Other CMS (Drupal, Joomla, Ghost)

Mastering Drupal: A Comprehensive Step-by-Step Guide

By the Domain India teamPublished 9 min read
Knowledge base article
Contents (9 sections)

Drupal is an open-source content management system built for structured, content-heavy websites: universities, government portals, membership sites and multilingual publications. It asks more of you than WordPress, but gives you custom content types, fine-grained permissions and powerful listings without extra plugins. This guide covers choosing a version in 2026, installing Drupal on shared hosting, the core concepts, and keeping a site fast and secure.

Key takeaways

Start new sites on Drupal 11 or Drupal CMS (the ready-to-use edition built on current Drupal core), never on Drupal 7, which reached end of life in January 2025. Drupal 11 needs PHP 8.3 or newer. On Domain India shared hosting, install it in a few clicks with Softaculous, or build it with Composer on your own computer and upload it, because Composer can't run on shared servers. Then set trusted host patterns, schedule cron, turn on caching, and apply security updates promptly.

1. Is Drupal the right choice?

Good for
  • Sites with many content types and fields: courses, events, staff, products
  • Complex roles and permissions, and editorial workflows (draft, review, published)
  • Multilingual sites: translation is built into core
  • Headless setups: JSON:API is included in core
Watch out for
  • A steeper learning curve than WordPress for site owners
  • Fewer ready-made themes, and custom work costs more
  • Adding modules properly depends on Composer
  • Major upgrades need planning (check module compatibility first)

If you need a simple business site or blog that non-technical staff update, WordPress or our AI Website Builder is usually quicker. See the WordPress guide for comparison.

2. Which Drupal version in 2026

VersionStatusUse it?
Drupal 7End of life since January 2025: no community security updatesNo. Migrate existing sites.
Drupal 8 and 9End of lifeNo
Drupal 10Still supported, in its final support periodOnly for existing sites; plan the move to 11
Drupal 11Current major versionYes, for new sites
Drupal CMSDrupal core plus recipes, a modern admin and useful modules preinstalledYes, if you want a quicker start

Check drupal.org for exact end-of-life dates, as they are announced per release.

3. Requirements, and what our servers provide

Drupal 11 needs:

  • PHP 8.3 or newer, with the usual extensions (GD for images, PDO for the database, mbstring, and others that Drupal's installer checks).
  • MariaDB 10.6+ or MySQL 8.0+ (PostgreSQL and SQLite are also supported by Drupal).
  • Apache with mod_rewrite for clean URLs, or nginx.

On Domain India shared hosting (measured September 2026):

ItemcPanelDirectAdmin
PHP5.1 to 8.5, per account; new accounts default to 8.3Up to 8.3
DatabaseMariaDB 10.11MariaDB 10.6
Web serverApache (nginx in front), mod_rewrite onApache, mod_rewrite on
Max PHP upload size256 MB64 MB

Both meet Drupal 11's minimums. Set your account to PHP 8.3 or newer before installing.

4. Install Drupal with Softaculous

Softaculous is installed on our cPanel and DirectAdmin servers. Its library includes Drupal CMS and Drupal 10, alongside obsolete versions such as Drupal 7. Choose Drupal CMS for a new site, or Drupal 10 only if you have a specific reason.

  1. Point the domain at your hosting
    and let free SSL issue, so you can install on https:// from the start.
  2. Open Softaculous
    from your control panel and search for Drupal.
  3. Pick the edition
    (Drupal CMS for new sites) and click Install.
  4. Choose the domain and folder.
    Leave the folder empty to install at the domain's root.
  5. Set the admin account.
    Use a unique username (not "admin"), a strong password and an email address you read.
  6. Install
    , then log in at https://yourdomain.com/user/login.

After installing, open Reports › Status report in Drupal's admin menu and fix anything shown in red or yellow.

5. Install with Composer (the developer route)

Drupal's recommended workflow uses Composer, which can't run on our shared hosting, so you build the site on your own computer or in CI and upload the result.

bash
# On your computer, with PHP 8.3+ and Composer installed
composer create-project drupal/recommended-project mysite
cd mysite
composer require drupal/pathauto drupal/metatag

The project puts Drupal's public files in mysite/web/, with vendor/ beside it, outside the web root. Upload the whole mysite folder (including vendor/) to your hosting account, outside public_html. When you add the domain in your control panel, set its document root to mysite/web. If you can't change the document root, for example for your account's main domain, install with Softaculous instead or ask support. Then create a database and user in the panel and open the domain in a browser to run the installer.

For every later module or update, run Composer locally, then upload the changed composer.lock, vendor/ and module folders and run database updates at /update.php.

In-browser module installs need Composer on the server

Project Browser and Automatic Updates install code through Composer running on the web server. Composer and the process functions it needs are disabled on shared hosting, so those features won't work there. Add modules with Composer on your computer, as above. For details, see PHP disabled functions on shared hosting.

6. Essential settings after installation

  • Trusted host patterns. In web/sites/default/settings.php, list the hostnames your site answers to. This blocks HTTP Host header attacks:
php
$settings['trusted_host_patterns'] = [
  '^yourdomain\.com$',
  '^www\.yourdomain\.com$',
];
  • Lock settings.php. After install, make settings.php read-only (permissions 444) and the sites/default folder 555.
  • Private files. Set $settings['file_private_path'] to a folder outside the web root for invoices, forms and other files that must not be public.
  • Cron. Drupal needs cron for search indexing, cleanup and update checks. Either keep the built-in Automated Cron module on, or add a cron job in your control panel that requests the cron URL shown under Configuration › System › Cron once an hour.
  • Clean URLs and aliases. Clean URLs work out of the box with Drupal's .htaccess. Add the Pathauto module for automatic, readable URLs.

7. The core concepts

Content types and fields
"Article", "Event" or "Course", each with its own fields: date, location, image, price.
Taxonomy
Vocabularies of terms (topics, departments, regions) to classify and filter content.
Views
Build lists, tables, grids, blocks and feeds of content without code.
Blocks and Layout Builder
Place content in theme regions, or design individual page layouts visually.
Users, roles and permissions
Give editors, reviewers and members exactly the access they need.
Workflows
Content Moderation adds draft, review and published states with approvals.

For multilingual sites, enable the Language, Content Translation, Interface Translation and Configuration Translation modules in core. Themes for Drupal 11 use Twig templates; start from a maintained contributed theme or a starter kit rather than editing core themes directly.

8. Performance, security and backups

  1. Turn on caching.
    Keep the Internal Page Cache and Dynamic Page Cache modules on, and enable CSS and JavaScript aggregation under Configuration › Development › Performance.
  2. Use a PHP version with OPcache on.
    OPcache is enabled on our cPanel servers. On DirectAdmin it is enabled for every PHP version except 8.3.
  3. Don't put php_value lines in .htaccess.
    Our servers run PHP-FPM, so those lines cause a 500 error. Change PHP settings in your panel or with .user.ini.
  4. Apply security updates quickly.
    Subscribe to Drupal security advisories and update core and modules as soon as fixes are released.
  5. Keep your own backups.
    Shared hosting includes weekly JetBackup backups on cPanel and DirectAdmin. Before every update, also export the database and download sites/default/files, and use Configuration › Development › Configuration synchronization to export your site configuration.

Drush, Drupal's command-line tool, needs SSH. Jailed SSH is available on every shared hosting plan on request; ask support to enable it. Some Drush commands start other processes, which are disabled on shared hosting, so test what you need. Full Drush and Composer workflows belong on a VPS.

9. Hosting Drupal with Domain India

A single Drupal site runs well on shared hosting with enough storage and databases. For several Drupal sites, a busy site, or a full Composer and Drush workflow on the server, consider a larger plan or a self-managed VPS.

cPanel Starter
₹125/mo + GST
  • 25 GB NVMe SSD Storage
  • 50 GB Monthly Bandwidth
  • 1 Website
  • 10 Email Accounts
See plan details
cPanel Growth
₹200/mo + GST
  • 50 GB NVMe SSD Storage
  • 100 GB Monthly Bandwidth
  • 5 Websites
  • 50 Email Accounts
See plan details

Prices on the cards are live Domain India list prices and exclude 18% GST. New shared hosting purchases have a full refund within 30 days.

Which Drupal version should I use for a new site in 2026?

Use Drupal 11, or Drupal CMS, which is built on current Drupal core. Don't start new sites on Drupal 7, which reached end of life in January 2025, and plan to move Drupal 10 sites to 11.

What PHP version does Drupal 11 need?

Drupal 11 requires PHP 8.3 or newer. On Domain India cPanel hosting you can choose PHP 8.3, 8.4 or 8.5 per account; DirectAdmin offers PHP 8.3.

Can I install Drupal with Softaculous on Domain India hosting?

Yes. Softaculous is installed on our cPanel and DirectAdmin servers and offers Drupal CMS and Drupal 10. Choose Drupal CMS for a new site.

Can I run Composer or Project Browser on shared hosting?

No. Composer and the process functions it needs are disabled on shared hosting, so Project Browser and Automatic Updates can't install code there. Build the site with Composer on your computer and upload it, including the vendor folder, or use a VPS.

How do I set up cron for Drupal?

Keep Drupal's Automated Cron module enabled, or add a cron job in your control panel that requests the cron URL shown under Configuration, System, Cron once an hour.

Why does my Drupal site give a 500 error after I edited .htaccess?

Our servers run PHP through PHP-FPM, so php_value and php_flag lines in .htaccess cause a 500 error. Remove them and change PHP settings in your control panel or a .user.ini file instead.

Is Drupal 7 still safe to run?

No. Drupal 7 reached end of life in January 2025 and no longer gets community security updates. Migrate to Drupal 11 or Drupal CMS.

Ready to build with Drupal? Compare plans on cPanel hosting or DirectAdmin hosting, or open a support ticket if you want help choosing.

Host your Drupal site

PHP up to 8.5, Softaculous for one-click installs, free SSL and weekly backups.

See cPanel plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app
Drupal Guide 2026: Install, Set Up, Secure | Domain India