Gecko v7 Gecko v7
  • +44 (0) 131 240 3390
  • +44 (0) 131 240 3390
  • Gecko Agency
    Design
    Brand Strategy
    Web Design
    Development
    Umbraco
    Custom API Integrations
    Custom Web Development
    Virtual Website Planning
    Digital Marketing
    Search Engine Optimisation
    Paid Search Marketing
    Content Marketing
    Social Media Marketing
    Support
    Support Packages
    Blog
    Case Studies
    About Us
    Careers
    Contact

    What It Means When Your Umbraco Site Is Out of Long-Term Support

    7th May 2026

    There is a particular kind of silence that happens when someone asks, “What version of Umbraco are we on?”

    It is the silence of a room collectively hoping the answer is not “something from the before-times”.

    If your website is still running on Umbraco 7, Umbraco 8, Umbraco 10 or an even older version, this post is for you. Not as a telling-off. Nobody needs that. Websites age for perfectly understandable reasons: budgets move, priorities change, the site keeps working, and the upgrade conversation gets nudged into next quarter until next quarter becomes a small historical era.

    But older Umbraco versions are now outside Long Term Support, or close enough to that territory that they need proper attention. And once a platform is out of LTS, the conversation changes.

    This does not mean your website will suddenly collapse into a pile of pixels. It does mean the risks become harder to ignore, harder to insure against, and usually harder to fix neatly.

    So, let’s talk about what out-of-LTS actually means, why it matters, and what your options are.

    What does “out of LTS” mean?

    LTS stands for Long Term Support.

    In plain English, it is the period where a software version continues to receive official support, including important fixes and security updates. For a CMS like Umbraco, that support window matters because your website is not a static brochure gathering dust in a cupboard. It is a living system made up of the CMS, hosting, databases, packages, integrations, code, content, forms, users, permissions and all the tiny moving parts that make everyone nervous when someone says, “Can we just change one thing?”

    When a version is out of LTS, it generally means official support for that version has ended. Security patches, bug fixes and compatibility updates are no longer being provided in the same way.

    Your site may still run. Your editors may still be able to log in. Your homepage may still look perfectly respectable.

    But underneath, the support safety net has gone.

    That is the bit that matters.

    Out-of-LTS is not the same as “broken”

    This is worth saying clearly: an out-of-LTS Umbraco site is not automatically broken.

    Plenty of older sites keep running for years. Some of them look fine on the surface. Some of them have never caused a major incident. Some of them may even have a charming “if it ain’t broke” argument attached to them.

    The problem is that “working” and “safe to keep relying on” are not the same thing.

    A smoke alarm with no battery can sit on the ceiling looking very committed to the job. That does not mean it is doing useful work.

    Out-of-LTS software is similar. The site may still function, but your ability to protect, maintain and improve it gets weaker over time.

    The security risk

    Security is usually the biggest concern, and rightly so.

    Once a CMS version is no longer supported, newly discovered vulnerabilities may not be patched for that version. Even where mitigations are possible, they can be slower, more manual and more expensive to apply.

    That creates a few practical problems.

    First, attackers do not need your website to be famous. Many attacks are automated and opportunistic. They scan for known weaknesses across thousands of sites. An older CMS, outdated plugin, exposed admin area or vulnerable dependency can be enough to attract the wrong sort of attention.

    Second, security risk is cumulative. It is rarely one dramatic issue. It is often a stack of smaller problems: old CMS version, old framework, old packages, old server configuration, old integrations, old assumptions. None of them are ideal alone. Together, they become a bit of a buffet for trouble.

    Third, it becomes harder to prove you are managing risk responsibly. That matters for governance, procurement, cyber insurance, compliance reviews, public sector requirements and internal IT teams who understandably prefer not to inherit digital archaeology with a login screen.

    In short: your older Umbraco site may not be unsafe today, but it is becoming harder to defend tomorrow.

    The dependency risk

    Modern websites rely on dependencies. That is a fancy way of saying your website is probably standing on the shoulders of lots of other software, some of which is maintained by other people, teams or vendors.

    Older Umbraco sites can depend on:

    • Older versions of .NET or .NET Framework.
    • Legacy hosting environments.
    • Unsupported packages.
    • Older database versions.
    • Old JavaScript libraries.
    • Retired third-party APIs.
    • Custom code written for a very different technical landscape.

    This matters because the web keeps moving whether your CMS does or not. Hosting providers upgrade platforms. Payment gateways change APIs. Browser behaviour shifts. Security standards evolve. Package maintainers move on. Developers stop being familiar with older frameworks. Eventually, the website becomes harder to support not because one thing failed, but because everything around it changed.

    That is often when “just a small update” becomes a much bigger conversation.

    For example, a form integration that used to work may need newer authentication. A package may not have a supported equivalent for your version. A hosting provider may stop offering the runtime your site depends on. A developer may need to spend extra time safely touching old code because the tooling is outdated.

    This is where cost starts to creep in. Not in one big dramatic invoice-shaped thunderclap, but in lots of little bits of friction.

    The maintenance risk

    Older platforms tend to slow down future work.

    That does not always show up as a single obvious problem. It shows up as estimates getting larger. Small requests taking longer. Developers needing extra investigation time. Testing becoming more fragile. Content editors putting up with clunky workflows because “that’s just how the site works”.

    Over time, this creates technical debt.

    Technical debt is not a moral failing. It is what happens when a useful website has been changed, extended, patched and kept alive over many years. In fact, a site with no technical debt is probably either brand new or fictional.

    But with older Umbraco versions, that debt becomes harder to manage because the platform underneath is no longer moving with you.

    The risk is not just that something breaks. The risk is that progress becomes slow, expensive and awkward.

    Nobody wants their website to become the digital equivalent of a cupboard where everyone is afraid to open the top shelf.

    The compliance and insurance risk

    This is the bit that often catches organisations by surprise.

    Even if your site seems stable, running unsupported software can create questions elsewhere in the business. Cyber insurers, auditors, procurement teams, information security teams and governance boards may ask whether critical systems are supported and patched.

    If the answer is “not officially”, that can become a problem.

    For some organisations, it may affect cyber insurance terms. For others, it may create an audit finding. For public sector or regulated organisations, it may complicate supplier assurance and risk management.

    We are not saying every older Umbraco site will immediately cause a compliance issue. That would be a bit dramatic, even for us. But we are saying that unsupported software is increasingly difficult to defend in a world where digital risk is taken seriously.

    And rightly so.

    What are your options?

    The good news: you do have options.

    The best route depends on your current version, the size and complexity of the site, your budget, your internal capacity, your appetite for change and whether the current website is still doing the job.

    Broadly, there are four sensible paths.

    Option 1: Upgrade to a supported Umbraco version

    For many clients, the right answer is to move to a supported LTS version of Umbraco.

    This gives you a modern, supported platform with a longer runway for security, maintenance and future development. It also means your site is no longer reliant on outdated frameworks, packages and hosting assumptions.

    However, this may not be a simple “click upgrade” exercise.

    For older sites, especially Umbraco 7 and 8, an upgrade can be closer to a migration. Data models, templates, packages, custom code and editor workflows may all need careful review. Some functionality may need rebuilding or replacing. Some old packages may have no direct modern equivalent.

    That is not a reason to avoid it. It is a reason to plan properly.

    A well-managed upgrade can protect the value of your existing site while giving it a safer technical foundation.

    Option 2: Rebuild on a modern version of Umbraco

    Sometimes the current site has simply reached the end of its useful life.

    That might be because the design is tired, the content structure no longer fits, editors are fighting the CMS, performance is poor, integrations are creaking, or the business has changed so much that an upgrade would preserve too many old compromises.

    In that case, a rebuild may be more sensible than a straight upgrade.

    A rebuild does not have to mean throwing everything away and starting from a blank page while everyone chants “digital transformation” around a conference table. It can be focused, practical and proportionate.

    The advantage is that you can rethink the parts that matter: content structure, user journeys, accessibility, performance, editor experience, integrations and long-term maintainability.

    The risk is scope. Rebuilds need discipline. Otherwise, the project can expand faster than a “quick meeting” with twelve stakeholders.

    Option 3: Stabilise first, then upgrade

    Not every organisation can move immediately.

    Budgets need approval. Procurement can take time. Internal teams may be busy. Sometimes the sensible first step is to stabilise the current site while planning the bigger move.

    That might include:

    • Reviewing hosting and backups.
    • Checking admin access and permissions.
    • Removing unused packages.
    • Applying any available security mitigations.
    • Improving monitoring.
    • Documenting integrations.
    • Reducing exposed attack surfaces.
    • Creating a clear upgrade or rebuild plan.

    This is not a permanent solution. It is a risk-reduction step.

    Think of it as putting scaffolding around the building while you plan the renovation. Useful, sensible, but not somewhere you want to live forever.

    Option 4: Decommission or replace the site

    Occasionally, the right answer is not to upgrade at all.

    Some older sites are no longer strategically important. They may be campaign sites, microsites, archive sites or platforms that have been replaced elsewhere but never properly switched off.

    In those cases, the best move may be to decommission the site, archive the content, redirect important pages, or replace it with something simpler.

    This is often the cheapest and cleanest option, but it still needs care. Old sites can carry SEO value, legal content, analytics history, user data, redirects and brand reputation. Turning them off without a plan is how you create digital ghosts. And digital ghosts are very bad at filling in support tickets properly.

    What we usually recommend

    For clients on Umbraco 7, 8, 10 or below, we usually recommend starting with a technical review.

    Not a giant strategy project. Not a 90-page document that gets admired once and then filed under “hmm”. A practical review that answers the important questions:

    • What version are you on?
    • What is the support status?
    • What dependencies does the site rely on?
    • What packages are installed?
    • What custom code exists?
    • What integrations need protecting?
    • What are the security and hosting risks?
    • What would an upgrade involve?
    • Would a rebuild be more sensible?
    • What should happen first?

    That gives everyone a clearer picture before decisions are made.

    Because the truth is that older Umbraco sites vary wildly. One may be a simple content site that can be migrated cleanly. Another may be a heavily customised platform with years of business logic tucked inside it like a technical lasagne.

    You do not know which one you have until someone looks properly.

    Why doing nothing is also a decision

    It is tempting to leave the site as it is, especially if everything seems fine.

    But doing nothing is still a decision. It means accepting the growing risks around security, support, dependencies, hosting and future change.

    That may be acceptable for a short period while you plan. It may even be acceptable for a low-risk site with limited functionality and no sensitive data, provided the risks are understood and documented.

    What we would not recommend is accidental inaction.

    That is when nobody has made a conscious decision, nobody owns the risk, and everyone assumes someone else is keeping an eye on it. This is how organisations end up with a business-critical website running on ancient software, a forgotten plugin and the collective hope that nothing exciting happens.

    Hope is not a maintenance plan. Annoyingly.

    How urgent is this?

    The older your version, the more urgent the conversation becomes.

    If you are on Umbraco 7 or 8, you should treat this as something that needs active planning. These versions belong to a much older generation of Umbraco, and moving forward is likely to involve proper migration work.

    If you are on Umbraco 10, the route may be more straightforward in some cases, but it still needs attention because support windows do not last forever and dependencies continue to age.

    If you are on anything older than that, you are firmly in “please let’s talk before the website starts making ominous noises” territory.

    Urgent does not always mean “drop everything today”. It means “this should have an owner, a plan and a realistic timeline”.

    What will the process look like?

    A typical process might look like this:

    1. Technical review
      We assess the current site, hosting, packages, integrations, custom code and risks.
    2. Recommendation
      We tell you whether upgrade, rebuild, stabilise-first or decommission looks like the best route.
    3. Planning
      We define scope, budget, timing, testing, content responsibilities and launch approach.
    4. Delivery
      We carry out the agreed work, whether that is a migration, rebuild, stabilisation project or decommissioning plan.
    5. Ongoing support
      We help keep the site maintained, monitored and ready for future Umbraco releases.

    The most important part is the first one. Without understanding the current platform, any recommendation is just a confident guess wearing a nice jacket.

    And nobody needs that.

    The reassuring bit

    Older Umbraco versions are not rare. If your site is behind, you are not alone.

    This happens to good organisations, sensible teams and perfectly competent people. The website kept working, priorities moved elsewhere, and now the technical foundation needs attention. That is normal.

    The key is not to feel guilty about it. The key is to stop the drift.

    Once there is a plan, the situation usually becomes much less stressful. You know the risks. You know the options. You know whether the work is a tidy upgrade, a larger migration, a rebuild, or a graceful goodbye to a site that has done its time.

    That clarity is the useful bit.

    What to do next

    If your website is on Umbraco 7, 8, 10 or anything older, the best next step is to review it properly.

    We can help you understand what out-of-LTS means for your specific site, where the real risks are, and which route makes most sense. Drop us a line today and we’ll help you make a sensible plan

    Sometimes that means upgrading. Sometimes it means rebuilding. Sometimes it means stabilising first. And sometimes it means finally retiring a website that has been quietly sitting in the corner pretending not to exist.

    Whatever the answer, it is better to know now than discover it during a security incident, failed hosting update, broken integration or panicked internal audit.

    Because unsupported does not always mean broken.

    But it does mean it is time to pay attention.

    7th May 2026 Share This:
    ...
    Author
    David Nicklen
    Support Manager
    Dave has been our master of support since 2013, and he's widely regarded as the second most popular answer to the question 'who you gonna call?' when you have a problem, coming in just behind the Ghostbusters. He's a superhero of problem-solving, always ready to help both clients and colleagues with anything tech-related. When he's not saving the day, Dave spends his free time with his family, taking on DIY projects and music.
    @Twitter
    Follow Us:

    Gecko Agency (Edinburgh)

    hello@wearegecko.co.uk
    t: 0131 240 3390

    t: 0131 240 3390

    Head Office

    3 Hill Street
    Edinburgh
    EH2 3JP

    Gecko Agency Ltd | Copyright © 2026

    • |GDPR
    • |Privacy Policy
    • |Cookie Policy