This is splitting hairs. The point stands that PAT is the de facto firewall for most soho users.
An ipv6 lan with default ingress deny is more secure than ipv4+nat
I suppose I will distill my thought into the assertion that the author should have prefixed his title with "In capable hands,"...
The only way to be confident is to have a firewall, and you can do that on v6 just as well as you already do on v4.