Drupal 7
Drupal 7 has reached end of life: how to protect the sites still running it
Drupal 7 support ended on 5 January 2025, yet according to drupal.org almost a third of Drupal sites still use it. Until the migration is ready, those sites need closer watching than the others.
The problem
New vulnerabilities will stay open.
Every flaw found in Drupal 7 from now on gets no official fix. It is the CMS hit by Drupalgeddon and Drupalgeddon2, and attackers still look for these sites.
The 2014 Drupalgeddon malware hid in the database, in the menu_router table, where a file scan never looks.
How it works
A module built for Drupal 7.
- 1
Install the Drupal 7 module
Same machine name as the module for Drupal 8 and later, written to run even on PHP 7.1.
- 2
Watching
Core integrity against the official archive, new administrators, suspicious files, dangerous callbacks in
menu_router, PHP filter module enabled. - 3
Backups and migration
Regular encrypted backups and the end-of-life alert, until the site moves to a supported release.
In detail
What you can do until you migrate.
- Drupal 7.x, even on PHP 7.1
- End-of-life alert, which you can ignore on sites you are not migrating yet
- Critical alert for callbacks like
file_put_contentsorassertin the menu - Alert when
update.phpis open without login - Encrypted, incremental backups to roll back when needed
FAQ
Frequently asked questions
Is Drupal 7 still supported?
No. Official security fixes ended on 5 January 2025. Plan the migration to Drupal 10 or 11.
Does the module run on PHP 7.1?
Yes, the Drupal 7 module runs even on PHP 7.1, encrypted backups included.
Related features
Goes well with
Try it on your clients' sites.
During the beta we let in a few agencies at a time and set up the first sites with you.