bcrypt has stood the test of time very well. It (unintentionally?) does better than some more modern algorithms which are optimized for the wrong kind of "computational hardness", i.e. cache/memory hard. That being said, to avoid all pertinent issues, it probably should only be used in a construction like: (where `mac` is HMAC, CMAC, the keyed mode of BLAKE etc.)
mac(bcrypt(mac(password, secret_key)), secret_key)
This has the following caveats:1) The output of `mac` might need to be encoded in an ASCII-clean way, e.g. using base64, as some implementations don't do well with embedded nulls or 8-bit data.
2) `mac` should produce 72 bytes of data or more. Truncating is better than padding.
3) An appropriate cost should be chosen, 12 or 13 seem to be common choices and should provide a large enough security margin.