How about OPNSense on open hardware of your choice, and passing messy wireless to separate AP? OpenWRT is very good, but the installation and upgrades are not easy. There is a zoo of images for different hardware, installation options and tools. It has to run on small devices, so there are limitations. The documentation on Wiki is scattered and could be improved. I had to search forums for weeks for a custom package…
I moved from pfSense to OpenWRT due to the really poor IPv6 support in pfSense. I don't use the AP capability either. How are things in OPNSense these days?
Particular pain points from pfSense was that it published global IP as DNS address to LAN clients and no way around it, so connectivity broke every time prefix changed, and no real support for specifying prefix-less firewall rules or similar, so couldn't really expose anything via IPv6 without pain.