The section discussing dynamic IP addresses seems to be based on a misunderstanding of Wireguard. The IP addresses that must be statically established in Wireguard are the addresses used inside of the tunnel, and are independent of the public (internet) IPs of the machines involved. The wg-dynamic daemon mentioned is a system for dynamically allocating IP addresses in the tunnel, and has so far not been completed, at least in part because it's not very obvious why you would want to do this (although in general the development of an in-band configuration standard for Wireguard has useful implications).
Wireguard allows you to identify the endpoint using a DNS name, which means you can handle a 'server' with a dynamic IP address by dynamically updating the DNS record - a common approach that is no doubt exactly what ipfire supports doing for ipsec.
In the end, though, the article just suffers from being an apples-to-oranges comparison. Wireguard is a VPN tunnel protocol implementation, ipfire is some sort of GUI frontend for managing a bunch of network tools. Of course ipfire has quite a few more features than wireguard.