This could indeed be the one size fits all, although I still think unused features should be removed entirely (maybe available as downloadable extra modules).
But features unused by you are not unused by everybody.
...
But features used by you are not used by everybody.We need figures to make sense. This was the purpose of this topic but nobody says if they actually using invoices or lightning other than for testing...
Hiding isn't enough in my opinion, see above.
If your concern is the attack vector presented by additional features, then your risk model is probably all messed up.
...
I don't think my risk model is messed up as it's the only thing I don't have under my own control which I always consider the biggest risk.
Servers sending malicious messages (in the past) illustrates this perfectly. The software didn't stop anything, my own caution saved me.
Greets.