Original research · July 2026
The State of CMS Migration Readiness 2026
Every CMS evaluation we have ever watched runs the same way. Somebody builds a spreadsheet, the vendors fill in the columns, and everyone argues about features that roughly nine people will ever touch. What nobody checks is the thing that actually decides whether the site survives the move: what the platform emits by default, on a normal page, when nobody has tuned anything.
That is the gap we wanted to close. Not which CMS is best, which is an argument with no end, but what real sites on each platform are actually shipping right now. So we went and measured, expecting the answer to be that one platform was simply tidier than the other. It was not, and that turned out to be the interesting part.
We measured a random sample of 48,588 live websites across eleven signals that determine whether a site keeps its search and AI visibility when it changes CMS — 27,385 were reachable and measurable. This page is the method and the data behind the finding, free to cite and download.
Headline finding
WordPress and Drupal score identically on overall readiness (75.4% vs 76.2%) — but fail in opposite directions. WordPress sites carry 2.6× more structured data than Drupal sites, while Drupal sites are 2.4× more likely to ship security headers.
Source: Replatform Radar, State of CMS Migration Readiness 2026 (n=4,998 WordPress, 989 Drupal). Free to cite with attribution and a link to this page.
What we measured
A random sample of 48,588 domains drawn systematically from the Tranco top 80,000, filtered to remove CDNs, DNS infrastructure and ad-tech endpoints. Each site was fetched once with a single polite request; 27,385 were reachable and measurable (the rest were dead, bot-walled, or unreachable and are excluded rather than counted as failures). For each site we recorded eleven signals that determine whether a replatform preserves search and AI visibility: HTTPS, title quality, meta description, mobile viewport, canonical tag, structured data, Open Graph tags, a single H1, and three security headers (HSTS, CSP, X-Content-Type-Options).
Finding: WordPress and Drupal fail in opposite directions
The averages are statistically tied. The profiles behind them are almost perfectly inverted. Each platform’s defaults become its users’ strengths and its users’ blind spots.
Two platforms, inverted strengths
WordPress and Drupal are tied on overall readiness (75.4% vs 76.2%) — but WordPress carries 2.6× more structured data, while Drupal is 2.4× more likely to ship security headers.
Structured data
Security headers
| Signal | WordPress (n=4,998) | Drupal (n=989) |
|---|---|---|
| Overall readiness | 75.4% | 76.2% |
| Structured data | 83.9% | 32.2% |
| Open Graph tags | 90.8% | 66.6% |
| X-Content-Type-Options | 40.1% | 97.6% |
| HSTS | 49.5% | 72.7% |
| Canonical tag | 92.4% | 97.1% |
| Page weight | 299 KB | 186 KB |
| Script tags | 18.2 | 17.1 |
WordPress’s dominant SEO plugins emit schema markup by default; Drupal ships hardened HTTP headers out of the box. The migration lesson generalizes past these two platforms: what your current CMS does for you by default is exactly what you are most likely to forget to rebuild.
Readiness by platform
Every CMS with at least 30 measurable sites in the sample, by overall readiness and the two signals most often lost in a migration, structured data (SEO / AI visibility) and security headers.
Overall readiness by platform
Across 15 platforms with at least 30 measurable sites, the spread from best to worst is 29 points— defaults, not effort, drive most of it.
Average readiness score
| Platform | Sites | Readiness | Structured data | Security headers |
|---|---|---|---|---|
| WordPress | 4,998 | 75.4% | 83.9% | 40.1% |
| Drupal | 989 | 76.2% | 32.2% | 97.6% |
| Adobe Experience Manager | 687 | 84% | 58.5% | 88.2% |
| HubSpot CMS | 474 | 80.5% | 56.8% | 42.8% |
| Sitecore | 234 | 78.1% | 46.6% | 61.5% |
| TYPO3 | 161 | 76.7% | 35.4% | 82.6% |
| Salesforce Commerce Cloud | 117 | 78.8% | 73.5% | 82.1% |
| Optimizely (Episerver) | 89 | 78.5% | 46.1% | 50.6% |
| Shopify | 58 | 76.6% | 60.3% | 53.4% |
| Adobe Commerce (Magento) | 57 | 75.3% | 70.2% | 86% |
| Kentico | 50 | 69.8% | 30% | 58% |
| Squarespace | 45 | 81.6% | 82.2% | 93.3% |
| Joomla | 42 | 55.2% | 35.7% | 59.5% |
| Concrete CMS | 40 | 67.7% | 60% | 32.5% |
| Wix | 38 | 83.5% | 86.8% | 81.6% |
So what do we actually make of this?
Our honest read is that the platform argument is mostly a distraction. WordPress and Drupal land within a point of each other overall, so if you are choosing between them expecting one to hand you a readier site, that is not what the data says. What you are really choosing is which blind spot you inherit. Go WordPress and you get the structured data more or less for free, and you will be the one arguing for security headers nobody budgeted. Go Drupal and the headers come with the furniture, while the markup that decides whether an answer engine can quote you is yours to build.
Which means the useful question is not which platform to move to. It is which half of this you are currently bad at, and whether you are about to move to a platform that is bad at the same half. That is a checkable thing, and it is checkable today, before anyone signs a statement of work.
If we had to give one piece of advice from all of this, it would be unglamorous. Measure your own site first, on these eleven signals, and treat the result as your migration scope rather than as a report card. A platform switch does not repair any of it. Whatever your site fails to emit today, the new one will fail to emit on launch day, only now with different URLs and a deadline. The good news is that both of these platforms are perfectly capable of scoring well. Almost nobody is asking them to.
Method and limitations
- Each domain was fetched once with a single identified GET request; no crawling, no repeated hits. Platform was inferred from response fingerprints, so a share of sites are recorded as “Unknown” and are excluded from the per-platform table.
- Percentages are of measurable sites only. Reachability exclusions (dead DNS, refused connections, bot walls) are published in the dataset so the base is transparent.
- CMS detection is fingerprint-based and conservative: a platform is only assigned on a platform-specific marker, not a generic path, so counts under-report rather than over-report.
- Signals are presence checks, not quality audits. “has structured data” means schema was detected, not that it was complete or valid.
Sources and related work
Independent data, standards and research this study builds on, and independent surveys you can check our numbers against.
- Le Pochat, V., Van Goethem, T., Tajalizadehkhoob, S., Korczyński, M., Joosen, W.. Tranco: A Research-Oriented Top Sites Ranking Hardened Against Manipulation, NDSS 2019. The sampling frame for this study; the live list is at tranco-list.eu.
- W3Techs. Usage statistics of content management systems. Independent, continuously updated platform-share survey to compare our fingerprint-based shares against.
- Koster, M., Illyes, G., Zeller, H., Sassman, L.. Robots Exclusion Protocol (RFC 9309), IETF, 2022. The crawl-permission standard our single-fetch method respects.
- Google Search Central. Introduction to structured data markup. Why the structured-data signal matters for search visibility.
- Schema.org. Schema.org — shared structured-data vocabulary. The vocabulary the structured-data signal detects.
- OWASP. OWASP Secure Headers Project. Reference guidance for the security headers we measure (HSTS, CSP, X-Content-Type-Options).
- MDN Web Docs. Content Security Policy (CSP) guide.
Cite this
Replatform Radar, The State of CMS Migration Readiness 2026, July 2026. replatformradar.com/research/cms-migration-readiness-2026. Licensed CC BY 4.0 — the dataset and every number on this page may be reused with attribution. Archived on Zenodo: doi:10.5281/zenodo.21615303. Ready-to-paste formats:
Replatform Radar, "The State of CMS Migration Readiness 2026," July 2026, https://replatformradar.com/research/cms-migration-readiness-2026. doi:10.5281/zenodo.21615303. Open dataset, CC BY 4.0.
{{cite web |author=Replatform Radar |title=The State of CMS Migration Readiness 2026 |date=2026-07-20 |url=https://replatformradar.com/research/cms-migration-readiness-2026 |publisher=Replatform Radar |doi=10.5281/zenodo.21615303 |access-date=}}@misc{replatformradar2026cms,
author = {{Replatform Radar}},
title = {The State of CMS Migration Readiness 2026},
year = {2026},
doi = {10.5281/zenodo.21615303},
howpublished = {\url{https://replatformradar.com/research/cms-migration-readiness-2026}},
note = {Open dataset, licensed CC BY 4.0}
}Want these eleven signals scored for your own site before you migrate?
Request a scan →