plugin.xml states exactly what a plugin will do to your native project (plugin.xml Wiring), and you can read it without installing anything. npm 2,036 pack downloads the published tarball:
npm pack cordova-plugin-camera@8.0.0 --silent
tar -xzf cordova-plugin-camera-8.0.0.tgz package/plugin.xml
grep -nE "<engine |<platform |uses-permission|<framework|<dependency|<preference" \
package/plugin.xmlcordova-plugin-camera-8.0.0.tgz 33: <engine name="cordova" version=">=9.0.0"/> 34: <engine name="cordova-android" version=">=12.0.0" /> 35: <engine name="cordova-ios" version=">=5.1.0" /> 51: <platform name="android"> 92: <preference name="ANDROIDX_CORE_VERSION" default="1.6.+"/> 93: <framework src="androidx.core:core:$ANDROIDX_CORE_VERSION" /> 101: <platform name="ios"> 106: <preference name="CameraUsesGeolocation" value="false" /> 120: <framework src="ImageIO.framework" weak="true" /> 121: <framework src="CoreLocation.framework" /> 122: <framework src="CoreGraphics.framework" /> 123: <framework src="AssetsLibrary.framework" /> 124: <framework src="MobileCoreServices.framework" /> 125: <framework src="CoreGraphics.framework" /> 126: <framework src="AVFoundation.framework" /> 131: <platform name="browser">
Read it from the top. The <engine> lines say this release needs cordova-android 12 or later, which BookNest's 15.1.0 meets. The Android section adds one Gradle 19,597 dependency, AndroidX 234 Core, whose version you can override with --variable ANDROIDX_CORE_VERSION=..., and no uses-permission at all, confirming Vibration and Camera: the plugin borrows the camera app instead of using the camera itself. There is no <dependency> on other plugins; cordova-plugin-media declares one on cordova-plugin-file.
An Android section that adds READ_CONTACTS or an unknown Maven 129 repository deserves a look at the source: Google Play 1 makes you justify every sensitive permission, whichever plugin added it.