Moderators are selected by Simon, and all of them were originally normal users. The FAQ says, under "How do I become a moderator?": "Be a nice user, help others, make saves, program for TPT - and maybe Simon will notice you." The only slight flaw being that Simon doesn't turn up very often these days.
Threads which need locking, and users who need banning, can be reported to an existing moderator by sending them a conversation. A list of moderators can be found at https://powdertoy.co.uk/Wiki/W/Notable_users.html#Moderators
Tags which need removing can be reported either via a conversation, or via an in-game save report. You can remove tags from your own saves.
Knowing who tagged a save is only really useful for moderators, so that they know who to ban for silly tags.
I think secret votes are a good thing, since they mean that there's no possility of treating people differently based on how/whether they have voted on a save.
Also, nice try, but the forum software has already been reasonably well tested for vulnerabilities over the years by other users. And it would be polite to do a test which is less problematic if successful, such as alert('test');