Known Limitations
WireGuard is a protocol that, like all protocols, makes necessary trade-offs. This page summarizes known limitations due to these trade-offs.
Deep Packet Inspection
WireGuard does not focus on obfuscation. Obfuscation, rather, should happen at a layer above WireGuard, with WireGuard focused on providing solid crypto with a simple implementation. It is quite possible to plug in various forms of obfuscation, however.
tl;dr Read the docs.
Mullvad does exactly this.
WireGuard limitations hurt the attempt however.
For example, multi-hop betrays the actual exit node to your ISP (or MITM) due to the port used.
To clarify, this is refering to Mullvad multi-hop feature. Doing your own multihop setup doesn't have this issue, right?
Correct. Note that the MTU will be further reduced and that WireGuard DIY multi-hop may be inferred.