1. Do you put anything for second password or password hint? I make sure i know what my password is so there won't be an issue so i assume just don't even bother leaving a hint then?
Nobody plans on forgetting their password. Always have some way of helping you remember it or some way of getting into your wallet in case you forget your passwords.
Most of the people who lost Bitcoin lost them because they forgot their password or lost their wallet file, not because they got hacked.
I believe second password with bc.info wallet is a password for actually sending funds. I would highly recommend using this.
2. Do i check always keep browser backup?
I believe this stores a backup of your wallet in your browser. You should probably use this, though I would recommend having a better system for backing up your wallet.
3. Do i put any secret phrase or leave it blank?
I believe this is to help speed up support issues, such as if you lose your 2FA device. You should use this.
4. Do i enable api access?
If you are not using the API, then don't enable it.
5. Do i block TOR ip addresses?
If you don't use Tor, you can if block Tor IP's if you want to. Though this is security by obscurity as anyone trying to hack your wallet will just chain a proxy/VPN onto Tor once they see it's blocked. Realistically this option provides no extra security at all.
6. IP address whitelist... i see my current ip. Do i just leave this blank?
7. Should i restrict to whitelisted ip addreses only? If i do.. then isn't that going to make it really safe?
The IP whitelist is a list of the only IP's allowed to access your wallet. This is a dangerous feature as if you are away from your PC or your ISP recycles your IP you won't be able to access your wallet. You should only turn this on if you REALLY know what you are doing, it is very easy to lock yourself out. This feature is really only for certain situations, such as if you are setting up a wallet for a website.