04 Aug 2026

feedDrupal.org aggregator

Drupal Association blog: Drupal Association 2025 Audit and Financial Overview

When I took on the role of Interim CEO, I committed to being direct about our finances and noted that our earlier audits already told much of the story. The board has now released our 2025 audit report, which was provided to the Board of Directors of the Drupal Association on 8 July 2026 and approved on 25 July 2026. It provides additional context and detail, but does not change the overall picture or our path forward.

To be clear, nothing in this audit means any of the services the project depends on are at risk. What this audit does is help us to understand the status quo so that we can take appropriate action moving forward.

The DA Has Been Operating With a Structural Deficit

The DA spent about $451,000 more on operations than we brought in last year (2025), and that followed a larger shortfall the year before ($923,000).

Those two years are not cleanly comparable, because the 2025 audit also restates our previously audited 2024 results. Our auditors determined that about $353,000 of membership revenue had been recognized in 2024 that should instead have been allocated to 2025, when it was actually earned. This was a non-cash correction to our books: no money changed hands, and nothing was lost or misspent.

Together, 2024 and 2025 produced a combined shortfall of about $1.15M, which averages roughly $573,000 a year. Our current forecast puts 2026 on the same path.

Chart of Revenues vs Expenses 2019-2025

Our cash reserves (the unrestricted funds we can actually spend on operations) have decreased by about 60% since the end of 2022, to roughly $960,000, which represents 2.3 months of operating expenses. Board policy sets a six-month target and a three-month reserve minimum. 2025 is the first year since 2019 that the DA has failed to meet the minimum. The DA remains a going concern and is not in danger of becoming insolvent, but it is time for action.

Unrestricted Assets (Reserves) by Month

Revenue Growth Has Not Covered the Costs of our Strategic Investments

Coming out of 2022 with strong reserves, the board approved a three-year strategic plan on 6 June 2023 and chose to put some of its surplus toward ambitious, community-requested investments in marketing and project support. Funding strategic growth is how excess reserves are best leveraged.

These investments have had a measurable impact:

  • Contributions to Drupal strategic product innovation tripled, reaching 211,037 organizational credits in 2025, a 54% increase over 2024.

  • We reached 106 Drupal Certified Partners under enhanced "maker" requirements, roughly double the 2022 figure.

  • 43 people were brought into Drupal leadership roles for the first time, against a goal of 38.

  • We adopted and executed a go-to-market plan for the launch of Drupal CMS, and built marketing capacity inside the DA for the first time.

However, the sustainability of these efforts long-term was tied to a goal which we did not meet:

  • Increase Drupal Association total revenues by 3X, from $3.49M in 2022 to $10.5M in 2026 to better support mission-driven activities.

Our reported revenue did grow about 25% between 2022 and 2025. While 2025 is one of our largest revenue years on record, this figure is misleading, because most of the growth is in non-monetary services provided in trade (described in more detail below). Putting that aside, the Association's cash revenue grew 5% over three years while out-of-pocket costs grew 27%.

The gap is paid for out of our reserves. Reserves are the right instrument for starting something and the wrong instrument for running it. Funding our strategic initiatives from reserves was the right decision for the duration of the strategic plan, but while that plan ended last year, the work has continued without a viable funding plan.

Marketing and project support are precisely the kind of mission-aligned work the DA should be doing. So the task in front of us is to fund it properly: each program examined discretely, with its own revenue plan, and held to revenue neutrality now that it has moved out of pilot and into operations.

Infrastructure Costs are Rising (and Invisible)

In 2022 we spent $1.3M running Drupal.org (the Web site, composer endpoints, GitLab, CI, authentication, and the global CDN), and in 2025 we spent $2.1M. That is up 61% in three years. It is the Drupal Association's single largest cost, and it has no direct funding mechanism. Every organization that uses Drupal relies on this infrastructure, but none of them are asked to pay for it, because we have never built a way for them to.

For most of Drupal's history that did not matter, because the surplus revenue from DrupalCon covered the costs of Drupal.org. However, since 2022 the DrupalCon surplus has fallen from about $994,000 to about $227,000. While event costs have continued to increase since we resumed in-person events, event revenue has gone down.

This means that we are increasingly relying on the generosity of a handful of vendors and partners who provide services for free or in trade for sponsorship placements. That generosity has grown from $249,249 in 2022 to $1,011,995 in 2025 and now covers nearly half of what we spend on Drupal.org. These services in trade and donated services have not reported in our monthly reports because they were "non-cash"; they appeared only at audit.

Share of what we spend on Drupal.org

2022

2025

Covered by DrupalCon surplus

76%

11%↓

Covered by services in trade, gratis

19%

48%↑

Covered by general operating revenue

4%

41%↑

The remainder of the infrastructure spending gap must be paid for out of general operating revenue, and failing that, out of reserves. These costs increased from $56,825 in 2022 to $859,384 in 2025.

It is also important to note that these numbers do not account for work that is deferred because the funding is not there to pay for it. This technical debt does not appear on any of our financial statements, but is a growing liability that will need to be paid for at some point.

The bottom line is that while our cash spending on infrastructure has remained steady, we have a rising essential cost that currently has no funding model attached to it yet.

Unpacking the Timeline

The fiscal year 2024 closed 31 December 2024. The initial audit for 2024 was released in July 2025 showing $570,000 of deficit. Then in July 2026, it was restated downward to a $923,000 deficit as part of the 2025 audit.

While the Drupal Association CEO is accountable for the organization's day-to-day operations, the board provides oversight over the organization's budget and finances. This oversight requires timely, accurate, and consistent financial reporting.

The monthly reports that the board's Finance Committee reviewed and the audited statements published 6 months after the year close were prepared on different bases, with nothing reconciling the two. The Finance Committee struggled to get consistent answers or clarity about what individual figures included. In April 2026, Finance Committee asked our auditors to examine the reporting revenue recognition practices directly. That request is what produced the restatement of 2024 as part of the 2025 audit. This also explains how long it took to know where we stood in 2024.

The Path Forward

The responsible approach is to act now, while we can still make changes on our own terms rather than in a crisis. Some of this is already underway and the rest has dates attached to it.

As Interim CEO, I am operationally accountable to make sure that the board has access to an annual budget that is actively managed with variances mitigated; receives consistent, contextualized and timely financial reports; and that robust internal controls and workflows are in place. This clarity will give the Finance Committee and the board what they need to exercise proper oversight within the policy guardrails they have set.

Our internal reporting will be reconciled to audit-basis accounting, so that the figures the board governs against during the year are as close as possible to the ones we publish after it; non-cash arrangements will be recorded as they occur rather than at year end; and our reserve position will be reported on a single defined basis, against both policy thresholds, every period.

Drupal.org will be presented as a program with a cost that the Drupal Association is accountable for funding. The Association needs a durable way to fund Drupal.org rather than the patchwork indirect one we have now. These issues are not unique to Drupal, and I am looking forward to hearing others' thoughts, but be assured that I do not intend to solve a funding problem by reducing the services the community relies on.

Within the coming months, I will publish:

  • What each part of our work actually costs and how it is funded

  • The full costs of Drupal.org as a measurable figure, which will be the first time anyone, including the board, will have seen that number

  • An updated 2026 forecast and preliminary mitigation plan

This fall, I will prepare a two-year 2027-2028 Operating Budget with the Finance Committee that the board will be able to review and approve before the end of the year.

Nothing about the 2025 audit changes our commitment, our mission or the direction we need to go. It just adds a little urgency. I am focused on co-creating a financial model where the work sustaining Drupal rests on a foundation that is resilient and sustainable for the next long-term CEO.

04 Aug 2026 2:26am GMT

03 Aug 2026

feedDrupal.org aggregator

Mike Herchel's Blog: A First Look at the DrupalCon Orlando Venue

A First Look at the DrupalCon Orlando Venue mherchel

03 Aug 2026 8:00pm GMT

The Drop Times: Public Code Must Survive the Contract

Public software is easiest to celebrate at launch, when a service is delivered, a repository is published, and an institution can point to visible progress. Its harder test begins after the original contract ends. Security response, documentation, upgrades, knowledge transfer and operational ownership must continue even when the delivery team or supplier changes. The EU Open Source Strategy, published by the European Commission on 3 June 2026, treats procurement, deployment, maintenance and governance as parts of the same software lifecycle.

Public procurement should therefore test continuity rather than initial delivery alone. Buyers need to know whether data, configuration and documentation can be transferred; whether another supplier can operate the service; whether publicly funded improvements can be reused; who will handle vulnerabilities and dependency updates; and how long transition support will remain available. An open licence can widen the range of possible suppliers, but that choice remains theoretical when system knowledge, access procedures or maintenance budgets stay with the incumbent. Avoiding lock-in requires both legal permission and the practical capacity to act on it.

The strategy proposes an Open Source Maintenance Instrument, dependency analysis, stewardship support and common security baselines for public repositories. These measures recognise that testing, release management, vulnerability response and documentation are infrastructure work rather than incidental volunteer activity. Drupal 7 reached end of life on 5 January 2025, but its source code remained available after community releases, fixes and security advisories ended. LocalGov Drupal offers a concrete model of organised stewardship by bringing councils and suppliers into shared product governance, technical maintenance and a cooperative structure intended to support financial sustainability.

Public money should produce more than software that can still be downloaded after the original team leaves. Contracts should fund security work, upgrades, current documentation, supplier handover, upstream contribution and governance across changes in vendors and budget cycles. Europe's open-source ambitions will achieve little if institutions publish more code without retaining the capacity to operate, improve and transfer it. Public code becomes infrastructure only when responsibility survives delivery.

Follow The DropTimes on LinkedIn, X, Bluesky, and Facebook, or join #thedroptimes on Drupal Slack.

This issue of Editor's Pick was written and curated by Kazima Abbas.

03 Aug 2026 1:52pm GMT

feedSymfony Blog

Symfony Polyfill 1.41.0 released: Io\Poll now available

Applications that adopt PHP 8.6's new I/O polling API normally cannot run that code on older PHP versions. Symfony Polyfill 1.41.0 brings this API to PHP 8.1 and later, alongside several compatibility fixes for the Grapheme, Intl and PHP version polyfills.…

03 Aug 2026 1:40pm GMT

02 Aug 2026

feedSymfony Blog

A Week of Symfony #1022 (July 27 – August 2, 2026)

This week, Symfony 6.4.43, 7.4.15, 8.0.16 and 8.1.3 maintenance versions were released. In addition, Symfony 8.0 reached its end of life. Finally, we introduced Symfony Reprise, the evolution of Webpack Encore for modern bundlers such as Vite and Rsbuild.…

02 Aug 2026 7:02am GMT

31 Jul 2026

feedSymfony Blog

Introducing Symfony Reprise: The Symfony Integration Layer for Modern Bundlers

For years, Webpack Encore was the answer to asset management in Symfony, and it still works. But the JavaScript bundler landscape has moved on since Encore was designed. Webpack needed a loader wired up for nearly everything (Sass, TypeScript, you name it),…

31 Jul 2026 7:52am GMT

01 Apr 2004

feedPlanet PHP

ezSystems are classy folks

cover
Last week I helped the folks at ezSystems debug some APC problems they were having. The problems ended up being a 64bit architecture problem (they have uber-fast Opterons) and the bug is now fixed in 2.0.3.

Today I received Python & XML from them (off my Amazon wishlist). Thanks guys!

On a side note, my wishlist seems borked. The list I get when I search on my email address or name is not the same one I can edit when I log into the site.

01 Apr 2004 6:53pm GMT

PHP april fools...

1st of April 2004 get's to it's end and I guess it's time, to summarize the recent April fools a bit. Not that I think anyone in the world believes in them, but some were quite funny:

1. Changes to case sensitivity in PHP.
Alan Knowles announced that PHP will change to the studlyCase API and therefor will get everything broken by changing established functions.

2. IBM takes over Zend.
Myself hacked a little article about IBM taking over Zend to make PHP a compete of Java.

3. The first PHP virus has been seen.
Wasn't there one last year, too?

4. PHP has been overtaken by Micro$oft.
Mhhh... a little bit unreliable, if they had been taken over by IBM this morning... Maybe one should first look, what others wrote...

5. And finally, PHP4 and 5 showed their real faces...
Take a look at a phpinfo() output!

I guess I missed some, so feel free to comment on this entry, if you found another!

01 Apr 2004 5:49pm GMT

PHP Virus Attacking Web Hosts

Symantec have a report of the virus here. I've yet to see any of the PHP news sites picking up on it but, using a virtual host account, managed to deliberately expose some PHP scripts to it. From examining the infected scripts, what's disturbing is once infected, every tim...

01 Apr 2004 12:19pm GMT