Skip to content

Drupal SEO: what Drupal 11 core does and which modules to install

Published 7 October 20269 min readBy the SmoothSeen editorial team

Drupal SEO comes down to core plus five modules: Metatag for titles, descriptions and canonicals; Pathauto for readable URLs; Redirect for 301s; Simple XML Sitemap for the sitemap; and Schema.org Metatag for JSON-LD. Core already outputs canonical tags, hreflang and two security headers. Everything below applies to Drupal 10.6 and 11.4.

Key points

  • The current release is Drupal 11.4 (11.4.8, out on 26 September 2026); Drupal 12 ships the week of 7 December 2026 and Drupal 10 reaches end of life on 9 December 2026.
  • Core already outputs a canonical on nodes, terms and users, adds hreflang through Content Translation and sends X-Frame-Options and X-Content-Type-Options.
  • Five modules cover the rest of SEO: Metatag, Pathauto, Redirect, Simple XML Sitemap and Schema.org Metatag; Security Kit adds HSTS, CSP and Referrer-Policy.
  • robots.txt is a Composer scaffold file that is overwritten on every update; your additions belong in a separate file loaded with «append».
  • Redirect creates a 301 when an alias changes and redirects to the canonical URL by default.

To check it on your own site: SEO audit

On this page

Drupal is an open-source PHP content management system that is installed and updated with Composer. It controls URLs, the <title>, the canonical tag, hreflang, robots.txt (a file in the web root) and some HTTP headers. It does not control the server: the http-to-https redirect, HTML compression and CDN caching depend on Apache, Nginx or your host. Admin labels are quoted exactly as they appear in Drupal's code.

Which Drupal version should you run in October 2026?

The current minor is Drupal 11.4, released the week of 29 June 2026; its latest patch is 11.4.8, out on 26 September 202612. Drupal 12 ships the week of 7 December 2026, and Drupal 10 reaches end of life on 9 December 20261. If you are still on 10, the move to 11 belongs in this quarter. Before jumping to 12, check each module's project page for declared compatibility.

What
URL aliases
Drupal 11 core
Yes, by hand, with the Path module
Module
Pathauto, through patterns
What
Canonical
Drupal 11 core
Yes, on nodes, terms and users
Module
Metatag customises it
What
Meta description
Drupal 11 core
No
Module
Metatag
What
hreflang
Drupal 11 core
Yes, with Content Translation, except on the front page
Module
Simple XML Sitemap repeats it in the sitemap
What
301 redirects
Drupal 11 core
No
Module
Redirect
What
XML sitemap
Drupal 11 core
No
Module
Simple XML Sitemap
What
Structured data
Drupal 11 core
No
Module
Schema.org Metatag
What
Security headers
Drupal 11 core
X-Frame-Options and X-Content-Type-Options
Module
Security Kit

If you install Drupal CMS rather than bare core, its Basic SEO and SEO Tools recipes already install Pathauto, Redirect, Metatag, Simple XML Sitemap and Real-time SEO, and raise browser caching to 15 minutes34.

What does Drupal core do for SEO without modules?

More than you might expect. This comes straight from the Drupal 11.4.8 code:

  1. Canonical. Any entity page with its own URL (a node, a taxonomy term, a user) gets a <link rel="canonical"> with the absolute URL and a rel="shortlink" with the unaliased path5. The absolute URL uses the host the request came in on, so if your site answers with and without www, or over both http and https, each variant declares its own canonical. Fix it at the server: Drupal's .htaccess ships with commented-out rules to force or strip www6.
  2. hreflang. With the Content Translation module enabled, translated content pages carry their <link rel="alternate" hreflang> tags. The front page does not: the code deliberately skips it7.
  3. Title. The <title> comes out as «page title | site name».
  4. Headers. Every response carries X-Content-Type-Options: nosniff and, unless something else has set one, X-Frame-Options: SAMEORIGIN8.
  5. Speed. The Standard profile enables Internal Page Cache, Dynamic Page Cache and BigPipe, and CSS and JavaScript aggregation is on by default910.

Check one setting under Configuration > Development > Performance: Browser and proxy cache maximum age defaults to <no caching>10. With that value, neither browsers nor a CDN keep the HTML. Raise it to 15 minutes or more unless some content has to appear instantly. Gzip or Brotli compression of the HTML is not Drupal's job: its .htaccess only serves pre-compressed aggregated CSS and JavaScript6. For the rest, the guide to Apache .htaccess compression and caching has ready-made blocks.

Which SEO modules should you install on Drupal 11?

These six modules fill the gaps in core, and all six declare Drupal 10 and 11 compatibility on drupal.org:

Module
Metatag
Stable release
2.2.0
What for
Title, description, canonical, Open Graph and Twitter Cards per content type and per node11
Module
Pathauto
Stable release
8.x-1.15
What for
Automatic aliases from token patterns12
Module
Redirect
Stable release
8.x-1.13
What for
301 redirects, plus 404 logging with Redirect 40413
Module
Simple XML Sitemap
Stable release
4.2.3
What for
Sitemaps with hreflang, images and multiple variants14
Module
Schema.org Metatag
Stable release
3.1.0
What for
JSON-LD in the <head> through Metatag15
Module
Security Kit
Stable release
2.0.3
What for
HSTS, CSP, Referrer-Policy and X-Frame-Options16

Install them with Composer and enable them with Drush:

composer require drupal/metatag drupal/pathauto drupal/redirect drupal/simple_sitemap drupal/schema_metatag drupal/seckit
drush en metatag metatag_open_graph pathauto redirect simple_sitemap schema_metatag schema_organization schema_article seckit -y

How do you configure Metatag, Pathauto and Redirect?

Metatag lives under Configuration > Search and metadata > Metatag (/admin/config/search/metatag). Its defaults are sensible17:

Scope
Global
Title
Page title plus site name
Description
Empty
Canonical
[current-page:url]
Scope
Content (nodes)
Title
Node title plus site name
Description
[node:summary]
Canonical
[node:url]
Scope
Taxonomy term
Title
Term name plus site name
Description
[term:description]
Canonical
[term:url]
Scope
403 access denied
Title
Inherited from Global
Description
Inherited from Global
Canonical
The front page, with noindex

The node title pattern, exactly as it ships in Metatag's configuration:

[node:title] | [site:name]

Node descriptions come from the summary of the Body field: if editors leave it empty, the meta description ends up thin. To write one by hand on each node, add a field of type Meta tags to the content type.

Pathauto lives under Configuration > Search and metadata > URL aliases > Patterns (/admin/config/search/path/patterns). A pattern such as blog/[node:title] turns /node/123 into /blog/my-article. Out of the box it transliterates («é» becomes «e»), separates words with hyphens and caps aliases at 150 characters18. It also strips a list of short English words (a, an, the, of…) from aliases; review that list on the Settings tab if you want words like «the» kept.

Redirect lives under Configuration > Search and metadata > URL redirects. Its defaults already do the right thing19:

  • Automatically create redirects when URL aliases are changed: on. When Pathauto regenerates an alias, the old URL answers with a 301.
  • Default redirect status: 301.
  • Enforce clean and canonical URLs: on. It redirects /node/123 to its alias, strips trailing slashes and adds the language prefix.

How do you configure Drupal's robots.txt without losing it on update?

Drupal's robots.txt is a Composer scaffold file: every composer install or core update writes it again. Edit it by hand and your changes disappear on the next update. Drupal's documentation recommends adding lines with append rather than excluding the file, so you keep receiving fixes to it20. In the project's composer.json:

{
  "extra": {
    "drupal-scaffold": {
      "file-mapping": {
        "[web-root]/robots.txt": {
          "append": "assets/robots-additions.txt"
        }
      }
    }
  }
}

And in assets/robots-additions.txt, the Sitemap line, which Google requires as a full URL21, plus your policy for training crawlers:

# Model training: blocking it does not remove you from ChatGPT or Google
User-agent: GPTBot
User-agent: ClaudeBot
User-agent: Google-Extended
User-agent: CCBot
Disallow: /

Sitemap: https://www.example.com/sitemap.xml

We checked the Drupal 11.4.8 robots.txt plus this addition with Protego, which applies Google's rules: articles, /sites/default/files/ and the CSS and JavaScript under /core/ stay open to Googlebot, OAI-SearchBot, Claude-SearchBot and PerplexityBot; /admin/, /user/login and search pages stay closed; GPTBot, ClaudeBot and CCBot are kept out entirely. The training group is optional and editorial: the crawlers that decide whether ChatGPT or Claude can cite you are OAI-SearchBot and Claude-SearchBot, and Google-Extended has no effect on Google Search222324. The guide to AI crawlers and robots.txt covers each one.

If you run several sites from one codebase, the RobotsTxt module generates a robots.txt per site that you edit in the admin UI; it requires deleting or renaming the physical file25.

How do you generate an XML sitemap in Drupal?

With Simple XML Sitemap, which publishes /sitemap.xml and regenerates it on cron26. Once installed:

  1. Under Configuration > Search and metadata > Simple XML Sitemap, Inclusion tab (/admin/config/search/simplesitemap/entities), choose which content types and vocabularies go in.
  2. Exclude any node set to noindex: a sitemap should only list URLs you want indexed.
  3. On a multilingual site, the sitemap includes each URL's hreflang alternates.
  4. Submit the sitemap URL in Search Console and check it matches the Sitemap line in robots.txt.

How do you add structured data in Drupal?

With Schema.org Metatag, which adds groups of fields to Metatag that are printed as JSON-LD in the <head>15. Each type is a submodule: schema_article, schema_organization, schema_product, schema_event, schema_recipe and so on. You fill the fields with tokens in Metatag's defaults and override them per node where needed.

The @type of the Organization group accepts any schema.org subtype of Organization, LocalBusiness included27: that is the route for marking up address and opening hours on your contact page. For a shop, schema_product lets you mark up Offer, Brand and ratings; what Google expects on product pages is in the guide to Product schema. Do not mark up FAQ or HowTo for Google's benefit: HowTo stopped showing as a rich result in 2023 and FAQ on 7 May 202628.

How do you add HSTS and CSP in Drupal?

Core sends no HSTS, Content-Security-Policy or Referrer-Policy. Security Kit adds them from Configuration > System > Security Kit settings (/admin/config/system/seckit). This is what it ships with29:

Option
HTTP Strict Transport Security
Default
Off; max-age of 1,000 seconds
What to do
Turn it on with a short max-age and raise it later
Option
Content Security Policy
Default
Off
What to do
Turn it on in Report Only mode first
Option
X-Frame-Options
Default
SAMEORIGIN
What to do
Keep it
Option
Referrer-Policy
Default
Off
What to do
Turn it on with strict-origin-when-cross-origin
Option
X-XSS-Protection
Default
Disabled
What to do
Leave it: the header is obsolete

Do not tick Preload for HSTS until it has run for weeks without problems: the preload list forces HTTPS on every subdomain and getting off it takes months30. Security Kit still uses Feature-Policy, the old name for Permissions-Policy; if you need that header, set it at the server. If Nginx or Apache already sends these headers, do not duplicate them in Drupal. The guide to HTTP security headers explains what each one does.

How to check it

  • Canonical and hreflang: view the source of a node and search for rel="canonical" and hreflang. Request the same URL with and without www: the secondary variant should 301.
  • Headers: curl -I https://www.example.com/ should show x-content-type-options, x-frame-options and, if enabled, strict-transport-security and referrer-policy. Mozilla's HTTP Observatory scores them.
  • robots.txt: after a composer update, open /robots.txt and check your lines are still at the end.
  • Structured data and sitemap: the Rich Results Test and Search Console's Sitemaps report.

What SmoothSeen does with this

SmoothSeen checks a page of your site for what this guide configures: robots.txt, sitemap, canonical and noindex, titles and descriptions, structured data, HTTPS and the redirect to https, and security headers via Mozilla's HTTP Observatory. On the AI side it looks at which crawlers your robots.txt allows, separating search from training, and whether your server returns a 403 to any of them while serving the page to a browser.

What to do this week

Request your site with and without www and over http: if any variant does not 301, enable the .htaccess rule or the server equivalent, because core's canonical depends on it. Then move your robots.txt additions into a file loaded with append. To see the rest of the list measured, run an SEO audit with SmoothSeen.

Frequently asked questions

Does Drupal need modules for SEO or is core enough?

Core covers the canonical tag, hreflang for translations, manual aliases and two security headers. It lacks meta descriptions, an XML sitemap, redirects and structured data. A site with a handful of pages can live with manual aliases, but meta descriptions and a sitemap justify installing Metatag and Simple XML Sitemap from day one.

Why does my Drupal robots.txt keep reverting to the original?

Because Composer's scaffold plugin rewrites it every time you install or update core. That is not a bug: it is how Drupal ships fixes to that file. Move your rules into a file of your own and declare in composer.json that it should be appended with append; that way you keep both your changes and core's improvements.

Should I use Metatag or Yoast SEO in Drupal?

They do not compete. Metatag is what prints the tags in the <head>, and the Real-time SEO for Drupal module (package yoast_seo) depends on it and adds readability and keyword analysis while editors write. Drupal CMS installs both in its SEO Tools recipe. If you do not need that writing analysis, Metatag on its own is enough.

Will the modules in this guide work on Drupal 12?

Drupal 12 ships in December 2026 and each module declares its compatibility separately on its drupal.org page. All six in this guide accept Drupal 10 and 11 today. Before upgrading, check that every one declares ^12, or run the Upgrade Status module, which scans your installation and flags code that still needs updating.

Sources

  1. 1Drupal core release schedule, Drupal.org, updated 27 August 2026.
  2. 2Drupal core (releases), Drupal.org, accessed 9 October 2026.
  3. 3Drupal CMS Basic SEO recipe (recipe.yml), official Drupal CMS repository, 2.0.x branch, accessed 9 October 2026.
  4. 4Drupal CMS SEO Tools recipe (recipe.yml), official Drupal CMS repository, 2.0.x branch, accessed 9 October 2026.
  5. 5EntityViewController.php, view function, official Drupal repository, version 11.4.8, accessed 9 October 2026.
  6. 6Drupal scaffold .htaccess, official Drupal repository, version 11.4.8, accessed 9 October 2026.
  7. 7ContentTranslationHooks.php, pageAttachments function, official Drupal repository, version 11.4.8, accessed 9 October 2026.
  8. 8FinishResponseSubscriber.php, official Drupal repository, version 11.4.8, accessed 9 October 2026.
  9. 9Standard install profile (standard.info.yml), official Drupal repository, version 11.4.8, accessed 9 October 2026.
  10. 10PerformanceForm.php and system.performance.yml, official Drupal repository, version 11.4.8, accessed 9 October 2026.
  11. 11Metatag, Drupal.org, accessed 9 October 2026.
  12. 12Pathauto, Drupal.org, accessed 9 October 2026.
  13. 13Redirect, Drupal.org, accessed 9 October 2026.
  14. 14Simple XML sitemap, Drupal.org, accessed 9 October 2026.
  15. 15Schema.org Metatag, Drupal.org, accessed 9 October 2026.
  16. 16Security Kit, Drupal.org, accessed 9 October 2026.
  17. 17Metatag default configuration (config/install), official Metatag repository, 2.2.x branch, accessed 9 October 2026.
  18. 18pathauto.settings.yml, official Pathauto repository, 8.x-1.x branch, accessed 9 October 2026.
  19. 19redirect.settings.yml, official Redirect repository, 8.x-1.x branch, accessed 9 October 2026.
  20. 20Using Drupal's Composer Scaffold, Drupal.org, updated 14 September 2026.
  21. 21How Google interprets the robots.txt specification, Google Search Central, updated 31 August 2026.
  22. 22Overview of OpenAI Crawlers, OpenAI, accessed 9 October 2026.
  23. 23Does Anthropic crawl data from the web, and how can site owners block the crawler?, Anthropic, updated 7 April 2026.
  24. 24AI features and your website, Google Search Central, updated 10 December 2025.
  25. 25RobotsTxt, Drupal.org, accessed 9 October 2026.
  26. 26simple_sitemap.settings.yml, official Simple XML Sitemap repository, 4.x branch, accessed 9 October 2026.
  27. 27SchemaOrganizationType.php, official Schema.org Metatag repository, version 3.1.0, accessed 9 October 2026.
  28. 28Latest Google Search documentation updates, Google Search Central, accessed 9 October 2026.
  29. 29seckit.settings.yml, official Security Kit repository, 2.x branch, accessed 9 October 2026.
  30. 30Strict-Transport-Security header, MDN Web Docs, updated 11 September 2026.

How to cite this article

SmoothSeen. (2026, October 7). Drupal SEO: what Drupal 11 core does and which modules to install. https://smoothseen.com/en/blog/drupal-seo/

Who writes this

SmoothSeen is a website audit tool that measures visibility in search engines and AI assistants and delivers reports under the agency's own brand.

This blog belongs to SmoothSeen: when an article discusses the product, it does so knowing the product is ours. Third-party figures link to their original source.

Change history

  • First version.

Keep reading

Drupal SEO for Drupal 11: core, modules and robots.txt