IMHO, a package should deliver a set of files to certain directories. That's it.
It should not overwrite existing files, that were installed by other packages. It should not change existing files in any way.
It might advise the system to trigger certain reindexing actions (systemd daemon reolad, update man-db, etc.) but doing this should be the duty of the package manager, not the package itself.
AFAIK, nix and Solaris' pkg are pretty close to this ideal.
A big advantage that this has, on top of security, is that:
- packages can be uninstalled safely and without side-effects
- package contents can be inspected (pkg contents)
- corrupted installations can be detected using checksums (pkg fix)
- package updates/installs can be rolled back using file system snapshots.