Fifteen years of building and rescuing websites, and here is the pattern I trust more than any benchmark: when a Drupal site gets breached, it is almost always because a patch sat there unapplied for months. When other platforms get breached, it is usually because of something the owner never chose, never installed deliberately, and could not have audited.

That is not luck. It is structure.

Drupal has a dedicated security team, coordinated disclosure, and a published risk score on every advisory. Releases land on a predictable schedule, so patching is something you plan rather than something that ambushes you the week before a launch.

Compare that to the usual alternative, where the published vulnerabilities are overwhelmingly not in core at all. They are in the plugin someone installed in 2019 to add a slider, whose author stopped answering email in 2021. That risk was never signed off by anyone. It just accumulated.

Drupal's ecosystem is smaller. People say that like it's a weakness. For anything handling citizen data or a public institution's reputation, a smaller and more governed surface is the feature you are paying for.

So: patch it, hand it over, or freeze it into static HTML and let it stop being an attack surface.

Boring is not a compromise. Boring is what security looks like when it is working.