Reading plugin.xml

Reading a Plugin's plugin.xml Before You Install It

plugin.xml states exactly what a plugin will do to your native project (plugin.xml Wiring), and you can read it without installing anything. npm 2,036 pack downloads the published tarball:

Unpacking cordova-plugin-camera's plugin.xml and listing what it changesXML
npm pack cordova-plugin-camera@8.0.0 --silent
tar -xzf cordova-plugin-camera-8.0.0.tgz package/plugin.xml
grep -nE "<engine |<platform |uses-permission|<framework|<dependency|<preference" \
  package/plugin.xml
Output
cordova-plugin-camera-8.0.0.tgz
33:        <engine name="cordova" version=">=9.0.0"/>
34:        <engine name="cordova-android" version=">=12.0.0" />
35:        <engine name="cordova-ios" version=">=5.1.0" />
51:    <platform name="android">
92:        <preference name="ANDROIDX_CORE_VERSION" default="1.6.+"/>
93:        <framework src="androidx.core:core:$ANDROIDX_CORE_VERSION" />
101:     <platform name="ios">
106:             <preference name="CameraUsesGeolocation" value="false" />
120:         <framework src="ImageIO.framework" weak="true" />
121:         <framework src="CoreLocation.framework" />
122:         <framework src="CoreGraphics.framework" />
123:         <framework src="AssetsLibrary.framework" />
124:         <framework src="MobileCoreServices.framework" />
125:         <framework src="CoreGraphics.framework" />
126:         <framework src="AVFoundation.framework" />
131:    <platform name="browser">

Read it from the top. The <engine> lines say this release needs cordova-android 12 or later, which BookNest's 15.1.0 meets. The Android section adds one Gradle 19,597 dependency, AndroidX 234 Core, whose version you can override with --variable ANDROIDX_CORE_VERSION=..., and no uses-permission at all, confirming Vibration and Camera: the plugin borrows the camera app instead of using the camera itself. There is no <dependency> on other plugins; cordova-plugin-media declares one on cordova-plugin-file.

An Android section that adds READ_CONTACTS or an unknown Maven 129 repository deserves a look at the source: Google Play 1 makes you justify every sensitive permission, whichever plugin added it.