Drupal vs Liferay is less a head-to-head contest than a question of which job a university needs done. Drupal is strongest on the public web: the main site, school and department sites, program pages and faculty profiles that prospective students, parents, journalists and search engines see. Liferay is strongest behind the login: student and staff portals, intranets and internal applications. For a university rebuilding its main website and departmental network, Drupal is usually the better fit. For a large authenticated portal that brings documents, forms, approvals and back-office systems into one place, Liferay remains a serious contender.
The comparison also deserves a fresh look in 2026, because Liferay has retired its free Community Edition and replaced it with a key-activated Free Tier. This guide compares the two platforms through a higher-education lens, explains what the licensing change means in practice, and sets out when each one makes sense.
Websites and portals are different jobs
A university's digital estate has two halves. The public website is read by people who are not logged in — prospective students comparing programs, parents, reporters and search engines. What matters there is running dozens or hundreds of sites from one platform, publishing in several languages, being found in search and meeting accessibility law.
The portal is the opposite. Students log in to check schedules and request documents; staff log in to read internal news and submit forms. Pages are personal, invisible to search engines and usually fed by back-office systems such as Banner, PeopleSoft or Workday. What matters there is permissions, workflow, document management and bringing internal applications under one roof.
Drupal's strengths sit in the first half, Liferay's in the second. Liferay can run public websites too, but portals and intranets head the list of solutions on its own product pages. Drupal's footprint in higher education comes from public sites: a study by The Drop Times based on the QS World University Rankings found that 80% of the world's top 100 universities use Drupal on at least one website.
Stanford University shows how the split plays out. Stanford Sites, the central platform where departments, institutes and labs build their websites, runs on the latest version of Drupal. According to a case study published by the implementation firm Base22, Stanford's student and faculty portal was running on Liferay DXP when Base22 redesigned it. Same campus, two platforms, each doing the job it is best at.
What changed in 2026: the end of Liferay Community Edition
For years Liferay shipped two products: the free Community Edition (CE) and the subscription-based Liferay DXP. According to Liferay, the final CE release came out in early 2025. Starting with the 2026.Q1 release, the two were merged into a single platform whose capabilities are switched on by an activation key, and free use moved to a new Free Tier.
The Free Tier key is requested at no cost through Liferay Marketplace, is valid for 12 months and is tied to the domain entered at registration. It unlocks the core platform — content management, sites, pages, headless APIs and workflow — plus clustering on up to three nodes. Liferay itself positions the tier for learning, development, small-scale use and proof-of-concept work.
The exclusions are what matter for higher education. Liferay's documentation lists multi-factor authentication, SAML and advanced search tuning among the capabilities that require an Enterprise Subscription. Wherever campus single sign-on runs on SAML — through Shibboleth or federations such as InCommon and eduGAIN — a production portal on the Free Tier is hard to justify. Updates are limited too: free users can install each quarter's releases from the .0 version up to the patch Liferay declares stable for that quarter, while later patches are reserved for subscribers.
Liferay's source code remains open. The company says it stays available under the LGPL in the master branch for anyone who prefers to build from it, although self-building puts you outside the tested releases and vendor support. Liferay does not publish list prices; subscriptions are quoted through its sales team. Our TCO analysis of open-source vs licensed systems walks through how to compare the long-term cost of both models.
Drupal's model is simpler. Drupal is licensed under the GPL, version 2 or later, and every release of core and contributed modules — security releases included — is the same for everyone. SAML login is handled by free contributed modules: the SAML Authentication module, for example, reports more than 19,000 sites, and its stable release is covered by Drupal's security advisory policy. Setup is covered in our guide to Drupal SSO integration with SAML, Shibboleth, LDAP and CAS.
Drupal vs Liferay for higher education: side by side
The table below summarizes the criteria university teams usually weigh. Market-share figures come from W3Techs data dated 8 October 2026.
| Criterion | Drupal | Liferay |
|---|---|---|
| Core strength | Public websites and multi-site networks | Authenticated portals, intranets and internal applications |
| License | GPL v2 or later; every release is free | Source under LGPL; packaged releases via the Free Tier or an Enterprise Subscription |
| Runtime | PHP | Java |
| SAML single sign-on | Free contributed modules | Requires an Enterprise Subscription |
| Search | Database search in core; Solr or similar added when needed | Separate Elasticsearch, OpenSearch or Solr cluster required in production |
| Multilingual | 110+ languages supported in core | Multilingual content and localization |
| Accessibility | Core targets WCAG 2.2 Level AA | Publishes VPAT-based Accessibility Conformance Reports |
| Support model | Community, agencies and hosting partners | Vendor support with an Enterprise Subscription |
| Share of top 10,000 sites | 6.7% | 0.8% |
The rows that usually decide the matter are runtime and search. Liferay runs on Java and needs a dedicated search cluster in production; the Elasticsearch sidecar it ships with is meant for testing only. That is no burden for an IT team already running Java services and Elasticsearch. A team built around PHP and standard Linux hosting will find that Drupal fits its existing skills more naturally.
Both platforms run many sites, in different ways. Liferay can host many sites, each on its own domain, inside one installation. Drupal offers several ways to run school and department sites from a shared codebase, and we compare their trade-offs in Drupal multisite for university websites.
Accessibility and compliance
Public colleges and universities in the United States fall under the Department of Justice's ADA Title II web accessibility rule, which uses WCAG 2.1 Level AA as its technical standard. After the DOJ's amendment of 20 April 2026, the compliance dates are 26 April 2027 for public entities serving 50,000 people or more, and 26 April 2028 for smaller entities and special district governments. In Europe, EN 301 549 sets the benchmark for public-sector websites and apps.
Neither platform makes a site compliant on its own; themes, components and content decide the outcome. The difference lies in what each project commits to. Drupal core targets WCAG 2.2 at Level AA for both public-facing and administrative interfaces, while noting that individual sites and contributed projects still need their own review. Liferay publishes Accessibility Conformance Reports based on VPAT 2.5 for its admin and site experiences, which procurement teams can review before signing.
Data protection follows a similar logic. Both platforms can be self-hosted, which keeps personal data on infrastructure the university controls. If a vendor cloud or managed hosting service is chosen, GDPR requires clarity on where personal data is processed and under which transfer mechanism.
When Liferay is the better choice — and where Drupal falls short
Liferay makes sense when the center of gravity is a large authenticated portal rather than the public website. Document management, forms, approval workflows and low-code app building come in one platform. If the IT team works in Java and leadership wants a single vendor accountable under a support contract, Liferay's subscription model delivers exactly that.
Drupal has real limits too. Portal features do not arrive as a packaged suite; they are assembled from modules and custom development. No single commercial vendor stands behind the platform, so support comes from agencies and hosting partners. Maintenance quality varies between contributed modules: the SAML Authentication project page itself says maintenance is lagging because it is volunteer-driven, while noting that this is not known to affect most sites using it. Major upgrades need a calendar as well. Drupal 12 is scheduled for December 2026, and security support for Drupal 10.6 ends the same month, so institutions still on Drupal 10 should plan their upgrade now.
How to decide
Start with the job, not the platform. If the project is the main website, school and department sites and international content, you are in Drupal's territory, and that is also where search visibility comes from, since nothing behind a login is crawled. If the project is a portal that integrates Banner, PeopleSoft or Workday data, expect custom integration work on either platform and weigh Liferay's packaged portal features against Drupal's flexibility. If Liferay is on the table for production, budget for the Enterprise Subscription from day one rather than planning around the Free Tier. For a wider view of how an open-source platform compares with a licensed DXP, see our comparison of Drupal vs Sitecore for universities.
At Drupart, the Drupal4edu team builds Drupal platforms for institutions such as TED University and Isik University. The first question we ask on every project is the one this article started with: which content belongs on the public site, and which belongs behind the login? You can read more about our approach on our Drupal for education page.
Drupal vs Liferay: frequently asked questions
Is Liferay still free after the end of Community Edition?
Partly. Liferay Community Edition received its final release in early 2025. Since the 2026.Q1 release, free use runs through the Liferay DXP Free Tier, which requires a free activation key from Liferay Marketplace. The key lasts 12 months, is tied to a domain and unlocks core features such as content management, sites, workflow and headless APIs. Multi-factor authentication, SAML and advanced search tuning require an Enterprise Subscription, and free users only receive each quarter's releases up to the designated stable patch. Liferay does not publish subscription prices; quotes come through its sales team.
Is Liferay open source?
Liferay's source code is open: the company keeps it available under the LGPL in the master branch, and anyone can build from it. What changed in 2026 is the distribution model. The packaged, tested releases that organizations deploy now run as a single platform activated by a key, with a free key for core features and a subscription key for the rest. Building from source is possible but leaves you without tested releases or vendor support. Drupal, by comparison, is licensed under the GPL, and every release, including security releases, is the same for everyone at no cost.
Can Drupal power a student portal?
Yes. Drupal's roles and permissions, SAML single sign-on modules and APIs are enough to show logged-in students personalized content, documents, forms and data pulled from a student information system such as Banner, PeopleSoft or Workday. The difference from Liferay is that none of this arrives as a packaged portal suite; modules are chosen and integrations are built during the project. For a portal that mainly delivers content and a handful of services, Drupal is a strong fit. For a portal meant to consolidate many internal applications and complex approval workflows, a portal-first platform such as Liferay deserves a serious look.
Can a university run Drupal and Liferay together?
Yes, and large universities do. Stanford runs its departmental, institute and lab websites on Stanford Sites, a Drupal platform, while a case study by the implementation firm Base22 describes Stanford's student and faculty portal as running on Liferay DXP. In this model the public website network lives in Drupal and the authenticated portal lives in Liferay. Two things make it work. Both systems should authenticate against the same identity provider so users sign in once, and both should share a design system so visitors see one institution rather than two platforms.