Drupal suits publishers with complex content, several editorial roles or many languages, because core ships content moderation, multilingual modules and JSON:API. The trade-off is a heavier build: SEO helpers such as URL patterns, meta tags and sitemaps are contributed modules, and a developer-led team is usually needed to set it up well.
What is Drupal?
Drupal is content management software that Drupal.org says is distributed under the GNU General Public License with no licensing fees. The Drupal Association is the non-profit that supports the project. The history page says Dries Buytaert decided to release the software behind drop.org in January 2001, so it is one of the older systems in this directory.
Drupal sits at the build-it-properly end of the spectrum. It is aimed at organisations with developers or an agency, and it is used where content has many types, many editors or many languages.
| Fact | Detail |
|---|---|
| Licence | GNU GPL version 2 or later |
| Latest version | 11.4.9 (9 October 2026) per the repository tags |
| Written in | PHP (11.x requires 8.3 or later) |
| Database | MariaDB, MySQL, PostgreSQL or SQLite |
| Hosting | Self-hosted on Apache, Nginx or similar; Linux recommended; Composer used for installs |
| Price | Software free; hosting and development extra |
| Made by | Drupal community, supported by the Drupal Association |
See the licence guide for what GPL means in practice.
Who is Drupal best for?
It suits a publisher that treats content as structured data: a magazine with distinct content types, several desks with different permissions, a news group publishing in several languages, or a site that feeds an app through an API. It also suits teams that want formal moderation states.
It is a poor match for a solo writer who wants a site live this week, or a team with no developer access. Compare WordPress for the simpler route, or Backdrop CMS for a lighter system with Drupal roots.
Editorial workflow
The Drupal User Guide has chapters on managing user accounts, with users, roles and permissions, and on setting up content structure, with taxonomy. The roles you define are yours to shape, so a desk-by-desk permission model is a configuration task rather than a plugin hunt.
The core Content Moderation module is the editorial piece. According to its documentation it adds workflows built from states such as Draft, Published and Archived and the transitions between them. A published version can stay live while a separate working copy is reviewed, and enabling the module creates a default Editorial workflow. You grant permissions to roles so authors can save drafts and editors can publish.
Scheduling is not part of that description. The contributed Scheduler module covers it: editors can schedule content, media, commerce products and taxonomy terms for publishing and unpublishing at set times. We have not verified how it interacts with moderation states, so test that combination.
SEO, structured data and feeds
This is where Drupal asks the most of you. Several SEO features come from contributed modules, each verified on its Drupal.org project page:
- Pathauto generates URL aliases for nodes, taxonomy terms and users from patterns. The project page reports 470,202 sites using it.
- Metatag provides page titles, canonical URLs, descriptions, Open Graph and Twitter Cards.
- Schema.org Metatag is a separate module for schema.org and JSON-LD, according to the Metatag page.
- Simple XML Sitemap produces sitemaps with hreflang and image support and supports IndexNow.
We did not verify RSS and feed behaviour in the pages we opened, so we make no claim about it here. Confirm it against your version before relying on it. The features checklist lists what to test.
Media, multilingual and performance
Multilingual is a strength. The User Guide says the base language of Drupal software is English and that the core Language module is required for any other language. Three further core modules handle different layers: Interface Translation for built-in text, Configuration Translation for things like field labels and site names, and Content Translation for the content itself. This is more granular than most systems, and more to configure.
We did not open documentation on core media handling, so we make no claim about it. For performance, the User Guide describes several cache types, including render and views caches, and ways to clear them from the admin interface or with Drush. Page and reverse-proxy caching strategy for a high-traffic news site is something to confirm with your developer or host.
Hosting and requirements
The 11.x branch of Drupal core requires PHP 8.3.0 or later in its composer.json. The requirements page lists MariaDB, MySQL, PostgreSQL and SQLite as database servers, says Drupal works on Apache, Nginx and other web servers, and recommends Linux or a similar operating system for hosting. Windows is supported only for development environments. Composer is needed for installation and updates.
That last point matters operationally. Updates are done through Composer, so whoever looks after the site needs command-line comfort. The releases page also shows Drupal 10.6.x receiving security support only until December 2026, so a site on an older branch has a deadline.
Extending Drupal
Drupal.org says the system extends through modules and themes. We did not verify a total count, so we give none. The Metatag, Pathauto, Scheduler and sitemap modules above show the pattern: core stays lean and contributed modules fill gaps.
For integrations, the JSON:API module is part of core. Its documentation describes it as an opinionated, zero-configuration way to allow RESTful create, read, update and delete operations on a site’s content, which suits a decoupled front end or an app. See our headless guide for the wider trade-offs.
What Drupal costs
The licence is free. The cost is in building and maintaining it: a developer or agency to model content types, configure moderation and roles, build the theme, install and test modules, and apply updates through Composer. We have not verified public prices for hosts or agencies, so we give no figures. See the cost guide.
Where Drupal falls short
- SEO and structured data depend on contributed modules, not core.
- Setup needs developer skill, including Composer.
- Scheduling is a contributed module, not a core feature, from what we opened.
- Older major branches reach end of security support on fixed dates, which creates upgrade work.
- Windows is supported only for development, so production hosting is expected to be Linux or similar.
What a sensible Drupal evaluation looks like
Scope a pilot around one desk. Ask your developer to model your main content types, enable Content Moderation with the Editorial workflow, and create roles for writer, sub-editor and publisher. Then add the contributed modules named above, Pathauto, Metatag, Schema.org Metatag and Simple XML Sitemap, and check their output against Google’s documentation.
Add Scheduler and test it with moderation states. Finally, ask what the update routine will be: who runs Composer updates, how quickly security releases are applied, and how the site will move from 11.x to 12 once it is stable. Those answers show whether you have the people to run Drupal, which matters more than any feature list.
The verdict for publishers
Drupal is the stronger tool when your publication has real structure: several content types, several roles with different rights, formal moderation, several languages or an API consumer. Core covers moderation, multilingual and JSON:API, and the contributed ecosystem covers SEO and scheduling.
For a small publication without developer time it is more machine than you need. WordPress will be quicker to launch, and Joomla sits in between. This profile is based on vendor documentation, not an install of our own; see how we test.
Questions people ask
Is Drupal free?
The software has no licence fee: Drupal.org says it is distributed under the GNU GPL with no licensing fees. You still pay for hosting, development, maintenance and any commercial services. Sites with complex needs usually spend most of the budget on development time rather than software.
What is the latest Drupal version?
The repository's tag list shows 11.4.9 as the newest stable release, tagged on 9 October 2026. Drupal 12.0.0-beta1 exists but is a pre-release. The releases page says Drupal 10.6.x receives security support until December 2026.
Does Drupal have editorial workflow built in?
Yes. The core Content Moderation module adds workflow states such as Draft, Published and Archived, with transitions between them, and creates a default Editorial workflow. Scheduled publishing is not described there, and the contributed Scheduler module covers it.
Is Drupal good for SEO?
It can be, but several SEO features come from contributed modules rather than core. Pathauto handles URL aliases, Metatag handles meta tags and Simple XML Sitemap handles sitemaps. Schema.org structured data needs a further module. Plan to install and configure them.
Can Drupal be used as a headless CMS?
Yes. JSON:API is part of core and provides RESTful access to content entities with no configuration. You still build and host the separate front end, and you should check how access control and caching behave for your publication.
How does Drupal handle multiple languages?
Through core modules: Language, Interface Translation, Configuration Translation and Content Translation. The User Guide treats interface text, configuration text and content as separate things to translate, which gives control but adds set-up work.
Sources
- The tag list of the Drupal repository shows Drupal 11.4.9, dated 9 October 2026, as the newest stable tag, ahead of 12.0.0-beta1 dated 30 September 2026, which is a pre-release. — source, checked 10 October 2026.
- The Drupal.org core releases page lists Drupal 11.4.9, 11.3.18 and 10.6.18 as bugfix releases, 12.0.0-beta1 as a testing release, and says Drupal 10.6.x receives security support until December 2026. — source, checked 10 October 2026.
- Drupal, and all contributed files that are derivative works of Drupal hosted on Drupal.org, are licensed under the GNU General Public License, version 2 or later. — source, checked 10 October 2026.
- Drupal.org describes Drupal as content management software, says it is distributed under the GNU General Public License, that there are no licensing fees, and that the Drupal Association is the non-profit supporting the project. — source, checked 10 October 2026.
- Drupal.org's history page says it was not until January 2001 that Dries Buytaert decided to release the software behind drop.org. — source, checked 10 October 2026.
- The composer.json of the Drupal core repository's 11.x branch requires PHP 8.3.0 or later and describes Drupal as an open source content management platform powering millions of websites and applications. — source, checked 10 October 2026.
- Drupal's system requirements page lists MariaDB, MySQL, PostgreSQL and SQLite as database servers, says Drupal works on Apache, Nginx and other web servers, recommends Linux or a similar operating system for hosting with Windows supported only for development, and says Composer is needed for installation and updates. — source, checked 10 October 2026.
- The core Content Moderation module expands the unpublished and published states with workflows made of states such as Draft, Published and Archived and the transitions between them, lets a published version stay live while a working copy is reviewed, and creates a default workflow called Editorial when enabled. — source, checked 10 October 2026.
- The Drupal User Guide covers users, roles and permissions in its chapter on managing user accounts, and taxonomy in its chapter on setting up content structure. — source, checked 10 October 2026.
- The contributed Scheduler module lets editors schedule content, media, commerce products and taxonomy terms for publishing and unpublishing at specified dates and times in the future. — source, checked 10 October 2026.
- The contributed Pathauto module automatically generates URL path aliases for nodes, taxonomy terms and users without requiring a manual path alias, and the project page reports 470,202 sites using it. — source, checked 10 October 2026.
- The contributed Metatag module provides meta tags including page titles, canonical URLs, descriptions, Open Graph and Twitter Cards; its page says schema.org and JSON-LD support is provided by the separate Schema.org Metatag module. — source, checked 10 October 2026.
- The contributed Simple XML Sitemap module generates multilingual sitemaps for entities, views and custom links, supports hreflang and image sitemaps, and supports the IndexNow protocol. — source, checked 10 October 2026.
- The Drupal User Guide says the base language of Drupal software is English, that the core Language module is needed to use another language, and that the core Interface Translation, Configuration Translation and Content Translation modules cover interface text, configuration text and content respectively. — source, checked 10 October 2026.
- The JSON:API module is part of Drupal core; it implements the JSON:API specification for Drupal entities and provides a zero-configuration, opinionated way to allow RESTful CRUD for a site's content. — source, checked 10 October 2026.
- The Drupal User Guide describes clearing caches through Configuration, Development, Performance, or with Drush commands, and lists cache types including theme-registry, menu, css-js, block, render and views. — source, checked 10 October 2026.