I think that nymvpn, despite its youth, is very promising.
But for them to claim to be the most secure vpn, they'd first have to be able to secure the router, they're not natively compatible with opnsense, pfsense, openwrt or any other router or firewall to my knowledge, they don't allow doh dns... I understand that nymvpn's mixnet design makes it unnecessary to change the dns, since they're mixed in the mixnet, so I won't comment on this technical peculiarity, which looks interesting. I'll be waiting for feedback in a few months or a year...but some applications require you to change the dns, like portmaster or others. You should have the choice of doing so with the double- or triple-hop configuration at least.
But above all, without ipsec tunnels and ikev2 protocol support, how can you be protected against mitm attacks? for me, that's their biggest flaw. To claim to be secure and to ignore this type of attack. Of course, the ipsec tunnel alone isn't enough to protect against these attacks, but in my current network configuration, I'm not allowed to implement nymvpn, and I think that's the case for many companies
It's an interesting project that I'd like to be an early adopter of, but the current roadmap doesn't mention these points and I think that's a shame, the only possible ways forward are proton vpn, mullvad ans maybe ivpn, obscura vpn also has teething problems and lacks some important features.