I respectfully disagree with the author.

Once you put stuff on someone else’s servers, they can do whatever they want to the package as long as it doesn’t break the license. That includes marking the package as critical or even making a fork the canonical repo. If you want that kind of control, you need to become your own package provider. Or distribute your code with a more restrictive license.

