files in package.json whitelists what ships, and prepublishOnly runs the build. Before a release, run npm 2,036 run verify (the web build, gradlew clean build test, and xcodebuild, which needs a Mac), then set the version and rehearse:
npm version 1.0.0
npm publish --dry-run --access publicv1.0.0 ... npm notice package size: 6.6 kB npm notice unpacked size: 23.8 kB npm notice total files: 26 ... npm notice Publishing to https://registry.npmjs.org/ with tag latest and public access (dry-run) + @booknest/capacitor-disk-space@1.0.0
npm version bumped package.json, committed and tagged v1.0.0. The 26 files are source code, the Kotlin and Swift files included, not binaries: every app compiles its plugins in its own build. The real publish is npm login, then npm publish --access public (scoped packages default to private, and you must own the scope).
Then keep the habits Vetting Community Plugins checks for: an honest @capacitor/core peer range, a new major for each Capacitor 243,123 major, and permissions declared in the plugin's own manifest, with the iOS Info.plist keys listed in the README.