We have the possibility to modify server.prop via an options editor. My suggestion is to implement a similar mechanism for spigot.yml's useful, non-abusive and not system-breaking parameters instead of blocking the file entirely.
messages:
- whitelist
- unknown-command
- server-full
- outdated-client
- outdated-server
stats:
- disable-saving
- forced-stats