I'll echo others responses. fw/1 was always meant to give you the basic MVC structure and di/1 was always meant to give you basic injection, based on a convention over configuration pattern.
It gives you what you need to implement the MVC pattern, and that's pretty much it. Or, as Sean Corfield used to say... it gives you what you need and then gets out of your way. It is still being maintained (as in, if someone were to submit a pull request to enhance it, it would likely be pulled in if it's relevant), but no new bells or whistles and no changes to the core should be expected.
ColdBox, on the other hand, is an ever evolving rich ecosystem of not just the core MVC patterns, but also touches a lot of other parts of an application lifecycle and (through add-on modules) can greatly enhance the core capabilities underpinning your application.
I still use both quite regularly. For (small or large) apps that don't require a lot of the in-built or modular features of ColdBox, fw/1 is a perfect fit. For (small or large) apps that do require more bells and whistles, more in-built functionality or want to make use of any of the modules (cborm, cbsecurity, etc.) then I turn to ColdBox.
ColdBox has deeper penetration (in the market) these days than any other framework and an entire corporation built around it to support, maintain and improve it (and the modules) over time.
That said, most of the *box ecosystem's modules also work as stand-alone code so it is able to be incorporated into any framework or no framework code. So, one may still enjoy the benefits of most of the *box ecosystem without being reliant on the core ColdBox MVC.