// Blog
// CMS, Security, Optimization

My CMS is outdated – what now?

How to tell that your content management system is outdated, what can happen in the worst case, and which ways lead out of the dead end

Diagram: three ways out of an outdated CMS – update, move and keep the design, or start over

Your website has been running for years, somehow. In the backend, the area where you edit your content, a notice says that updates are no longer possible, your hosting provider keeps sending warning emails, and all you actually wanted was to quickly change your opening hours. At the latest by then, the question comes up: how bad is this – and what do I do now?

In this article I show you how to recognise an outdated content management system (CMS), what consequences it can have and which options you have. My example is a project where exactly this happened.

How to recognise an outdated CMS

A CMS rarely becomes outdated overnight. There are usually warning signs over months or years that are easy to miss:

  • There are no more updates. The vendor has discontinued the version you use, or an update fails because the gap has become too large.
  • The PHP version has reached the end of its life. Most CMS run on the programming language PHP. Each PHP version only receives security updates for a few years, then no more. You can see which versions are currently supported on the official PHP page. An old CMS often only runs on an old PHP version – and so keeps the entire website stuck in an insecure state.
  • Plugins and extensions are no longer maintained. A contact form, a gallery or a calendar in particular often come from third parties. When their developers stop, the extension stays where it is.
  • Your hosting provider warns you. Many providers switch off old PHP versions at some point or charge extra for them. Large German providers such as IONOS (German) or STRATO (German) add a paid "PHP Extended Support" for outdated PHP versions if you don't switch in time. They announce this by email beforehand – emails you shouldn't ignore.
  • The layout breaks. Images are missing, menus shift, the site is barely readable on a smartphone, or cryptic error messages appear.
  • You no longer dare to change anything. If every change in the backend gives you a queasy feeling, that's a warning sign too.

What happens in the worst case

An outdated system is more than a cosmetic flaw. Two risks stand out.

Security holes. Known vulnerabilities in old CMS and plugin versions are documented publicly. Attackers scan automatically for websites that still use these versions. So nobody needs to be interested in you specifically – it's enough that your site can be found. The consequences range from spam pages quietly appearing on your domain to stolen form data. With forms that collect personal data, data protection issues come into play as well.

Total failure. At some point the old system no longer fits the environment it runs in. The hosting provider updates the server, and the website shows nothing but an error message – or nothing at all.

I experienced exactly this in a client project. The website's CMS was outdated and could no longer be updated. First errors appeared, then the website went down completely. The first person to notice was a visitor who tried to open the site. After that, it was unreachable for a good few days.

What options you have

If you find that your CMS is outdated, there are basically three ways forward. Which one fits depends on how old the system is and how happy you are with your website.

1. Update

If the system is only a few versions behind and is still maintained by the vendor, an update is often the quickest and cheapest way. Before you start, make a complete backup of files and database. It's also worth checking whether all plugins support the new version.

This way no longer works if the CMS itself has been discontinued or important extensions no longer exist.

2. Move and keep the design

Clients are often quite happy with how their website looks. The problem is just the technology underneath. In that case the website can be rebuilt in a current CMS while keeping the existing design. Ideally visitors barely notice anything – except that the site works reliably again.

This involves transferring the content, reviewing texts and images, and keeping the page structure as far as possible so that existing links and search engine rankings aren't lost.

3. Start over

If the website no longer suits you anyway, works poorly on smartphones or the content needs a fundamental overhaul, starting over often makes more sense. Then it isn't worth laboriously moving an old design into a new system.

How I handled this case

In this project we chose the second way: the CMS could no longer be updated, but the look of the website was to stay.

Working closely with the client, I kept the existing design and rebuilt the website with the CMS Statamic. What decided the choice of system was that the client can maintain and update her content herself, easily – without technical knowledge and without being afraid of breaking something.

From the decision to the new website took about two weeks. So that visitors wouldn't be faced with an error message during that time, I uploaded a simple maintenance page: a single static HTML file that needs neither a CMS nor PHP and therefore works on any server.

Today the client manages her content well. Part of the reason is that I recorded a few short videos for her, so-called screencasts, in which I show and explain the backend tasks that matter most to her. That way she can look up how something works at any time.

The advantage of this approach: the familiar look stays, and at the same time the website is technically back on a current foundation.

What you can do now

Even if your website is still running, a quick check is worthwhile:

  • Ask your hosting provider, or look in their customer area, which PHP version your website uses.
  • Check in the backend of your CMS whether updates are offered or warnings appear.
  • Find out whether there is a current backup of your website – and who has access to it in an emergency.
  • Have your website checked once with a tool such as Lighthouse. I described how to do that in the article Quality check of your own website.

Conclusion

An outdated CMS is no reason to panic, but it is a reason to act – before the website goes down. The sooner you react, the more options you have. Often the existing design can be kept, so little changes for you and your visitors, except that everything runs securely and reliably again.

If you're unsure how your website is doing, I'm happy to take a look. Modernising old systems is part of my transformation and improvement service. Just write to me, and we'll find the right way together.

Yours, Michael Becker