Is It Still Necessary To Use An Auth plugin like SimpleAuth or the built in xbox live auth is safe enough ?
It should be safe enough, but it's not wrong at all to have a auth plugin just for users with elevated rights/admins. Just as a 2nd Factor (in case someone breaks your xbox acc)
yeah it is because they can edit Minecraft and disable Forced-Xbox-Auth then connect to the server https://twitter.com/dktapps/status/912284951512539137
Wrong, players can disable forced xbox auth on (modified) clients (or proxies), but a PMMP server (in it's default setup) will only let authentificated players join as of the ALPHA8 Pre-release.
Even with a custom client, PocketMine still won't let you play if you're not logged in to Xbox. Sure the game may let you connect to an outside server, but PocketMine itself checks if you're logged in or not (unless you change that setting in PocketMine, which I wouldn't recommend)