LineageOS roms are probably as safe (regarding bad actors) as they can get with custom ROMs.
They undeniably have declined in popularity, partially because Stock Android now contains lots of features that used to be exclusive to custom roms and partially because those people more privacy minded have moved to alternatives like Pinephones and such.
I generally don't trust custom roms you can get from individuals in XDA unless they have a really strong reputation. If they are supported "officially" by someone like LineageOS it might be safer.
Terminate the ssl connection at a reverse proxy hosted in your home server, and instead useiptables to redirect the traffic through the wireguard interface
What exactly does this check? a ping? trying to retrieve something from the API?