Unused modules and themes report

Last updated on
1 October 2026

Every enabled module and installed theme is code someone has to patch, scan and host, and every one widens what a security review has to cover. The Unused modules and themes report lists the ones that look unused, plus code sitting on disk that isn't installed at all, with the evidence for each verdict.

It is a report only. It never uninstalls or deletes anything.

Where to find it

Reports » Drupal Cleanup » Unused modules and themes (/admin/reports/drupal-cleanup/extensions), with the Administer Drupal Cleanup permission. By default it shows only what to review; Show everything includes what is in use, with the evidence. From the command line:

drush cleanup:extensions
drush cleanup:extensions --all
drush cleanup:extensions --format=csv

How modules are judged

For each installed module the report looks for evidence of use:

  • other installed modules that require it,
  • content or configuration stored in the entity types it provides (with the size of their tables, on MySQL and MariaDB),
  • rows in the tables it declares itself,
  • site configuration built on it: views, blocks, fields, text formats, roles granting its permissions and so on, not counting the configuration the module ships itself,
  • its log entries from the last 30 days, if Database Logging is on.
Verdict Meaning
Development module A development or UI-building module (Devel, Kint, Webprofiler, Views UI, Field UI...) that is usually turned off in production.
No usage detected None of the evidence above was found. Review it before uninstalling: a module can still change behavior through hooks, services or routes without leaving data behind.
Removable code On disk but not installed, and no module from the same project is installed, so the whole project can be removed from the codebase (for example with composer remove).
Part of a project in use On disk but not installed, but another module from the same project is, so it can't be removed on its own. Shown only in the full view.
Infrastructure A core module that does its job without storing data (page caching, BigPipe, the database driver, logging...). Not a candidate.
In use / Required Evidence of use was found, or the module is required by core or is the site's install profile.

Uninstalled core modules aren't listed (core can't be removed piece by piece), and neither are hidden or testing modules.

How themes are judged

The default theme, the administration theme and the base themes of either are in use. Any other installed theme is listed as Installed, not used, with the number of blocks placed in it. A module could still switch to it on some pages, so check before uninstalling. Non-core themes on disk that aren't installed are listed as removable code.

Why it matters

  • Less to patch. Every module on disk, installed or not, can receive security advisories that someone has to assess and apply.
  • Less to scan and accredit. Vulnerability scanners flag code on disk whether or not it is enabled, and an ATO or FISMA review covers every component of the system. Removing what isn't used shrinks both.
  • Less to run. Each enabled module adds to cron, cache rebuilds and every request's bootstrap.

Help improve this page

Page status: No known problems

You can: