Those are not cryptographically secure. It would not be hard for someone to figure out how to decode it.
“Do you have a question or comment that involves "security" and "hashids" in the same sentence? Don't use Hashids.”
Still, I can see the temptation that these generated strings “look random so people can’t guess them”. Possibly good enough to obfuscate the number of db records from the casual onlooker but not good protection against enumerating accessible records.