My understand is that WEP in totally insecure now, and WPA with TKIP is broken within an hour, but that WPA with AES is still fine.
WPA2 is better yet, but my prior router didn’t handle it.
The newer routers will give you a choice. You are right; WPA2 is definitely the way to go.
But there is also the question of the speed of your wireless network. You definitely want a dual-band router. That way your fast devices will work at a faster network speed appropriate for them, and your slower devices will work at a slower speed appropriate for them. But if you have a single-band router, the slowest device on your network will determine the speed for all devices on your network. Not good.