Drupal SEO: what Drupal 11 core does and which modules to install
Published 7 October 20269 min readBy the SmoothSeen editorial team
Drupal SEO comes down to core plus five modules: Metatag for titles, descriptions and canonicals; Pathauto for readable URLs; Redirect for 301s; Simple XML Sitemap for the sitemap; and Schema.org Metatag for JSON-LD. Core already outputs canonical tags, hreflang and two security headers. Everything below applies to Drupal 10.6 and 11.4.
Key points
- The current release is Drupal 11.4 (11.4.8, out on 26 September 2026); Drupal 12 ships the week of 7 December 2026 and Drupal 10 reaches end of life on 9 December 2026.
- Core already outputs a canonical on nodes, terms and users, adds hreflang through Content Translation and sends X-Frame-Options and X-Content-Type-Options.
- Five modules cover the rest of SEO: Metatag, Pathauto, Redirect, Simple XML Sitemap and Schema.org Metatag; Security Kit adds HSTS, CSP and Referrer-Policy.
- robots.txt is a Composer scaffold file that is overwritten on every update; your additions belong in a separate file loaded with «append».
- Redirect creates a 301 when an alias changes and redirects to the canonical URL by default.
To check it on your own site: SEO audit
On this page
- Which Drupal version should you run in October 2026?
- What does Drupal core do for SEO without modules?
- Which SEO modules should you install on Drupal 11?
- How do you configure Metatag, Pathauto and Redirect?
- How do you configure Drupal's robots.txt without losing it on update?
- How do you generate an XML sitemap in Drupal?
- How do you add structured data in Drupal?
- How do you add HSTS and CSP in Drupal?
- How to check it
- What SmoothSeen does with this
- What to do this week
- Frequently asked questions
Drupal is an open-source PHP content management system that is installed and updated with Composer. It controls URLs, the <title>, the canonical tag, hreflang, robots.txt (a file in the web root) and some HTTP headers. It does not control the server: the http-to-https redirect, HTML compression and CDN caching depend on Apache, Nginx or your host. Admin labels are quoted exactly as they appear in Drupal's code.
Which Drupal version should you run in October 2026?
The current minor is Drupal 11.4, released the week of 29 June 2026; its latest patch is 11.4.8, out on 26 September 202612. Drupal 12 ships the week of 7 December 2026, and Drupal 10 reaches end of life on 9 December 20261. If you are still on 10, the move to 11 belongs in this quarter. Before jumping to 12, check each module's project page for declared compatibility.
- What
- URL aliases
- Drupal 11 core
- Yes, by hand, with the Path module
- Module
- Pathauto, through patterns
- What
- Canonical
- Drupal 11 core
- Yes, on nodes, terms and users
- Module
- Metatag customises it
- What
- Meta description
- Drupal 11 core
- No
- Module
- Metatag
- What
- hreflang
- Drupal 11 core
- Yes, with Content Translation, except on the front page
- Module
- Simple XML Sitemap repeats it in the sitemap
- What
- 301 redirects
- Drupal 11 core
- No
- Module
- Redirect
- What
- XML sitemap
- Drupal 11 core
- No
- Module
- Simple XML Sitemap
- What
- Structured data
- Drupal 11 core
- No
- Module
- Schema.org Metatag
- What
- Security headers
- Drupal 11 core
- X-Frame-Options and X-Content-Type-Options
- Module
- Security Kit
If you install Drupal CMS rather than bare core, its Basic SEO and SEO Tools recipes already install Pathauto, Redirect, Metatag, Simple XML Sitemap and Real-time SEO, and raise browser caching to 15 minutes34.
What does Drupal core do for SEO without modules?
More than you might expect. This comes straight from the Drupal 11.4.8 code:
- Canonical. Any entity page with its own URL (a node, a taxonomy term, a user) gets a
<link rel="canonical">with the absolute URL and arel="shortlink"with the unaliased path5. The absolute URL uses the host the request came in on, so if your site answers with and withoutwww, or over both http and https, each variant declares its own canonical. Fix it at the server: Drupal's.htaccessships with commented-out rules to force or stripwww6. - hreflang. With the Content Translation module enabled, translated content pages carry their
<link rel="alternate" hreflang>tags. The front page does not: the code deliberately skips it7. - Title. The
<title>comes out as «page title | site name». - Headers. Every response carries
X-Content-Type-Options: nosniffand, unless something else has set one,X-Frame-Options: SAMEORIGIN8. - Speed. The Standard profile enables Internal Page Cache, Dynamic Page Cache and BigPipe, and CSS and JavaScript aggregation is on by default910.
Check one setting under Configuration > Development > Performance: Browser and proxy cache maximum age defaults to <no caching>10. With that value, neither browsers nor a CDN keep the HTML. Raise it to 15 minutes or more unless some content has to appear instantly. Gzip or Brotli compression of the HTML is not Drupal's job: its .htaccess only serves pre-compressed aggregated CSS and JavaScript6. For the rest, the guide to Apache .htaccess compression and caching has ready-made blocks.
Which SEO modules should you install on Drupal 11?
These six modules fill the gaps in core, and all six declare Drupal 10 and 11 compatibility on drupal.org:
- Module
- Metatag
- Stable release
- 2.2.0
- What for
- Title, description, canonical, Open Graph and Twitter Cards per content type and per node11
- Module
- Pathauto
- Stable release
- 8.x-1.15
- What for
- Automatic aliases from token patterns12
- Module
- Redirect
- Stable release
- 8.x-1.13
- What for
- 301 redirects, plus 404 logging with Redirect 40413
- Module
- Simple XML Sitemap
- Stable release
- 4.2.3
- What for
- Sitemaps with hreflang, images and multiple variants14
- Module
- Schema.org Metatag
- Stable release
- 3.1.0
- What for
- JSON-LD in the
<head>through Metatag15
- Module
- Security Kit
- Stable release
- 2.0.3
- What for
- HSTS, CSP, Referrer-Policy and X-Frame-Options16
Install them with Composer and enable them with Drush:
composer require drupal/metatag drupal/pathauto drupal/redirect drupal/simple_sitemap drupal/schema_metatag drupal/seckit
drush en metatag metatag_open_graph pathauto redirect simple_sitemap schema_metatag schema_organization schema_article seckit -yHow do you configure Metatag, Pathauto and Redirect?
Metatag lives under Configuration > Search and metadata > Metatag (/admin/config/search/metatag). Its defaults are sensible17:
- Scope
- Global
- Title
- Page title plus site name
- Description
- Empty
- Canonical
[current-page:url]
- Scope
- Content (nodes)
- Title
- Node title plus site name
- Description
[node:summary]- Canonical
[node:url]
- Scope
- Taxonomy term
- Title
- Term name plus site name
- Description
[term:description]- Canonical
[term:url]
- Scope
- 403 access denied
- Title
- Inherited from Global
- Description
- Inherited from Global
- Canonical
- The front page, with
noindex
The node title pattern, exactly as it ships in Metatag's configuration:
[node:title] | [site:name]Node descriptions come from the summary of the Body field: if editors leave it empty, the meta description ends up thin. To write one by hand on each node, add a field of type Meta tags to the content type.
Pathauto lives under Configuration > Search and metadata > URL aliases > Patterns (/admin/config/search/path/patterns). A pattern such as blog/[node:title] turns /node/123 into /blog/my-article. Out of the box it transliterates («é» becomes «e»), separates words with hyphens and caps aliases at 150 characters18. It also strips a list of short English words (a, an, the, of…) from aliases; review that list on the Settings tab if you want words like «the» kept.
Redirect lives under Configuration > Search and metadata > URL redirects. Its defaults already do the right thing19:
- Automatically create redirects when URL aliases are changed: on. When Pathauto regenerates an alias, the old URL answers with a 301.
- Default redirect status: 301.
- Enforce clean and canonical URLs: on. It redirects
/node/123to its alias, strips trailing slashes and adds the language prefix.
How do you configure Drupal's robots.txt without losing it on update?
Drupal's robots.txt is a Composer scaffold file: every composer install or core update writes it again. Edit it by hand and your changes disappear on the next update. Drupal's documentation recommends adding lines with append rather than excluding the file, so you keep receiving fixes to it20. In the project's composer.json:
{
"extra": {
"drupal-scaffold": {
"file-mapping": {
"[web-root]/robots.txt": {
"append": "assets/robots-additions.txt"
}
}
}
}
}And in assets/robots-additions.txt, the Sitemap line, which Google requires as a full URL21, plus your policy for training crawlers:
# Model training: blocking it does not remove you from ChatGPT or Google
User-agent: GPTBot
User-agent: ClaudeBot
User-agent: Google-Extended
User-agent: CCBot
Disallow: /
Sitemap: https://www.example.com/sitemap.xmlWe checked the Drupal 11.4.8 robots.txt plus this addition with Protego, which applies Google's rules: articles, /sites/default/files/ and the CSS and JavaScript under /core/ stay open to Googlebot, OAI-SearchBot, Claude-SearchBot and PerplexityBot; /admin/, /user/login and search pages stay closed; GPTBot, ClaudeBot and CCBot are kept out entirely. The training group is optional and editorial: the crawlers that decide whether ChatGPT or Claude can cite you are OAI-SearchBot and Claude-SearchBot, and Google-Extended has no effect on Google Search222324. The guide to AI crawlers and robots.txt covers each one.
If you run several sites from one codebase, the RobotsTxt module generates a robots.txt per site that you edit in the admin UI; it requires deleting or renaming the physical file25.
How do you generate an XML sitemap in Drupal?
With Simple XML Sitemap, which publishes /sitemap.xml and regenerates it on cron26. Once installed:
- Under Configuration > Search and metadata > Simple XML Sitemap, Inclusion tab (
/admin/config/search/simplesitemap/entities), choose which content types and vocabularies go in. - Exclude any node set to
noindex: a sitemap should only list URLs you want indexed. - On a multilingual site, the sitemap includes each URL's hreflang alternates.
- Submit the sitemap URL in Search Console and check it matches the Sitemap line in robots.txt.
How do you add structured data in Drupal?
With Schema.org Metatag, which adds groups of fields to Metatag that are printed as JSON-LD in the <head>15. Each type is a submodule: schema_article, schema_organization, schema_product, schema_event, schema_recipe and so on. You fill the fields with tokens in Metatag's defaults and override them per node where needed.
The @type of the Organization group accepts any schema.org subtype of Organization, LocalBusiness included27: that is the route for marking up address and opening hours on your contact page. For a shop, schema_product lets you mark up Offer, Brand and ratings; what Google expects on product pages is in the guide to Product schema. Do not mark up FAQ or HowTo for Google's benefit: HowTo stopped showing as a rich result in 2023 and FAQ on 7 May 202628.
How do you add HSTS and CSP in Drupal?
Core sends no HSTS, Content-Security-Policy or Referrer-Policy. Security Kit adds them from Configuration > System > Security Kit settings (/admin/config/system/seckit). This is what it ships with29:
- Option
- HTTP Strict Transport Security
- Default
- Off;
max-ageof 1,000 seconds - What to do
- Turn it on with a short
max-ageand raise it later
- Option
- Content Security Policy
- Default
- Off
- What to do
- Turn it on in Report Only mode first
- Option
- X-Frame-Options
- Default
SAMEORIGIN- What to do
- Keep it
- Option
- Referrer-Policy
- Default
- Off
- What to do
- Turn it on with
strict-origin-when-cross-origin
- Option
- X-XSS-Protection
- Default
- Disabled
- What to do
- Leave it: the header is obsolete
Do not tick Preload for HSTS until it has run for weeks without problems: the preload list forces HTTPS on every subdomain and getting off it takes months30. Security Kit still uses Feature-Policy, the old name for Permissions-Policy; if you need that header, set it at the server. If Nginx or Apache already sends these headers, do not duplicate them in Drupal. The guide to HTTP security headers explains what each one does.
How to check it
- Canonical and hreflang: view the source of a node and search for
rel="canonical"andhreflang. Request the same URL with and withoutwww: the secondary variant should 301. - Headers:
curl -I https://www.example.com/should showx-content-type-options,x-frame-optionsand, if enabled,strict-transport-securityandreferrer-policy. Mozilla's HTTP Observatory scores them. - robots.txt: after a
composer update, open/robots.txtand check your lines are still at the end. - Structured data and sitemap: the Rich Results Test and Search Console's Sitemaps report.
What SmoothSeen does with this
SmoothSeen checks a page of your site for what this guide configures: robots.txt, sitemap, canonical and noindex, titles and descriptions, structured data, HTTPS and the redirect to https, and security headers via Mozilla's HTTP Observatory. On the AI side it looks at which crawlers your robots.txt allows, separating search from training, and whether your server returns a 403 to any of them while serving the page to a browser.
What to do this week
Request your site with and without www and over http: if any variant does not 301, enable the .htaccess rule or the server equivalent, because core's canonical depends on it. Then move your robots.txt additions into a file loaded with append. To see the rest of the list measured, run an SEO audit with SmoothSeen.
Frequently asked questions
Does Drupal need modules for SEO or is core enough?
Core covers the canonical tag, hreflang for translations, manual aliases and two security headers. It lacks meta descriptions, an XML sitemap, redirects and structured data. A site with a handful of pages can live with manual aliases, but meta descriptions and a sitemap justify installing Metatag and Simple XML Sitemap from day one.
Why does my Drupal robots.txt keep reverting to the original?
Because Composer's scaffold plugin rewrites it every time you install or update core. That is not a bug: it is how Drupal ships fixes to that file. Move your rules into a file of your own and declare in composer.json that it should be appended with append; that way you keep both your changes and core's improvements.
Should I use Metatag or Yoast SEO in Drupal?
They do not compete. Metatag is what prints the tags in the <head>, and the Real-time SEO for Drupal module (package yoast_seo) depends on it and adds readability and keyword analysis while editors write. Drupal CMS installs both in its SEO Tools recipe. If you do not need that writing analysis, Metatag on its own is enough.
Will the modules in this guide work on Drupal 12?
Drupal 12 ships in December 2026 and each module declares its compatibility separately on its drupal.org page. All six in this guide accept Drupal 10 and 11 today. Before upgrading, check that every one declares ^12, or run the Upgrade Status module, which scans your installation and flags code that still needs updating.
Sources
- 1Drupal core release schedule, Drupal.org, updated 27 August 2026.
- 2Drupal core (releases), Drupal.org, accessed 9 October 2026.
- 3Drupal CMS Basic SEO recipe (recipe.yml), official Drupal CMS repository, 2.0.x branch, accessed 9 October 2026.
- 4Drupal CMS SEO Tools recipe (recipe.yml), official Drupal CMS repository, 2.0.x branch, accessed 9 October 2026.
- 5EntityViewController.php, view function, official Drupal repository, version 11.4.8, accessed 9 October 2026.
- 6Drupal scaffold .htaccess, official Drupal repository, version 11.4.8, accessed 9 October 2026.
- 7ContentTranslationHooks.php, pageAttachments function, official Drupal repository, version 11.4.8, accessed 9 October 2026.
- 8FinishResponseSubscriber.php, official Drupal repository, version 11.4.8, accessed 9 October 2026.
- 9Standard install profile (standard.info.yml), official Drupal repository, version 11.4.8, accessed 9 October 2026.
- 10PerformanceForm.php and system.performance.yml, official Drupal repository, version 11.4.8, accessed 9 October 2026.
- 11Metatag, Drupal.org, accessed 9 October 2026.
- 12Pathauto, Drupal.org, accessed 9 October 2026.
- 13Redirect, Drupal.org, accessed 9 October 2026.
- 14Simple XML sitemap, Drupal.org, accessed 9 October 2026.
- 15Schema.org Metatag, Drupal.org, accessed 9 October 2026.
- 16Security Kit, Drupal.org, accessed 9 October 2026.
- 17Metatag default configuration (config/install), official Metatag repository, 2.2.x branch, accessed 9 October 2026.
- 18pathauto.settings.yml, official Pathauto repository, 8.x-1.x branch, accessed 9 October 2026.
- 19redirect.settings.yml, official Redirect repository, 8.x-1.x branch, accessed 9 October 2026.
- 20Using Drupal's Composer Scaffold, Drupal.org, updated 14 September 2026.
- 21How Google interprets the robots.txt specification, Google Search Central, updated 31 August 2026.
- 22Overview of OpenAI Crawlers, OpenAI, accessed 9 October 2026.
- 23Does Anthropic crawl data from the web, and how can site owners block the crawler?, Anthropic, updated 7 April 2026.
- 24AI features and your website, Google Search Central, updated 10 December 2025.
- 25RobotsTxt, Drupal.org, accessed 9 October 2026.
- 26simple_sitemap.settings.yml, official Simple XML Sitemap repository, 4.x branch, accessed 9 October 2026.
- 27SchemaOrganizationType.php, official Schema.org Metatag repository, version 3.1.0, accessed 9 October 2026.
- 28Latest Google Search documentation updates, Google Search Central, accessed 9 October 2026.
- 29seckit.settings.yml, official Security Kit repository, 2.x branch, accessed 9 October 2026.
- 30Strict-Transport-Security header, MDN Web Docs, updated 11 September 2026.
How to cite this article
SmoothSeen. (2026, October 7). Drupal SEO: what Drupal 11 core does and which modules to install. https://smoothseen.com/en/blog/drupal-seo/
Keep reading
What is SEO? How search engine optimisation works and how to improve it in 2026
What SEO is, how Google decides which pages to show and a prioritised checklist to improve your rankings with free tools.
.htaccess force HTTPS: redirect to https, enable HSTS and add security headers in Apache
How to force HTTPS in .htaccess or an Apache VirtualHost, roll out HSTS safely and add security headers. Every snippet tested on Apache 2.4.69.
.htaccess gzip and Brotli: browser caching and blocking AI bots in Apache
How to enable gzip and Brotli, set browser caching and block AI training bots in Apache .htaccess without dropping out of ChatGPT search. Tested.