cordova plugin add takes one or more npm 2,036 package names, a Git 1,932 URL or a local folder, installs each into plugins/ for every platform in the project, and records it in package.json:
cordova plugin add cordova-plugin-device cordova-plugin-network-information
cordova plugin lsInstalling "cordova-plugin-device" for android Installing "cordova-plugin-device" for browser Adding cordova-plugin-device to package.json Installing "cordova-plugin-network-information" for android Installing "cordova-plugin-network-information" for browser Adding cordova-plugin-network-information to package.json cordova-plugin-device 3.0.0 "Device" cordova-plugin-network-information 3.1.0 "Network Information"
package.json now lists both under devDependencies and under cordova.plugins, so cordova prepare restores them on a fresh clone (Exporting Projects). cordova plugin rm cordova-plugin-device removes one, cordova plugin add cordova-plugin-camera@8.0.0 pins a version, and --variable NAME=value answers a plugin's install-time <preference>, such as an API key.
The CLI also checks each plugin's declared engine requirements before choosing a version. For cordova plugin add cordova-plugin-splashscreen it printed Unmet project requirements for latest version of cordova-plugin-splashscreen: cordova-android (15.1.0 in project, >=3.6.0 <11.0.0 required) and installed 6.0.1 instead of 6.0.2. That fallback is not a fix: 6.0.1 simply predates the restriction, and Orientation and Statusbar shows the conflict it causes. When a plugin's newest release excludes your platform version, remove the plugin.