Web Development
Drupal or Joomla Website? Keep It, Upgrade It, or Move to WordPress
Thousands of organisations still run Drupal 7 and Joomla 3 sites that have passed end of life. Each has three honest options. This is how we help owners choose between them, and what each one costs in practice.

Drupal and Joomla were the serious choices for organisation websites through the 2010s: universities, councils, membership bodies, multi-language company sites. Many of those sites are still running, still doing their job, and now sitting on versions that no longer receive security fixes. Drupal 7 reached end of life in January 2025. Joomla 3 did in 2023. The owners we speak to are not negligent; they simply have a site that works and a decision they have been putting off.
Our Drupal and Joomla service covers all three paths below. The point of this article is to help you pick one.
First, What Is Actually at Risk
An unsupported CMS is not an immediate catastrophe, but it is a slowly widening door. New vulnerabilities in the core, in PHP, and in the dozens of modules or extensions a typical site uses will not be patched. Automated scanners find these sites within days of a disclosure. We clean up the aftermath often enough through our hacked website cleanup service to say plainly: the cost of a breach is always more than the cost of the decision you are avoiding.
Option 1: Keep It, Safely
Some sites should stay where they are for now. A Drupal site with complex content types, workflows, multilingual content and integrations that WordPress would struggle to reproduce is a candidate. So is a site that is being replaced in eighteen months anyway.
Keeping it safely means more than leaving it alone: a web application firewall in front, PHP pinned to a version the site tolerates, file permissions locked, admin behind an extra login, backups tested, and a monitor that notices change. Extended-support programmes exist for Drupal 7 and are worth their fee for a year or two of breathing room. This is a holding pattern, not a destination.
Option 2: Upgrade Within the Same Family
Drupal 7 to Drupal 10 or 11 is a migration in all but name: the architecture changed completely, and content is moved across rather than updated in place. Modules must be found again or rewritten. The theme is rebuilt. For a content-rich site with structured data, editorial workflow and several languages, this is still often the right answer, because what you end up with is a modern platform that does exactly what the old one did, only better.
Joomla 3 to 4 or 5 is gentler but not trivial. Templates and extensions are the risk; many popular ones were abandoned at the version boundary. We audit every extension first and tell you which have a path forward, which have a replacement and which will need custom work.
Option 3: Move to WordPress
For most small and mid-sized organisation sites, the honest answer is that WordPress will do everything the old site did, with a far larger pool of people able to maintain it, lower running costs and an editing experience staff already know from somewhere else. The structured content Drupal is good at can be reproduced with custom post types and fields, and the result is usually faster to edit and cheaper to host.
When a dental group with nine practices moved from an ageing CMS to WordPress, the win was not the technology but that each practice manager could finally update their own opening hours. That is the typical shape of a successful move: fewer moving parts, more people able to help themselves. Our WordPress development team builds the new site; our migration service handles the move itself.
Whichever You Choose, Protect the Rankings
A CMS change is where organisations lose search traffic, and it is entirely avoidable. Every old URL needs a destination, either kept identical or redirected one-to-one. Titles, descriptions, headings and image text come across unchanged. The XML sitemap is resubmitted on the day. We run a crawl of the old site before and of the new site after, and the two lists must match. The technical SEO checklist we use is public; it applies to any platform change.
How to Decide in an Afternoon
- Count the content types, languages and integrations. Many, and complex: upgrade within Drupal. Few, and simple: WordPress.
- Ask who edits the site. A trained web team: either. Busy staff with other jobs: WordPress.
- Check the extensions. If the site depends on modules nobody maintains, the rebuild cost is similar either way; choose the platform you want for the next ten years.
- Look at the replacement date. Under two years out: keep it safely and spend the money on the replacement.
If you are not sure which bucket you are in, send us the site address. We can tell from a crawl and a look at the admin which option fits, and the review costs nothing. For the broader question of what the new site should be built on, our comparison of custom websites and WordPress is the next thing to read.


