Security of the plugins

I love Obsidian, been obsessed with it and went through the learning curve, there was data on my notes that were not sensitive before but now I just can’t afford for it to be exfiltrated. Without really strict controls on how plugins could manipulate data I will be forced to use some alternative for this vault / content. Question, the core plugins are completely under Obsidian dev control including any libraries these could use?
Edit: Note that I was always aware the plugins could potentially pose a risk, this is not new, just found this post which reflects my similar thoughts.