Unused modules and themes report
Every enabled module and installed theme is code someone has to patch, scan and host, and every one widens what a security review has to cover. The Unused modules and themes report lists the ones that look unused, plus code sitting on disk that isn't installed at all, with the evidence for each verdict.
It is a report only. It never uninstalls or deletes anything.
Where to find it
Reports » Drupal Cleanup » Unused modules and themes (/admin/reports/drupal-cleanup/extensions), with the Administer Drupal Cleanup permission. By default it shows only what to review; Show everything includes what is in use, with the evidence. From the command line:
drush cleanup:extensions drush cleanup:extensions --all drush cleanup:extensions --format=csv
How modules are judged
For each installed module the report looks for evidence of use:
- other installed modules that require it,
- content or configuration stored in the entity types it provides (with the size of their tables, on MySQL and MariaDB),
- rows in the tables it declares itself,
- site configuration built on it: views, blocks, fields, text formats, roles granting its permissions and so on, not counting the configuration the module ships itself,
- its log entries from the last 30 days, if Database Logging is on.
| Verdict | Meaning |
|---|---|
| Development module | A development or UI-building module (Devel, Kint, Webprofiler, Views UI, Field UI...) that is usually turned off in production. |
| No usage detected | None of the evidence above was found. Review it before uninstalling: a module can still change behavior through hooks, services or routes without leaving data behind. |
| Removable code | On disk but not installed, and no module from the same project is installed, so the whole project can be removed from the codebase (for example with composer remove). |
| Part of a project in use | On disk but not installed, but another module from the same project is, so it can't be removed on its own. Shown only in the full view. |
| Infrastructure | A core module that does its job without storing data (page caching, BigPipe, the database driver, logging...). Not a candidate. |
| In use / Required | Evidence of use was found, or the module is required by core or is the site's install profile. |
Uninstalled core modules aren't listed (core can't be removed piece by piece), and neither are hidden or testing modules.
How themes are judged
The default theme, the administration theme and the base themes of either are in use. Any other installed theme is listed as Installed, not used, with the number of blocks placed in it. A module could still switch to it on some pages, so check before uninstalling. Non-core themes on disk that aren't installed are listed as removable code.
Why it matters
- Less to patch. Every module on disk, installed or not, can receive security advisories that someone has to assess and apply.
- Less to scan and accredit. Vulnerability scanners flag code on disk whether or not it is enabled, and an ATO or FISMA review covers every component of the system. Removing what isn't used shrinks both.
- Less to run. Each enabled module adds to cron, cache rebuilds and every request's bootstrap.
Help improve this page
You can:
- Log in, click Edit, and edit this page
- Log in, click Discuss, update the Page status value, and suggest an improvement
- Log in and create a Documentation issue with your suggestion