Everything in www ships inside the APK as plain files. Anyone can unzip it:
unzip -p platforms/android/app/build/outputs/apk/debug/app-debug.apk \
assets/www/js/index.js | grep -n "fetch("42: books = (await (await fetch('data/books.json')).json()).books;An API key in that file or in config.xml is public, minified or not. Keep service keys on a server your app calls with a per-user token, restrict any key that must ship to your package and signing certificate, and keep tokens in a plugin backed by the Android Keystore and iOS Keychain, not localStorage.
Plugins need the same care as any dependency, with one extra risk: their native code runs with your app's permissions. In BookNest, npm 2,036 outdated printed nothing and npm audit reported found 0 vulnerabilities. Run both before each release, and upgrade cordova-android every summer for Google Play 1 's target-API deadline (Play Console Requirements).