It appears to be biased towards npm given that one set of dots is "JSON Based" and could have just as easily been "XML Based." I mean strictly the chart, not the article. The article seemed fair.
I don't know that I agree that having the dependency definition in native code is a source of vulnerabilities; it could make the definition easier to write for people packaging code in that language. Also, I think JSON could be considered native code for npm since it is written in nodejs/javascript.