Meanwhile, Gray's suggestion would provide any attacker within enough capital to a backdoor, while legitimate users need to pay to unlock their account without any benefit to them from a security perspective.
I strongly disagree with such a concept -- unless, as you mentioned, payment could be used to verify the identity. That said, I think that's the same reason GitLab is now only offering MFA for paying customers, because they have a bit more PII to confirm your identity if you're a current customer -- in which case, why require payment at all?
If NPM or any other package repository introduced this, do you think maintainers of commonly used open source projects wouldn't feel obliged to pay up? Generally immediately after a traumatic event such as having their phone stolen.
Even if you never plan to update your package, you can't fix a security vulnerability without spending money.
I don't need recovery codes for anything in my professional nor personal life outside open source programming.
Sort of like "If this person is paying for this, he's probably legit."