26.6% of Drupal websites that show their version run Drupal 7, 8 or 9, releases that have reached end of life and no longer get security fixes. Drupal 7, retired in January 2025, is still the most common of the three.
Analysis of 956 Drupal websites · public websites running Drupal, September 2026
Key Findings
- 1.26.6% of Drupal websites that show their version run Drupal 7, 8 or 9, releases that no longer receive security fixes.
- 2.13.8% of Drupal websites that show their version still run Drupal 7, which reached end of life in January 2025, more than Drupal 8 and 9 combined.
- 3.12.8% of Drupal websites that show their version run Drupal 8 or 9, which can reach a supported release with an upgrade rather than a rebuild.
- 4.40.3% of Drupal websites that show their version run Drupal 10, the most common release, and 33.1% run the newest, Drupal 11.
- 5.Drupal websites announce their server software 12.8% of the time, the highest rate of nine website platforms and more than twice the 5.3% across all websites.
Summary
Three organizations each launched a Drupal website in the early 2010s. Two of them have since moved to Drupal 10. The third still runs Drupal 7, which stopped getting security fixes in January 2025, and every new weakness found in it since then stays open.
Drupal is used by many larger organizations, and it has a strong security team. But that team supports each major version for a fixed period, and moving from Drupal 7 to a modern release is closer to a rebuild than an update, so the oldest websites tend to wait the longest.
Most Drupal websites are on a supported release. 26.6% are not: they run Drupal 7, 8 or 9, and more than half of those are still on Drupal 7.
What we measured
In September 2026 we checked 956 public websites running Drupal, mostly in the US. 718 of them show their major Drupal version, and we grouped those by version. We also recorded whether each website redirects visitors to its secure https:// address, whether its server announces its software, and which version of the jQuery code library it loads, and ran the same checks on 25,708 websites across nine platforms.
A release reaches end of life when the Drupal project stops publishing security fixes for it. Drupal 7, 8 and 9 have all reached that point, so we count them as outdated; Drupal 10 and 11 are supported. A website has no HTTPS redirect when typing or following the plain http:// address leaves the visitor on the unencrypted page instead of moving them to the secure https:// version, which browsers label "Not secure". A server that shows its software names the program it runs in its response headers, information most security guides recommend keeping private.
One in four Drupal websites runs an unsupported release
Drupal 10 is the largest group, on 40.3% of Drupal websites that show a version, and Drupal 11 is close behind at 33.1%. The rest are on releases that no longer get fixes: 13.8% on Drupal 7, 7.8% on Drupal 9 and 5% on Drupal 8. The Drupal 7 group, 99 websites, is larger than Drupal 8 and 9 combined.
Drupal 7 websites wait longest because the move is hardest. Drupal 8 rebuilt the system from the ground up, so leaving Drupal 7 means rebuilding the site's structure, theme and custom modules rather than running an update.
Source: Suff Digital analysis of 956 Drupal websites · public websites running Drupal, September 2026
| Drupal version | Drupal websites | Share of Drupal websites showing a version | Gets security fixes |
|---|---|---|---|
| Drupal 7 | 99 | 13.8% | No |
| Drupal 8 | 36 | 5% | No |
| Drupal 9 | 56 | 7.8% | No |
| Drupal 10 | 289 | 40.3% | Yes |
| Drupal 11 | 238 | 33.1% | Yes |
Drupal 8 and 9 websites are the quickest wins
12.8% of Drupal websites that show their version run Drupal 8 or 9. Unlike Drupal 7, those releases share their architecture with Drupal 10 and 11, so bringing them up to date is an upgrade, not a rebuild: update the code, replace retired modules and test.
Old jQuery is a second sign of an old Drupal install. Drupal 7 core shipped an old jQuery release, and where a Drupal website shows its jQuery version, 36.8% load one older than 3.5.0, the release that fixed two publicly documented security flaws.
Drupal websites show their server software more than any other platform
12.8% of Drupal websites name their server software in response headers, the highest rate of the nine platforms, ahead of OpenCart at 11%, and more than twice the 5.3% across all 25,708 websites. That is a hosting setting, and it takes minutes to turn off.
On the other checks Drupal does well. 7.4% of Drupal websites do not redirect visitors from http:// to https://, below the 9.1% across all websites and far below OpenCart's 19.3%.
Source: Suff Digital analysis of 956 Drupal websites · public websites running Drupal, September 2026
| Platform | Websites | No redirect from http:// to https:// | Show server software |
|---|---|---|---|
| WordPress | 7,515 | 4.9% | 4.8% |
| Drupal | 956 | 7.4% | 12.8% |
| Joomla | 707 | 12.5% | 7.6% |
| Magento | 550 | 8.9% | 7.5% |
| PrestaShop | 387 | 4.9% | 6.5% |
| OpenCart | 426 | 19.3% | 11% |
| Shopify | 1,636 | 1.4% | 0.1% |
| Squarespace | 2,004 | 6.3% | 0.05% |
| Wix | 1,853 | 0.1% | 0% |
| All websites | 25,708 | 9.1% | 5.3% |
What this means for Drupal site owners
If you are on Drupal 7, budget for the move now. Every month on an unsupported release adds weaknesses that will never be fixed, and the move is a rebuild, so it needs a plan: an inventory of content types, custom modules and integrations, and a decision on whether to rebuild on Drupal 11 or another platform.
If you are on Drupal 8 or 9, schedule the upgrade to Drupal 10 or 11 as a contained project, and in the meantime ask your host to hide server software details.
Whichever you choose, protect what the site has earned in search. Experienced drupal migration services map every old URL to its new home so rankings and links carry over.
Embed this research
Paste this on your site to embed the charts. It links back to the source automatically.
<iframe id="sd-drupal-version-health" src="https://www.suffdigital.com/embed/data-studies/drupal-version-health" width="100%" height="600" style="width:100%;border:1px solid #E5E7EB;border-radius:12px" loading="lazy" title="27% of Drupal Websites Run a Version That No Longer Gets Security Fixes - Suff Digital"></iframe>
<script>window.addEventListener("message",function(e){if(e&&e.data&&e.data.sdEmbed==="drupal-version-health"&&e.data.height){var f=document.getElementById("sd-drupal-version-health");if(f){f.style.height=e.data.height+"px";}}});</script>
<p style="font:14px/1.5 system-ui,sans-serif">Source: <a href="https://www.suffdigital.com/resources/data-studies/drupal-version-health">27% of Drupal Websites Run a Version That No Longer Gets Security Fixes - Suff Digital</a></p>
Cite this study
Suff Digital. (2026). 27% of Drupal Websites Run a Version That No Longer Gets Security Fixes. https://www.suffdigital.com/resources/data-studies/drupal-version-health
27% of Drupal Websites Run a Version That No Longer Gets Security Fixes - Suff Digital - https://www.suffdigital.com/resources/data-studies/drupal-version-health
Frequently asked questions
Related studies
- Website Maintenance44.5% of WordPress Sites Are Behind the Latest Release, and Popular Sites Barely Do Better
- Website Maintenance83% of PrestaShop Websites Showing a jQuery Version Run One With Known Flaws vs 36.1% Web-Wide
- Website Maintenance61.6% of Websites Skip HSTS, the Security Header That Forces Secure Connections
- Website Maintenance48.1% of Websites That Show Their PHP Version Run One With No Security Fixes
