I think the criticism is still valid: combining a MAC and cipher into an AE scheme (especially an AEAD scheme) is anything but trivial. For example, I don't think it's reasonable to suggest someone would, given those two tools, end up with the moral equivalent of secretbox but with ChaCha20 replacing XSalsa20. (At least there's not a padding timing differential for MtE, but still.)