Regarding your second point: PAR's zipping of files is
not presented as anything other than packing several files
together in a single file for convenience in delivery. It
is not held out as meant for hiding anything. Using XOR
(so-called) encryption only serves to obscure the source.
It is a weak attempt at source code encryption, having
nothing at all to do with bundling files together into
a single distribution file.
I think that that distinction is central to the "problem".