What they did
Mark Williams-Cook, of Candour and AlsoAsked, found that a Google endpoint could be modified to return JSON containing internal scoring and classification data about queries and sites. His team then ran queries against it at scale, collecting around 2TB of data covering more than 90 million queries.
He reported the hole to Google, which paid a bug bounty of $13,337. He donated it to charity. That payment matters for our purposes: it’s Google implicitly confirming the data was genuine rather than an artefact.
What they found
Three findings stand out. Site quality scores exist and are calculated at subdomain level, which supports years of observation that quality assessment runs sitewide rather than page by page. Queries are sorted into a small set of semantic types (short fact, boolean, instruction, definition, reason, comparison, consequence, other), which explains why SERP layouts differ so sharply between question shapes. And passages are scored for how they sit against consensus: agreeing, contradicting, or neither.
How much weight to give it
This is about as strong as external SEO evidence gets. It’s direct observation of Google’s own computed values, at scale, from a named researcher who disclosed responsibly and was paid for it.
What it doesn’t prove
Seeing that Google computes something tells you nothing about how heavily that value counts at ranking time, or whether it’s used at all in the final ordering. Anyone converting these properties into a weighted ranking-factor checklist has gone well beyond what the data supports. The endpoint is also closed now, so the snapshot ages from here.