Is the rules recommended in VPN providers website for OpenWrt or routers? Can you give me a link?

LAN, you can reject forward because there is another rule defining forwarding rules from LAN to vpn. This should not be a problem.

WAN, should not have Accept in input. WAN should not accept data otherwise it cannot be a firewall. Users can ssh to your router from WAN.

VPN, yes you can use Reject for input to make sure there is no input from your vpn server.

I am not sure how MSS clamping will affect the traffic.

So you can use Reject if you can in LAN forwarding and WAN input.