MultiCmsManager

Drupal 7

Drupal 7 has reached end of life: how to protect the sites still running it

Drupal 7 support ended on 5 January 2025, yet according to drupal.org almost a third of Drupal sites still use it. Until the migration is ready, those sites need closer watching than the others.

The problem

New vulnerabilities will stay open.

Every flaw found in Drupal 7 from now on gets no official fix. It is the CMS hit by Drupalgeddon and Drupalgeddon2, and attackers still look for these sites.

The 2014 Drupalgeddon malware hid in the database, in the menu_router table, where a file scan never looks.

How it works

A module built for Drupal 7.

  1. 1

    Install the Drupal 7 module

    Same machine name as the module for Drupal 8 and later, written to run even on PHP 7.1.

  2. 2

    Watching

    Core integrity against the official archive, new administrators, suspicious files, dangerous callbacks in menu_router, PHP filter module enabled.

  3. 3

    Backups and migration

    Regular encrypted backups and the end-of-life alert, until the site moves to a supported release.

In detail

What you can do until you migrate.

  • Drupal 7.x, even on PHP 7.1
  • End-of-life alert, which you can ignore on sites you are not migrating yet
  • Critical alert for callbacks like file_put_contents or assert in the menu
  • Alert when update.php is open without login
  • Encrypted, incremental backups to roll back when needed

FAQ

Frequently asked questions

Is Drupal 7 still supported?

No. Official security fixes ended on 5 January 2025. Plan the migration to Drupal 10 or 11.

Does the module run on PHP 7.1?

Yes, the Drupal 7 module runs even on PHP 7.1, encrypted backups included.

Try it on your clients' sites.

During the beta we let in a few agencies at a time and set up the first sites with you.