WP-STEG is a WordPress security audit tool that detects orphaned or hidden media files by comparing data from the WP-JSON API with files found via directory listing.
Wreckair-DB is a WordPress security testing tool that exploits insecure design in the repair.php functionality to trigger a prolonged Denial of Service (DoS) condition.