported, packaging feeds are shut off, and sites may be flagged as insecure by third-party scanners. CVEs can now be disclosed publicly without a fix.
Drupal 7 keeps working. What ends is the supply of fixes for anything discovered from that point forward.
Is Drupal 7 still a security risk after end of life?
Yes. Since end of life, vulnerabilities continue to surface in widely used contributed modules, including Cross-Site Scripting and access-control flaws, many with high severity. These are foundational modules that appear across many production sites, not obscure edge cases.
The difference now is that these issues are no longer eligible for official Drupal 7 fixes, even when the same class of flaw is being fixed in modern Drupal versions.
Why is running Drupal 7 a compliance problem?
Most compliance frameworks, including PCI DSS, HIPAA, SOC 2, ISO 27001, and FedRAMP, share one expectation: known vulnerabilities must be remediated within defined timelines. Once upstream support ends, there is no official channel to patch a CVE, so the gap becomes documented and auditable. "Nothing has happened yet" does not reduce the risk, because CVEs are public, which increases the risk of exploitation.
What are your options for a Drupal 7 site?
For most organizations, migrating to modern Drupal is the correct long-term strategy, but the path from Drupal 7 to the latest Drupal version is usually a full rebuild that can take many months, and many Drupal 7 platforms support business-critical processes.
That timing gap is what extended support is designed to cover. HeroDevs is a certified vendor in the Drupal Association's Extended Security Support Provider Program, and its Drupal 7 Never-Ending Support provides ongoing security updates for core and modules while a migration is in progress.
Frequently asked questions
When did Drupal 7 reach end of life?
January 5, 2025, exactly fourteen years after its release.
Are new vulnerabilities still found in Drupal 7?
Yes. They continue to surface in widely used contributed modules.
Is it a compliance violation to run Drupal 7?
It is not automatic, but most frameworks require timely remediation of known vulnerabilities, which is not possible without upstream patches. There are several unpatched Drupal 7 CVEs.
Can I get security support for Drupal 7 after end of life?
Yes. HeroDevs offers Never-ending Support for Drupal 7, addressing vulnerabilities of all security levels.
Do I still have to migrate if I buy extended support?
Extended support is a bridge that secures your organization while you plan and execute migration.
Resources
View All Articles


