opnsense. you dont need to run these garbage consumer routers. downside is if your ISP still provides a modem/CPE. but some times you can put those into bridge mode and make them less of a risk
Maybe they don't care to fiddle with a command line, read up on dhcp servers, ipv6 router advertisements, pf configuration and what have you. In such a case, throwing opnsense on some machine, clicking around on three pages and calling it a day isn't that bad.
The experience is close enough to an off-the-shelf router (except for the installation part), all the while getting a much better security situation.
In both cases it is behind a firewall (and NAT, if applicable).